email-auth · severity low
TLS reporting
Share of email-active domains publishing no TLS-RPT (SMTP TLS reporting) record.
Measured every Monday · last updated
How it is measured
Tier 0. TXT at _smtp._tls.<domain> for v=TLSRPTv1. Denominator: has_mx.
Why it matters
Without TLS-RPT, a domain has no way to learn that mail to it is being delivered in the clear or that its MTA-STS policy is failing. It is the feedback loop that makes the other two enforceable rather than aspirational.
Limits of this measurement
Low severity and near-universally absent, so it is reported as context on adoption maturity rather than as an urgent defect.
The base rate
Two independent populations. The global, domain-anchored figure is unbiased; the company-anchored figures are built by matching company names to domains and skew toward more digitally-mature firms. Both are published, so the gap is visible.
By company size band
Company-anchored cuts (national registries with a size proxy), split by size band. Right-hand figure is the share not meeting the control.
Every segment
Pick one to see the citable answer for a company like yours, with its trend and methodology.
Show the remaining 62 segments
Slices below 100 measured members are withheld rather than shown with a wide interval — an absent country or issuer means too little data, not zero failures. Licensed CC BY 4.0. Machine-readable data per segment: append .json or .csv to its URL.