We use MTA-STS (for inbound AND outbound) with our mode set to enforce[1], to require senders to communicate with us only using TLS encrypted sockets. There is no legal precedence currently requiring software services to implement backdoors.
[1]: https://github.com/forwardemail/mta-sts.forwardemail.net/blo...