Explore observed MX, SPF and DMARC infrastructure for 668,195 domains, provider relationships, historical periods and inbox-placement tools. Last meaningful update: 2026-07-24.
Browse the domain directory · Popular providers · Recent historical periods · Run Inbox Placement Test
What you're looking at. Headline numbers for the analysed Tranco
snapshot: how many domains publish each kind of email-related DNS record, and what share
of DMARC publishers actually enforce their policy (quarantine/reject).
Higher MX vs SPF gap = more domains receive mail than authorise sending; higher SPF vs
DMARC gap = SPF adopted but no policy/feedback enforcement yet.
rua= address and therefore receive no aggregate reports at all — and 115 721 of them (24.97% of all DMARC publishers) pair that with p=none, so the record enforces nothing and reports nowhere. #Each statement is recomputed daily from the full dataset — cite freely, a link to this page is appreciated. Machine-readable version: api/latest.json · llms.txt. Looking for one domain? Domain lookup — mailbox provider, ESPs and DMARC policy of any top-10k website.
Reading the long series: the vertical dashed line marks the change of the underlying list — OpenINTEL alexa (2016-01-22 … 2022-08-10, ~1.6 M measured names) and tranco (from 2022-08-11, ~1.1 M). Absolute counts across that line are not comparable: they describe different measured populations. Gaps in a line are real gaps — no interpolation is drawn. DMARC series start on 2022-08-11 because the alexa partitions contain no _dmarc queries at all; earlier points are empty, not zero. Snapshots flagged partial (an incomplete day at the source) are excluded from deltas and trends.
What this block shows. Where each domain hosts incoming mail —
derived from its primary MX record (lowest mx_preference). This is the
receiving side of email: Google Workspace, Microsoft 365, Zoho, on-prem Exchange, etc.
"Generic / unmatched" buckets are common mail.* / mx*.* hostnames
we couldn't attribute to a specific provider; "Unknown / Other" is everything else.
Note: Cloudflare Email Routing also appears in the ESP table below — that is the
same service observed through two different record types (MX here, SPF there), not a
double count of domains.
The accessible table below contains the full current ranking. Interactive charts are disabled in fast mode.
| # | Mailbox provider | Domains | Share of MX-having domains |
|---|---|---|---|
| 1 | Self-Hosted → | 151 019 | 22.60% |
| 2 | Google Workspace → | 145 231 | 21.73% |
| 3 | Microsoft 365 → | 112 029 | 16.77% |
| 4 | Unknown / Other → | 50 134 | 7.50% |
| 5 | Generic / unmatched (mx*.*) → | 17 202 | 2.57% |
| 6 | Proofpoint → | 12 688 | 1.90% |
| 7 | Generic / unmatched (mail.*) → | 11 687 | 1.75% |
| 8 | Yandex 360 → | 11 025 | 1.65% |
| 9 | Cloudflare Email Routing → | 10 764 | 1.61% |
| 10 | Mimecast → | 10 135 | 1.52% |
| # | Mailbox provider | Domains | Share of MX-having domains |
|---|---|---|---|
| 11 | Hostinger → | 7 861 | 1.18% |
| 12 | Zoho Mail → | 6 914 | 1.03% |
| 13 | Namecheap Email Forwarding → | 6 704 | 1.00% |
| 14 | QQ Mail (Tencent) → | 5 577 | 0.83% |
| 15 | GoDaddy → | 5 066 | 0.76% |
| 16 | OVH Mail → | 4 797 | 0.72% |
| 17 | Amazon WorkMail → | 4 672 | 0.70% |
| 18 | 1&1 IONOS → | 4 057 | 0.61% |
| 19 | Mail.ru for Business → | 3 591 | 0.54% |
| 20 | Barracuda → | 3 541 | 0.53% |
| 21 | Proofpoint Essentials → | 2 902 | 0.43% |
| 22 | Jellyfish (Namecheap) → | 2 815 | 0.42% |
| 23 | SpamExperts (SolarWinds) → | 2 681 | 0.40% |
| 24 | Cisco IronPort → | 2 607 | 0.39% |
| 25 | Beget (RU) → | 2 393 | 0.36% |
| 26 | Mailgun (inbound) → | 2 293 | 0.34% |
| 27 | Rackspace Email → | 2 260 | 0.34% |
| 28 | Alibaba Mail (China) → | 2 101 | 0.31% |
| 29 | Zoho Mail (EU) → | 1 818 | 0.27% |
| 30 | Hosted Email (Rackspace/IONOS) → | 1 729 | 0.26% |
Reading the long series: the vertical dashed line marks the change of the underlying list — OpenINTEL alexa (2016-01-22 … 2022-08-10, ~1.6 M measured names) and tranco (from 2022-08-11, ~1.1 M). Absolute counts across that line are not comparable: they describe different measured populations. Gaps in a line are real gaps — no interpolation is drawn. DMARC series start on 2022-08-11 because the alexa partitions contain no _dmarc queries at all; earlier points are empty, not zero. Snapshots flagged partial (an incomplete day at the source) are excluded from deltas and trends.
What this block shows. The slice of domains whose mailbox cannot be attributed to a named provider — regional hosters, self-built Postfix/Exim, corporate gateways, niche ESPs. Researchers ask for this specifically because it captures the deliverability reality outside the Google / Microsoft monoculture. The detailed report drills down into Top-1000 most common unmatched hosts, 100 hand-picked curiosities (longest one-off names) and a TLD breakdown.
The same metrics cut by list position. Enforcement is a function of how big the site is: the gradient from the top of the list to the tail is the finding, not the average. "Not in current list" = domains measured in this snapshot that are absent from today's Tranco file (list rotation).
| # | Tier | Domains with MX | SPF | DMARC enforced | Self-hosted |
|---|---|---|---|---|---|
| 1 | Tranco top-1k | 695 | 93.53% | 72.81% | 11.80% |
| 2 | top-1k … 10k | 6 509 | 92.89% | 56.46% | 14.30% |
| 3 | top-10k … 100k | 64 807 | 91.15% | 43.30% | 17.66% |
| 4 | top-100k … 1M | 477 860 | 89.90% | 29.81% | 22.75% |
| 5 | not in current list | 114 118 | 87.70% | 18.96% | 26.14% |
What this block shows. Outbound mass-mailing platforms each domain authorises in its SPF record — the marketing-automation, transactional-email and customer-engagement layer (SendGrid, Mailchimp, Mailgun, Klaviyo, HubSpot, Salesforce Marketing Cloud, etc.). One domain can use several ESPs, so percentages sum to more than 100% of SPF-publishing domains.
