Mail server certificate · UK medium & large companies

What share of UK medium & large companies have a mail server presenting a self-signed or expired certificate?

1.91%

1.91% of UK medium & large companies (95% CI 0.97–3.72%), measured across 419 companies on 2026-08-14.

valid: 93.08%hostname_mismatch: 5.01%self_signed: 1.43%expired: 0.48%
valid · 93.08%hostname_mismatch · 5.01%self_signed · 1.43%expired · 0.48%
Trend

Measured every Friday since 2026-08-01 — 5 observations to date. Last measured 2026-08-14.

How this is measured

Complete STARTTLS, inspect the leaf certificate. Denominator: MXs offering STARTTLS.

Passive measurement: a single DNS lookup, TLS handshake, or homepage GET per domain. Aggregate-only; no individual company is named. 95% Wilson confidence intervals. Population: national company registries (Companies House, Brreg, SIRENE), sampled by size band and resolved to email-active domains. Parked domains excluded. Snapshot: uk-companies-house-per600-seed20260728.

Licensed CC BY 4.0 — reuse with attribution to Quiet Failures. Download: JSON · CSV.

Why it matters

SMTP TLS is opportunistic (RFC 7435) — senders accept any certificate — so an invalid certificate still encrypts but authenticates nothing, leaving the connection open to interception. It only becomes a hard failure under DANE or MTA-STS enforce.

Limits of this measurement

Honesty demands the split. Because opportunistic TLS tolerates mismatches, only self_signed and expired are counted as the quiet failure; hostname_mismatch is reported but not counted.

The same check, other segments

Show the remaining 5 segments

Share or cite this figure

Reuse is free under CC BY 4.0 — attribution to Quiet Failures is all we ask.

Post on X

Embed this stat

Free to reuse under CC BY 4.0 — the card links back and updates as the data does.

<iframe src="https://quietfailures.com/embed/mx-tls-cert/gb-medium-large" width="380" height="210" style="border:0;max-width:100%" loading="lazy" title="What share of UK medium & large companies have a mail server presenting a self-signed or expired certificate?"></iframe>