Mail server certificate · global domains
What share of domains worldwide have a mail server presenting a self-signed or expired certificate?
4.82% of domains worldwide (95% CI 3.7–6.25%), measured across 1,100 domains on 2026-10-01.
Measured every Friday since 2026-08-01 — 11 observations to date. Last measured 2026-10-01.
How this is measured
Complete STARTTLS, inspect the leaf certificate. Denominator: MXs offering STARTTLS.
Passive measurement: a single DNS lookup, TLS handshake, or homepage GET per domain. Aggregate-only; no individual company is named. 95% Wilson confidence intervals. Population: domains sampled from the Common Crawl web graph, filtered to those that do email. Parked domains excluded. Snapshot: common-crawl-domain-stratified-c400-g2500-seed20260729.
Licensed CC BY 4.0 — reuse with attribution to Quiet Failures. Download: JSON · CSV.
Why it matters
SMTP TLS is opportunistic (RFC 7435) — senders accept any certificate — so an invalid certificate still encrypts but authenticates nothing, leaving the connection open to interception. It only becomes a hard failure under DANE or MTA-STS enforce.
Limits of this measurement
Honesty demands the split. Because opportunistic TLS tolerates mismatches, only self_signed and expired are counted as the quiet failure; hostname_mismatch is reported but not counted.
The same check, other segments
- Norway large companies2.26%
- France medium companies1.94%
- France micro companies1.33%
- UK medium & large companies1.13%
- France companies1.03%
- Norway medium companies0.88%
- France large companies0.85%
- UK companies0.83%