The accessible table below contains the full current ranking. Interactive charts are disabled in fast mode.
| # | ESP | Domains | Share of SPF-publishing domains |
|---|---|---|---|
| 1 | Amazon SES → | 38 817 | 6.19% |
| 2 | SendGrid (Twilio) → | 29 772 | 4.75% |
| 3 | Mailgun → | 25 778 | 4.11% |
| 4 | Zendesk → | 24 021 | 3.83% |
| 5 | Mailchimp → | 23 081 | 3.68% |
| 6 | Mandrill → | 21 020 | 3.35% |
| 7 | HubSpot → | 19 879 | 3.17% |
| 8 | Salesforce → | 16 361 | 2.61% |
| 9 | Mailjet (Sinch) → | 13 348 | 2.13% |
| 10 | Cloudflare Email Routing → | 11 370 | 1.81% |
| # | ESP | Domains | Share of SPF-publishing domains |
|---|---|---|---|
| 11 | Brevo (ex-Sendinblue) → | 9 041 | 1.44% |
| 12 | Mimecast → | 8 864 | 1.41% |
| 13 | MailerSend → | 8 071 | 1.29% |
| 14 | Namecheap Forwarding → | 6 974 | 1.11% |
| 15 | MailChannels → | 6 730 | 1.07% |
| 16 | Proofpoint → | 5 859 | 0.93% |
| 17 | Elastic Email → | 4 466 | 0.71% |
| 18 | Unisender (RU) → | 3 642 | 0.58% |
| 19 | Constant Contact → | 3 631 | 0.58% |
| 20 | Campaign Monitor → | 3 529 | 0.56% |
| 21 | Marketo (Adobe) → | 3 276 | 0.52% |
| 22 | Zoho Campaigns → | 3 242 | 0.52% |
| 23 | Emsd1 (transactional) → | 3 008 | 0.48% |
| 24 | Postmark → | 2 953 | 0.47% |
| 25 | SendPulse → | 2 901 | 0.46% |
| 26 | Exclaimer (signatures) → | 2 701 | 0.43% |
| 27 | SparkPost → | 2 657 | 0.42% |
| 28 | Zoho ZeptoMail → | 2 657 | 0.42% |
| 29 | Help Scout → | 2 306 | 0.37% |
| 30 | Salesforce Marketing Cloud → | 2 217 | 0.35% |
Reading the long series: the vertical dashed line marks the change of the underlying list — OpenINTEL alexa (2016-01-22 … 2022-08-10, ~1.6 M measured names) and tranco (from 2022-08-11, ~1.1 M). Absolute counts across that line are not comparable: they describe different measured populations. Gaps in a line are real gaps — no interpolation is drawn. DMARC series start on 2022-08-11 because the alexa partitions contain no _dmarc queries at all; earlier points are empty, not zero. Snapshots flagged partial (an incomplete day at the source) are excluded from deltas and trends.
What this block shows. SaaS apps that send mail FROM a
customer's domain on the customer's behalf — productivity, support, payments, HR,
e-commerce and other business apps appearing as include: targets in the
customer's SPF. Distinct from ESPs (mass-mailing platforms) and mailbox providers
(where the inbox lives).
The accessible table below contains the full current ranking. Interactive charts are disabled in fast mode.
| # | SaaS app | Domains | Share of SPF-publishing domains |
|---|---|---|---|
| 1 | Shopify → | 5 472 | 0.87% |
| 2 | Pardot (Salesforce) → | 4 916 | 0.78% |
| 3 | CodeTwo Email Signatures 365 → | 4 458 | 0.71% |
| 4 | KnowBe4 → | 3 506 | 0.56% |
| 5 | Statuspage (Atlassian) → | 2 087 | 0.33% |
| 6 | Trustpilot → | 1 879 | 0.30% |
| 7 | Firebase (Google) → | 1 840 | 0.29% |
| 8 | Atlassian (Jira/Confluence) → | 1 835 | 0.29% |
| 9 | BigCommerce → | 1 523 | 0.24% |
| 10 | Lark / Feishu → | 1 302 | 0.21% |
| # | SaaS app | Domains | Share of SPF-publishing domains |
|---|---|---|---|
| 11 | Sage Intacct → | 1 143 | 0.18% |
| 12 | NetSuite (Oracle) → | 1 134 | 0.18% |
| 13 | Qualtrics → | 1 097 | 0.18% |
| 14 | Oracle Cloud Email → | 1 086 | 0.17% |
| 15 | WordPress.com / WP Cloud → | 974 | 0.16% |
| 16 | Docebo (LMS) → | 928 | 0.15% |
| 17 | Oracle Cloud → | 839 | 0.13% |
| 18 | One.com (DK hosting) → | 793 | 0.13% |
| 19 | Zoho Books → | 708 | 0.11% |
| 20 | AFAS → | 669 | 0.11% |
| 21 | Greenhouse → | 619 | 0.10% |
| 22 | SAP SuccessFactors → | 588 | 0.09% |
| 23 | PayPal Braintree → | 582 | 0.09% |
| 24 | ClickDimensions → | 569 | 0.09% |
| 25 | UKG / UltiPro → | 552 | 0.09% |
| 26 | Autotask (ConnectWise) → | 474 | 0.08% |
| 27 | FormAssembly → | 458 | 0.07% |
| 28 | TOPdesk → | 458 | 0.07% |
| 29 | Freshservice (Freshworks) → | 444 | 0.07% |
| 30 | ConnectWise → | 439 | 0.07% |
Reading the long series: the vertical dashed line marks the change of the underlying list — OpenINTEL alexa (2016-01-22 … 2022-08-10, ~1.6 M measured names) and tranco (from 2022-08-11, ~1.1 M). Absolute counts across that line are not comparable: they describe different measured populations. Gaps in a line are real gaps — no interpolation is drawn. DMARC series start on 2022-08-11 because the alexa partitions contain no _dmarc queries at all; earlier points are empty, not zero. Snapshots flagged partial (an incomplete day at the source) are excluded from deltas and trends.
