Hey Greg,
For enforced (Required TLS) you will need to work with the admin on the destination side to ensure they're only going to accept TLS from your side as well.
As a end user recipient, you wouldn't be able to tell if it was required or preferred as the headers will just indicate TLS usage but not the level of TLS usage.
As the mail admin though, you can check if the connections were done under TLS or plain text if there was no TLS negotiation done within the respective DCIDs.
Also via the GUI > Monitor > TLS and checking the number of 'preferred' connections and cross matching them.
Regards,
Matthew