Hey Daniel,
On the ESA (outgoing rules only) you can configure emails to be sent with encryption profile configured and to use TLS and only fail-over to CRES when TLS fails.
However as shared, it's restricted to outbound traffic only - requires the encryption profile and CRES account and trusted TLS domains (cannot be applied globally, only via the list on CRES portal under your account).
Regards,
Mathew