What this block shows. The policy each DMARC-publishing domain
advertises at _dmarc.<domain>: none = monitor only,
quarantine = mark as spam on fail, reject = drop on fail,
invalid = a syntactically broken record. "Enforced %" treats only
quarantine / reject with pct=100 as actually
enforcing.
The accessible table below contains the full current ranking. Interactive charts are disabled in fast mode.
Reading the long series: the vertical dashed line marks the change of the underlying list — OpenINTEL alexa (2016-01-22 … 2022-08-10, ~1.6 M measured names) and tranco (from 2022-08-11, ~1.1 M). Absolute counts across that line are not comparable: they describe different measured populations. Gaps in a line are real gaps — no interpolation is drawn. DMARC series start on 2022-08-11 because the alexa partitions contain no _dmarc queries at all; earlier points are empty, not zero. Snapshots flagged partial (an incomplete day at the source) are excluded from deltas and trends.
Reading the long series: the vertical dashed line marks the change of the underlying list — OpenINTEL alexa (2016-01-22 … 2022-08-10, ~1.6 M measured names) and tranco (from 2022-08-11, ~1.1 M). Absolute counts across that line are not comparable: they describe different measured populations. Gaps in a line are real gaps — no interpolation is drawn. DMARC series start on 2022-08-11 because the alexa partitions contain no _dmarc queries at all; earlier points are empty, not zero. Snapshots flagged partial (an incomplete day at the source) are excluded from deltas and trends.
A three-way split instead of the usual enforced/not-enforced binary.
Enforcing — p=quarantine or p=reject.
Monitoring — p=none with a working rua=
address: a legitimate rollout phase, someone is reading the reports.
Inert — p=none with no reporting address at all:
the record enforces nothing and reports nowhere.
Maturity split of 463 497 DMARC-publishing domains:
49.34% enforcing,
25.65% monitoring,
24.97% inert.
Under DMARCbis (RFC 9989/9990/9991) the pct= tag no longer exists, so the
same snapshot yields 49.34% enforcing
against 46.99% under RFC 7489 — both are published, the
RFC 7489 figure keeps the 2016 series continuous.
DMARCbis adoption is still marginal: 243 domains
(0.05%) publish np=,
63 publish psd=.
959 records carry a rua= tag that
parses to no usable address at all.
| # | DMARC reporting destination | Domains | Share of DMARC publishers |
|---|---|---|---|
| 1 | Self-hosted / Other | 214 803 | 46.34% |
| 2 | Cloudflare DMARC | 26 981 | 5.82% |
| 3 | Valimail | 14 278 | 3.08% |
| 4 | Proofpoint EFD | 12 603 | 2.72% |
| 5 | Brevo (ex-Sendinblue) | 12 329 | 2.66% |
| 6 | dmarcian | 9 776 | 2.11% |
| 7 | Postmark DMARC | 7 389 | 1.59% |
| 8 | DMARC Analyzer | 6 955 | 1.50% |
| 9 | DMARC Advisor | 3 195 | 0.69% |
| 10 | DMARC Digests | 2 893 | 0.62% |
| # | DMARC reporting destination | Domains | Share of DMARC publishers |
|---|---|---|---|
| 11 | PowerDMARC | 2 416 | 0.52% |
| 12 | Agari (Fortra) | 2 300 | 0.50% |
| 13 | URIports | 2 144 | 0.46% |
| 14 | DMARCLY | 1 972 | 0.43% |
| 15 | Barracuda | 1 554 | 0.34% |
| 16 | Google Workspace | 932 | 0.20% |
| 17 | EasyDMARC | 844 | 0.18% |
| 18 | MailHardener | 722 | 0.16% |
| 19 | Red Sift OnDMARC | 572 | 0.12% |
| 20 | Cisco Secure Email | 433 | 0.09% |
| 21 | Validity (Return Path) | 314 | 0.07% |
| 22 | Microsoft 365 | 298 | 0.06% |
| 23 | Netcraft | 290 | 0.06% |
| 24 | TDMARC | 216 | 0.05% |
| 25 | MXToolbox | 44 | 0.01% |
Which sending platforms sit on top of which inbound stack. Cell = domains whose primary MX belongs to that mailbox provider and whose SPF authorises that ESP; the percentage is of that provider's domains. A domain may use several ESPs, so rows do not sum to 100%.
| Mailbox provider | Amazon SES | SendGrid (Twilio) | Zendesk | Mailchimp | Mailgun | HubSpot | Mandrill | Salesforce | Cloudflare Email Routing | Mailjet (Sinch) |
|---|---|---|---|---|---|---|---|---|---|---|
| Self-Hosted | 2 739 1.81% | 1 468 0.97% | 768 0.51% | 1 415 0.94% | 1 599 1.06% | 398 0.26% | 1 185 0.78% | 385 0.25% | 103 0.07% | 1 255 0.83% |
| Google Workspace | 14 612 10.06% | 11 763 8.10% | 11 186 7.70% | 9 196 6.33% | 9 808 6.75% | 9 691 6.67% | 8 546 5.88% | 4 285 2.95% | 323 0.22% | 3 515 2.42% |
| Microsoft 365 | 9 672 8.63% | 9 311 8.31% | 6 981 6.23% | 7 409 6.61% | 6 352 5.67% | 6 480 5.78% | 6 589 5.88% | 7 142 6.38% | 48 0.04% | 4 156 3.71% |
| Proofpoint | 835 6.58% | 682 5.38% | 725 5.71% | 452 3.56% | 336 2.65% | 461 3.63% | 494 3.89% | 1 097 8.65% | 1 0.01% | 245 1.93% |
| Yandex 360 | 161 1.46% | 39 0.35% | 29 0.26% | 72 0.65% | 211 1.91% | 2 0.02% | 73 0.66% | 1 0.01% | 8 0.07% | 29 0.26% |
| Cloudflare Email Routing | 227 2.11% | 72 0.67% | 74 0.69% | 29 0.27% | 130 1.21% | 13 0.12% | 18 0.17% | 6 0.06% | 10 532 97.84% | 94 0.87% |
| Mimecast | 1 012 9.99% | 1 058 10.44% | 786 7.76% | 698 6.89% | 537 5.30% | 816 8.05% | 648 6.39% | 1 183 11.67% | 0 0.00% | 199 1.96% |
| Hostinger | 40 0.51% | 38 0.48% | 8 0.10% | 6 0.08% | 48 0.61% | 4 0.05% | 6 0.08% | 0 0.00% | 8 0.10% | 27 0.34% |
| Zoho Mail | 404 5.84% | 178 2.57% | 93 1.34% | 122 1.76% | 316 4.57% | 19 0.27% | 106 1.53% | 3 0.04% | 44 0.64% | 103 1.49% |
| Namecheap Email Forwarding | 14 0.21% | 10 0.15% | 4 0.06% | 2 0.03% | 19 0.28% | 0 0.00% | 6 0.09% | 0 0.00% | 3 0.04% | 9 0.13% |
The literal record string copied verbatim from DNS — useful to spot copy-pasted
"starter" policies and identify reporting endpoints (the rua= /
ruf= tags) shared across many domains.
| # | DMARC record | Domains |
|---|---|---|
| 1 | v=DMARC1; p=none; | 58 041 |
| 2 | v=DMARC1; p=none | 32 867 |
| 3 | v=DMARC1; p=none; rua=mailto:rua@dmarc.brevo.com | 9 032 |
| 4 | v=DMARC1; p=quarantine; | 5 016 |
| 5 | v=DMARC1; p=quarantine | 4 029 |
| 6 | v=DMARC1; p=reject; | 3 912 |
| 7 | v=DMARC1;p=none; | 3 771 |
| 8 | v=DMARC1; p=quarantine; adkim=r; aspf=r; rua=mailto:dmarc_rua@onsecureserver.net; | 3 569 |
| 9 | v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com | 3 119 |
| 10 | v=DMARC1; p=quarantine; adkim=s; aspf=s | 3 030 |
| 11 | v=DMARC1; p=reject | 2 884 |
| 12 | v=DMARC1; p=none; aspf=r; adkim=r; | 2 391 |
| 13 | v=DMARC1; p=quarantine; pct=100 | 2 377 |
| 14 | v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s; | 2 124 |
| 15 | v=DMARC1; p=none; sp=none; rua=mailto:dmarc@mailinblue.com!10m; ruf=mailto:dmarc@mailinblue.com!10m; rf=afrf; pct=100; ri=86400 | 2 101 |
| 16 | v=DMARC1;p=none | 1 807 |
| 17 | v=DMARC1; p=none; aspf=r; sp=none | 1 737 |
| 18 | v=DMARC1; p=none; adkim=r; aspf=r; | 1 542 |
| 19 | v=DMARC1; p=reject; sp=reject; rua=mailto:dmarc.report@axa.com; | 1 469 |
| 20 | v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com; | 1 468 |
| 21 | v=DMARC1;p=quarantine;pct=100;fo=1 | 1 266 |
| 22 | v=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.email | 1 258 |
| 23 | v=DMARC1; p=none; rua=mailto:dmarc_agg@vali.email | 1 257 |
| 24 | v=DMARC1;p=reject; | 1 234 |
| 25 | v=DMARC1;p=none;sp=none;adkim=r;aspf=r;pct=100;fo=0;rf=afrf;ri=86400 | 1 231 |
| # | DMARC record | Domains |
|---|---|---|
| 26 | v=DMARC1; p=none; sp=none | 1 055 |
| 27 | v=DMARC1; p=none; sp=none; | 1 026 |
| 28 | v=DMARC1; p=reject; adkim=r; aspf=r; rua=mailto:dmarc_rua@onsecureserver.net; | 1 001 |
| 29 | v=DMARC1; p=none; rua=mailto:dmarc_agg@vali.email; | 971 |
| 30 | v=DMARC1; p=reject; rua=mailto:report@dmarc.amazon.com; ruf=mailto:report@dmarc.amazon.com | 888 |
| 31 | v=DMARC1; p=none; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com | 884 |
| 32 | v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s | 813 |
| 33 | v=DMARC1; p=quarantine; rua=mailto:dmarc_agg@vali.email | 759 |
| 34 | v=DMARC1; p=none; pct=100 | 733 |
| 35 | v=DMARC1; p=reject; pct=100 | 731 |
| 36 | v=DMARC1; p=quarantine; fo=1; ruf=mailto:dmarc@qiye.163.com; rua=mailto:dmarc_report@qiye.163.com | 727 |
| 37 | v=DMARC1;p=quarantine;sp=none;adkim=r;aspf=r;pct=100;fo=0;rf=afrf;ri=86400 | 684 |
| 38 | v=DMARC1; p=reject; rua=mailto:dmarc_rua@onsecureserver.net; adkim=r; aspf=r; | 682 |
| 39 | v=DMARC1; p=none; fo=1; ruf=mailto:dmarc@qiye.163.com; rua=mailto:dmarc_report@qiye.163.com | 671 |
| 40 | v=DMARC1; p=reject; rua=mailto:mailauth-reports@google.com | 614 |
| 41 | v=DMARC1; p=reject; fo=1; ri=3600; rua=mailto:ewai10d2@ag.eu.dmarcian.com; ruf=mailto:ewai10d2@fr.eu.dmarcian.com | 609 |
| 42 | v=DMARC1; p=none; sp=none; rf=afrf; pct=100; ri=86400 | 554 |
| 43 | v=DMARC1; p=quarantine; pct=100; | 548 |
| 44 | v=DMARC1;p=quarantine | 522 |
| 45 | v=DMARC1; p=quarantine; rua=mailto:dmarc_agg@vali.email; | 516 |
| 46 | v=DMARC1; p=none; rua=mailto:mailauth-reports@qq.com | 511 |
| 47 | v=DMARC1; p=reject; pct=100; | 464 |
| 48 | v=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.email; | 442 |
| 49 | v=DMARC1;p=reject;sp=reject;adkim=s;aspf=s | 423 |
| 50 | v=DMARC1; p=none; sp=none; adkim=r; aspf=r | 394 |
| 51 | v=DMARC1; p=none; adkim=r; aspf=r | 381 |
| 52 | v=DMARC1; p=reject; adkim=s; aspf=s; | 367 |
| 53 | v=DMARC1; p=none; pct=100; | 364 |
| 54 | v=DMARC1; p=reject; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com; fo=1 | 348 |
| 55 | v=DMARC1;p=reject | 326 |
| 56 | v=DMARC1 | 326 |
| 57 | v=DMARC1;p=quarantine; | 318 |
| 58 | v=DMARC1; p=reject; adkim=s; aspf=s | 316 |
| 59 | v=DMARC1;p=reject;fo=1;rua=mailto:dmarc_rua@emaildefense.proofpoint.com;ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com | 316 |
| 60 | v=DMARC1; p=none; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com; | 309 |
| 61 | v=DMARC1; p=reject; sp=none; rf=afrf; pct=100; ri=86400 | 308 |
| 62 | v=DMARC1; p=none; aspf=r; adkim=r | 306 |
| 63 | v=DMARC1; p=none; fo=1 | 306 |
| 64 | v=DMARC1; p=reject; sp=reject; pct=100; fo=1; ri=3600; rua=mailto:dmarcrecord@gmail.com; ruf=mailto:dmarcrecord@gmail.com; | 305 |
| 65 | v=DMARC1; p=none; rua=mailto:dmarc@smtp.mailtrap.live; ruf=mailto:dmarc@smtp.mailtrap.live; rf=afrf; pct=100 | 293 |
| 66 | v=DMARC1; p=reject; rua=mailto:tnoff9hr@ag.eu.dmarcadvisor.com; aspf=s; adkim=s; | 282 |
| 67 | v=DMARC1;p=none;sp=none;pct=50;adkim=r;aspf=r; | 271 |
| 68 | v=DMARC1; p=none; rua=mailto:mailauth-reports@google.com | 269 |
| 69 | v=DMARC1;p=none;pct=100 | 266 |
| 70 | v=DMARC1; p=reject; rua=mailto:zsrbf6su@ag.eu.dmarcadvisor.com; | 266 |
| 71 | v=DMARC1;p=reject;sp=none;adkim=r;aspf=r;pct=100;fo=0;rf=afrf;ri=86400 | 264 |
| 72 | v=DMARC1; p=quarantine; rua=mailto:rua@dmarc.brevo.com | 250 |
| 73 | v=DMARC1; p=reject; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com;fo=1 | 248 |
| 74 | v=DMARC1;p=none;rua=mailto:dmarc_report@service.aliyun.com | 246 |
| 75 | v=DMARC1; p=quarantine; adkim=s; aspf=s; | 233 |
| 76 | v=DMARC1; p=none; rua=mailto:rua-mpse@mpub.ne.jp | 231 |
| 77 | v=DMARC1; p=quarantine; adkim=r; aspf=r | 230 |
| 78 | v=DMARC1; p=reject; rua=mailto:dmarc_rua@onsecureserver.net; | 220 |
| 79 | v=DMARC1; p=none; rua=mailto:dmarc.rua@edrone.app; ruf=mailto:dmarc.ruf@edrone.app | 216 |
| 80 | v=DMARC1; p=none; sp=none; rua=mailto:dmarc-raports@dhosting.pl | 207 |
| 81 | v=DMARC1; p=reject; rua=mailto:zicaptxt@ag.dmarcian.com; | 201 |
| 82 | v=DMARC1; p=reject; fo=1; ri=3600; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com | 200 |
| 83 | v=DMARC1; p=quarantine; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com | 198 |
| 84 | v=DMARC1; p=none; rua=mailto:dmarc@reporting.unisender.com | 198 |
| 85 | v=DMARC1;p=none;rua=mailto:rua@dmarc.brevo.com | 188 |
| 86 | v=DMARC1; p=reject; sp=reject | 186 |
| 87 | v=DMARC1; p=quarantine; pct=100; rua=mailto:61e7fc8674b33@ag.eu.dmarcly.com; ruf=mailto:61e7fc8674b33@fo.eu.dmarcly.com; sp=quarantine; fo=1; | 185 |
| 88 | v=DMARC1;p=reject;pct=100; | 184 |
| 89 | v=DMARC1; p=quarantine; pct=100; adkim=r; aspf=r | 183 |
| 90 | v=DMARC1; p=quarantine; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com; | 181 |
| 91 | v=DMARC1; p=none; pct=100; rua=mailto:dmarc@fbl.optin.com; | 176 |
| 92 | v=DMARC1; p=quarantine; adkim=r; aspf=r; | 172 |
| 93 | v=DMARC1; p=quarantine; fo=1 | 171 |
| 94 | v=DMARC1;p=none;pct=100;aspf=r;adkim=r; | 170 |
| 95 | v=DMARC1; p=reject; sp=reject; | 170 |
| 96 | v=DMARC1; p=quarantine; sp=none; pct=100; ri=86400 | 168 |
| 97 | v=DMARC1;p=none;sp=none;adkim=r;aspf=r;pct=100 | 165 |
| 98 | v=DMARC1; p=reject; pct=100; adkim=s; aspf=s | 164 |
| 99 | v=DMARC1; p=quarantine; sp=quarantine | 163 |
| 100 | v=DMARC1; p=reject; rua=mailto:a@dmarcreports.facebook.com; | 163 |
What this block shows. The most popular MX hostnames our dictionary
does not yet attribute to a named mailbox provider. Public list — these feed
back into dictionaries/mx_providers.py for the next iteration so coverage
keeps improving.
| # | MX target | Domains |
|---|---|---|
| 1 | localhost | 498 |
| 2 | mx.services | 284 |
| 3 | 239 | |
| 4 | zonemx.eu | 193 |
| 5 | mail1.sbnation.com | 166 |
| 6 | mail.parktons.com | 161 |
| 7 | alltheemails.com | 151 |
| 8 | mx.email-messaging.com | 141 |
| 9 | mail.autoline.com.ua | 135 |
| 10 | mx2.z-ns.net | 134 |
| 11 | ~ | 124 |
| 12 | lbmx.bcc.gov.bd | 124 |
| 13 | uk.mx1.mailanyone.net | 121 |
| 14 | uk.mx2.mx25.net | 120 |
| 15 | mxi.alpha-prm.jp | 119 |
| 16 | uk.mx3.mailanyone.net | 118 |
| 17 | mx1.ticketsinbound.com | 117 |
| 18 | mail2.recop.jp | 113 |
| 19 | mx2.ticketsinbound.com | 113 |
| 20 | uk.mx4.mx25.net | 113 |
| 21 | s.mail.dcsaas.net | 112 |
| 22 | mx1d10.thinline.cz | 109 |
| 23 | mx1b20.thinline.cz | 109 |
| 24 | mailin.mx-hub.sk | 106 |
| 25 | mailin.mx-hub.cz | 104 |
| # | MX target | Domains |
|---|---|---|
| 26 | se.mx1.mailanyone.net | 101 |
| 27 | se.mx2.mx25.net | 101 |
| 28 | mailin.mx-hub.eu | 101 |
| 29 | se.mx3.mailanyone.net | 97 |
| 30 | cloudmail.auto-vision.ru | 96 |
| 31 | se.mx4.mx25.net | 96 |
| 32 | mx1.cleanmx.pt | 94 |
| 33 | smtp-fwd.wordpress.com | 94 |
| 34 | mx2.cleanmx.pt | 93 |
| 35 | mx.maxns.net | 90 |
| 36 | mx-backup.serveriai.lt | 89 |
| 37 | mailforward.dnsv.jp | 87 |
| 38 | amazon-smtp.amazon.com | 85 |
| 39 | mx1-dk.centerasecurity.dk | 83 |
| 40 | mx2-dk.centerasecurity.dk | 83 |
| 41 | mail.pickelhost.com | 81 |
| 42 | mx.aams4.jp | 78 |
| 43 | mx01.1and1.fr | 77 |
| 44 | mx3-dk.centerasecurity.dk | 77 |
| 45 | mx00.1and1.fr | 76 |
| 46 | mx01.1and1.es | 76 |
| 47 | sitemail.everyone.net | 76 |
| 48 | mail.global.frontbridge.com | 76 |
| 49 | mx-01.mail-forwarder.io | 76 |
| 50 | mx1.netim.net | 75 |
| 51 | mx2.netim.net | 75 |
| 52 | mx-0.aams4.jp | 75 |
| 53 | mx-1.aams4.jp | 75 |
| 54 | mx.vshosting.eu | 75 |
| 55 | void.blackhole.mx | 74 |
| 56 | mx-02.mail-forwarder.io | 74 |
| 57 | mail-fr.securemail.pro | 72 |
| 58 | mx.sendcloud.org | 71 |
| 59 | mx1.email-cluster.com | 71 |
| 60 | mx2.email-cluster.com | 71 |
| 61 | q01es.mail.s-web.de | 70 |
| 62 | q02es.mail.s-web.de | 70 |
| 63 | r01es.mail.s-web.de | 70 |
| 64 | r02es.mail.s-web.de | 70 |
| 65 | mx.spamfilter.io | 69 |
| 66 | mx00.1and1.es | 69 |
| 67 | mail.mpcloud.net | 69 |
| 68 | failover1.email-cluster.com | 69 |
| 69 | mxa.expediagroup.com | 68 |
| 70 | mxb.expediagroup.com | 68 |
| 71 | email.webglobe.cz | 68 |
| 72 | email2.webglobe.cz | 68 |
| 73 | mx2.emailarray.com | 68 |
| 74 | mx1.nepal.gov.np | 68 |
| 75 | email3.webglobe.cz | 67 |
| 76 | email4.webglobe.cz | 67 |
| 77 | mx2.nepal.gov.np | 67 |
| 78 | mx6.kvnbw.de | 67 |
| 79 | mx7.kvnbw.de | 67 |
| 80 | mx8.kvnbw.de | 67 |
| 81 | mx9.kvnbw.de | 67 |
| 82 | smtp-avas.seeweb.it | 66 |
| 83 | mx.emailarray.com | 66 |
| 84 | mx4.emailowl.com | 64 |
| 85 | usa.mx1.mailanyone.net | 64 |
| 86 | antispam.korea.kr | 64 |
| 87 | gmail22.gadmail.de | 64 |
| 88 | gmail23.gadmail.de | 64 |
| 89 | wmail22.gadmail.de | 64 |
| 90 | mx1.oderland.com | 63 |
| 91 | mx2.oderland.com | 63 |
| 92 | mx5.emailowl.com | 63 |
| 93 | usa.mx2.mx25.net | 63 |
| 94 | usa.mx3.mailanyone.net | 63 |
| 95 | usa.mx4.mx25.net | 63 |
| 96 | mx1.daouoffice.com | 63 |
| 97 | mx01.statens-it.dk | 63 |
| 98 | mx02.statens-it.dk | 63 |
| 99 | mx03.statens-it.dk | 63 |
| 100 | mx04.statens-it.dk | 63 |
What this block shows. The most popular SPF include:
targets that don't match any known ESP, mailbox-as-sender, or SaaS pattern yet. Same
feedback loop: top hits get added to dictionaries/esps.py or
dictionaries/saas_senders.py.
| # | SPF include | Domains |
|---|---|---|
| 1 | yunyou.top | 142 |
| 2 | _spf.edhost.eu | 126 |
| 3 | _spf.mail-neoserv.si | 120 |
| 4 | spf.mailii.org | 117 |
| 5 | _spf1-aws.recop.jp | 114 |
| 6 | mlrcloud.com | 113 |
| 7 | spf.pitcom.net | 113 |
| 8 | _spf.exsilia.net | 112 |
| 9 | _spf.lh.pl | 112 |
| 10 | dospf.simplepart.com | 112 |
| 11 | spf.w4ymail.at | 110 |
| 12 | spf.greengeeks.net | 108 |
| 13 | spf.boldem.cz | 105 |
| 14 | _spf.armada.it | 105 |
| 15 | send.k-crm.jp | 103 |
| 16 | spf-2248456.jmsend.com | 103 |
| 17 | spf.mijndomeinhosting.nl | 103 |
| 18 | spf.aams4.jp | 103 |
| 19 | spf.cesky-hosting.cz | 102 |
| 20 | spf.betrend.com | 102 |
| 21 | spf.mailcamp.nl | 101 |
| 22 | spf.v6send.net | 101 |
| 23 | _spf.wpopt.net | 101 |
| 24 | spf.spcloud.jp | 101 |
| 25 | outbound.smtp.wisestamp.net | 100 |
| # | SPF include | Domains |
|---|---|---|
| 26 | gateways.firstdata.com | 100 |
| 27 | _spf.abcp.ru | 100 |
| 28 | _spf.localservices.com.br | 100 |
| 29 | relay.guzelhosting.com | 99 |
| 30 | _spf.octadesk.com | 99 |
| 31 | fmx.etius.jp | 98 |
| 32 | amazon.com | 98 |
| 33 | spf.ssmx.net | 98 |
| 34 | _spf.presscloud.com | 97 |
| 35 | _pmta2.antevenio.com | 96 |
| 36 | _spf.sendnode.com | 96 |
| 37 | _spf.ogicom.pl | 96 |
| 38 | _spf.simpleviewinc.com | 95 |
| 39 | mailii.org | 95 |
| 40 | spf.satorimail.net | 95 |
| 41 | mfg.siteprotect.com | 94 |
| 42 | spf.symplicity.com | 93 |
| 43 | mailing.eqs.com | 93 |
| 44 | _spf.academicworks.com | 93 |
| 45 | smtp-cluster.plusvps.com | 93 |
| 46 | _spf01.mykronos.com | 92 |
| 47 | spf.emailfilter.io | 92 |
| 48 | senders.mailmasterplus.net | 92 |
| 49 | spf.shopserve.jp | 92 |
| 50 | verifymyfafsa.com | 92 |
| 51 | _spf.tld-mx.com | 91 |
| 52 | usermail.zohocreator.com | 91 |
| 53 | relay.thundermail.uk | 91 |
| 54 | spf.host-ww.net | 90 |
| 55 | _spf-dc10.sapsf.com | 90 |
| 56 | spf.protection.outlook | 90 |
| 57 | ofsys.com | 89 |
| 58 | eversrv.com | 89 |
| 59 | spf.qb-feedback.com | 89 |
| 60 | _spf.aid.no | 89 |
| 61 | _spf.sent2email.com | 88 |
| 62 | spf.chinaemail.cn | 88 |
| 63 | spf.w2solution.com | 88 |
| 64 | spf.sosafe.de | 87 |
| 65 | spf.form.run | 87 |
| 66 | spf | 87 |
| 67 | spf.redpoints.com | 87 |
| 68 | _spf.shared-server.net | 87 |
| 69 | spf.qboxmail.com | 86 |
| 70 | custmail.vdata.com | 86 |
| 71 | spfref.jackhenry.com | 85 |
| 72 | ciphr247.com | 85 |
| 73 | spf.esvacloud.com | 84 |
| 74 | mailmailmail.net | 84 |
| 75 | _spf.eemsg.mail.mil | 84 |
| 76 | mail.zohoanalytics.com | 83 |
| 77 | spf-us.appmail.granicusgovaccess.net | 83 |
| 78 | _spf.herodesk-mails.io | 83 |
| 79 | sender.zcsend.jp | 83 |
| 80 | spf2.nlk2.smtps.jp | 83 |
| 81 | _spf.firmstep.com | 82 |
| 82 | spf.zoner.fi | 82 |
| 83 | spf.rpost.net | 81 |
| 84 | spf.pantheon.io | 81 |
| 85 | no-ip.com | 81 |
| 86 | spf.gansend.com | 80 |
| 87 | spf.byway.it | 80 |
| 88 | mail.imismailcenter.com | 79 |
| 89 | spf.mlwrx.com | 79 |
| 90 | _spf.postaffiliatepro.com | 79 |
| 91 | _spf-c.arukereso.hu | 79 |
| 92 | universalspf.org | 79 |
| 93 | x.universalspf.org | 79 |
| 94 | _spf.saashr.com | 79 |
| 95 | support.gov.sg | 79 |
| 96 | relay.email-cluster.com | 79 |
| 97 | _spf.yourfilter.nl | 79 |
| 98 | spf.am.arara.com | 79 |
| 99 | spf.263xmail.com | 79 |
| 100 | successfactors.eu | 78 |
The dataset is the daily OpenINTEL forward-DNS Tranco snapshot
(University of Twente / SURFnet / SIDN Labs). OpenINTEL queries the entire
Tranco top-1M domain list
daily for MX, TXT, NS, A, AAAA, SOA, CAA, DNSSEC and other records, publishing the
results as Apache Parquet. For pre-2022 history we additionally use OpenINTEL's
alexa source (the legacy Alexa top-1M list, retired 2023).
Cite: Roland van Rijswijk-Deij et al., "A High-Performance, Scalable Infrastructure for Large-Scale Active DNS Measurements", IEEE JSAC 2016.
Six deep-dive pages are rebuilt by the same daily run and were previously
reachable only through the sitemap:
SPF health (final all qualifier, DNS-lookup
limit, record length) ·
Email security posture (MTA-STS, BIMI, TLS-RPT, DKIM
selectors) ·
SaaS via verification tokens ·
DNS/NS providers ·
Country × ESP ·
Infrastructure & TLS.
Each report covers a single date — OpenINTEL publishes snapshot D on D+1, so the current UTC date is never treated as an expected snapshot. Freshness means matching the latest date actually present in the OpenINTEL catalogue, typically ~700 k domains with MX records and ~620 k with SPF. The pipeline runs daily at 03:00 UTC, after the usual source-publication window; each daily run produces an HTML report, a JSON summary, an updated time-series, and incremental updates to the domain registry (§ 12). No sub-sampling.
For each domain we read its MX RRset and pick the record with the lowest
mx_preference as the primary mailbox host. The hostname of that
primary MX is matched against an open regex dictionary (dictionaries/mx_providers.py,
currently 328 patterns, hash below). Specific patterns (e.g. .mail.protection.outlook.com)
are tried first; generic fallbacks (mail.*, mx*.*) only after.
Domains whose MX matches no rule are kept as "Unknown / Other" — never dropped — and
exported in Unmatched MX targets for dictionary improvement.
For each domain's apex SPF record (TXT starting with v=spf1) we extract every
include: and redirect= target and resolve them against open classification dictionaries (ESPs, mailbox-as-sender, anti-spam gateways, forwarders, SaaS senders, DMARC vendors, NS providers, verification tokens).
Resolution order: PURE_ESP → MAILBOX_AS_SENDER → GATEWAYS → FORWARDERS → bare-apex
substring fallback → SAAS_SENDERS substring iteration. Bare-apex derivation strips
leading _spf., _spf-eu., spf., mail.
prefixes from dict keys to catch subdomain variants
(e.g. _spf.m1.websupport.sk → matches websupport.sk).
Malformed includes (no dot, <4 chars) are filtered.
One domain may use several ESPs simultaneously, so ESP shares sum to more than 100% of SPF-publishing domains. Current SPF-include target coverage: 0.00%, recomputed from this snapshot rather than hard-coded.
Limitation: "flattened" SPF (where include chains were replaced with raw IP ranges to fit the 10-lookup limit) is not detectable from DNS alone — those domains appear ESP-less even when an ESP is in fact used.
For each domain we query the _dmarc.<domain> TXT record. Records
starting with v=DMARC1 are parsed for:
p= (apex policy): none / quarantine / reject / invalidsp= (subdomain policy)pct= (rollout percentage)rua= aggregate-report destinations → classified into vendor buckets
(Postmark DMARC, Valimail, dmarcian, URIports, EasyDMARC, Red Sift,
Proofpoint EFD, Agari/Fortra, …) using dictionaries/dmarc_vendors.pyA domain is counted as enforced if p=quarantine or
p=reject with pct=100 (or pct absent — defaults to
100).
For every SPF record we additionally extract:
all mechanism:
-all (hard fail), ~all (soft fail), ?all
(neutral), +all (pass-everything — broken / dangerous), or missinginclude:, redirect=,
a:, mx:, exists:, ptr:) — each
mechanism counts as 1 against the spec limit of 10. Records exceeding the limit
return PermErr at recipientsAdoption of modern mail-security TXT records, parsed from the same OpenINTEL parquet:
_mta-sts.<domain> with
v=STSv1 — domain advertises required-TLS to its MXdefault._bimi.<domain> with
v=BIMI1 — brand publishes a verified logo (requires
p=reject)_smtp._tls.<domain>
with v=TLSRPTv1 — domain monitors TLS-failure reports*._domainkey.<domain> queries, well-known selectors
(google, selector1/2, s1/s2, k1/k2/k3,
mailo, mte1, …) are mapped to issuing ESPsFor each domain's NS RRset, every NS hostname is matched against a suffix dictionary
(dictionaries/ns_providers.py) with patterns for Cloudflare, AWS Route 53,
Azure DNS, Google Cloud DNS, GoDaddy, Akamai, NS1, UltraDNS, Yandex, DNSPod,
Aliyun, OVH, Hetzner, Gandi, registrars, and others. A domain is assigned to its
dominant NS provider; ties resolve to whichever pattern was matched first.
Many SaaS apps a domain is connected to never appear in SPF (because the SaaS doesn't
send mail FROM the customer domain). To recover this signal we parse apex TXT records for
verification tokens — google-site-verification=…, MS=…,
atlassian-domain-verification=…, stripe-verification=…, plus
149 other patterns in
dictionaries/verification_tokens.py. This produces a
complementary "SaaS density" metric and surfaces apps that the SPF-only view misses.
Three additional TLS / IPv6 metrics:
_25._tcp.<mx_host>
(where the parquet includes TLSA queries)0 issue … / 0 issuewild … record
at apex; CAs aggregated into a market-share view (Let's Encrypt, DigiCert,
Sectigo, …)Every domain ever observed across snapshots is assigned a stable integer ID
in /var/openintel-cache/registry/domains.sqlite3 (currently
1 867 220 domains). Reports reference domains by ID rather than embedding
strings; clients resolve names from a single gzipped registry dump
(/email-stats/domains.csv.gz, 21.0 MB). This keeps per-report payloads
compact, enables fast set-operation diffs across snapshots, and gives every domain a
first-seen / last-seen timestamp.
Each daily run computes a domain-level diff vs the previous scan and emits a
change-feed at /email-stats/alerts.html (also as JSON + Atom). Detected
events: ESP added/removed in SPF, DMARC policy upgrade/downgrade, primary-mailbox-provider
change, SPF strict→soft regression, MTA-STS / BIMI first publication. Severity tag is
good / bad / info.
The top-100 ESPs, top-100 SaaS senders and top-80 mailbox providers each have a dedicated
detail page at /email-stats/detail/<kind>/<slug>.html showing KPI
cards, a Chart.js sparkline (from history.json), TLD distribution and a
sample of customer domains.
Each domain is assigned a tier from its Tranco rank: top-1k / top-10k / top-100k / top-1M, plus unranked for domains measured in the snapshot but absent from the current list file (rotation). Published as Authentication by Tranco tier: SPF, DMARC enforcement and self-hosting per tier.
Dictionary hashes for this run (sha256, first 12 hex):
Every published report includes the exact OpenINTEL date, dictionary file hashes, and counts of unmatched MX hosts and SPF includes — so any reader can verify or reproduce the figures. Raw OpenINTEL parquet is downloaded into a temporary cache and deleted after analysis; only aggregated, non-redistributable counts are kept long-term (per OpenINTEL data agreement). The domain registry stores names but no record-level content.
Every change to a metric definition is recorded in
the methodology changelog and stamped into each
history point as methodology_version — so a step in a series can
always be attributed to a formula change rather than to reality.
mail.example.com →
mail.example.protection.outlook.com) are not unrolled — only the first MX target
is matched. This biases a small share of domains toward "Unknown" when their MX is a
CNAME to a known provider.Spotted a mis-classified MX target, missed ESP, or want to discuss a finding? We publish corrections in the next daily snapshot.
Send feedback to support@live-direct-marketing.onlineInline comments coming soon. For now, email is the fastest path — you'll see your fix reflected in tomorrow's run.
Daily snapshots — last 90 days kept fully, older ones thinned to monthly.