Email Domain and Deliverability Statistics
Observed MX, SPF and DMARC infrastructure across 1,062,465 resolved domains of the Tranco top-1M (674,627 publish MX), rebuilt daily from OpenINTEL measurements. Snapshot 2026-09-02.
Domain directory Providers Historical snapshots JSON API Run inbox placement test
What you're looking at. Headline numbers for the analysed Tranco
snapshot: how many domains publish each kind of email-related DNS record, and what share
of DMARC publishers actually enforce their policy (quarantine/reject).
Higher MX vs SPF gap = more domains receive mail than authorise sending; higher SPF vs
DMARC gap = SPF adopted but no policy/feedback enforcement yet.
Key findings — 2026-09-02
- According to Live Direct Marketing's daily Tranco top-1M scan (September 2, 2026), only 47.18% of DMARC-publishing domains actually enforce their policy (p=quarantine or p=reject) — and the share is down 0.24 pp over the last 30 days. DMARC adoption still added 12 053 domains, but p=none accounted for 62% of that net growth. #
- According to Live Direct Marketing's daily Tranco top-1M scan (September 2, 2026), 35.65% of DMARC-publishing domains (170 307) have no working
rua=address and therefore receive no aggregate reports at all — and 120 298 of them (25.19% of all DMARC publishers) pair that withp=none, so the record enforces nothing and reports nowhere. # - As of September 2, 2026, Google Workspace and Microsoft 365 together host inbound mail for 38.42% of Tranco top-1M domains with MX records — 21.60% Google, 16.82% Microsoft (-0.6 pp year-over-year). #
- Self-hosted mail keeps shrinking: 22.75% of MX-publishing domains run their own mail server as of September 2, 2026. #
- The fastest-moving sender platform of the last 30 days is SendGrid (Twilio): it lost 0.14 pp and now sits at 4.61% of SPF-publishing domains. #
Each statement is recomputed daily from the full dataset and published under CC BY 4.0 — reuse it, cite "Live Direct Marketing, Email infrastructure of the Tranco top-1M" with a link. Machine-readable version: api/latest.json · llms.txt. Looking for one domain? Domain lookup — mailbox provider, ESPs and DMARC policy of any top-10k website.
Classification coverage — what the dictionaries explain
Coverage is recomputed from every snapshot. MX vendor attribution excludes
self-hosted domains (22.75%); SPF coverage counts each
distinct include:/redirect= target once per domain. Fully classified
SPF stacks: 72.30% of domains
that delegate through at least one include.
Trend — last 30 day(s) · KPIs
Reading the long series: the vertical dashed line marks the change of the underlying list — OpenINTEL alexa (2016-01-22 … 2022-08-10, ~1.6 M measured names) and tranco (from 2022-08-11, ~1.1 M). Absolute counts across that line are not comparable: they describe different measured populations. Gaps in a line are real gaps — no interpolation is drawn. DMARC series start on 2022-08-11 because the alexa partitions contain no _dmarc queries at all; earlier points are empty, not zero. Snapshots flagged partial (an incomplete day at the source) are excluded from deltas and trends.
Top mailbox providers
What this block shows. Where each domain hosts incoming mail —
derived from its primary MX record (lowest mx_preference). This is the
receiving side of email: Google Workspace, Microsoft 365, Zoho, on-prem Exchange, etc.
"Generic / unmatched" buckets are common mail.* / mx*.* hostnames
we couldn't attribute to a specific provider; "Unknown / Other" is everything else.
Note: Cloudflare Email Routing also appears in the ESP table below — that is the
same service observed through two different record types (MX here, SPF there), not a
double count of domains.
| # | Mailbox provider | Domains | Share of MX-having domains |
|---|---|---|---|
| 1 | Self-Hosted → | 153 445 | 22.75% |
| 2 | Google Workspace → | 145 687 | 21.60% |
| 3 | Microsoft 365 → | 113 459 | 16.82% |
| 4 | Unknown / Other → | 46 095 | 6.83% |
| 5 | Generic / unmatched (mx*.*) → | 17 400 | 2.58% |
| 6 | Proofpoint → | 12 695 | 1.88% |
| 7 | Generic / unmatched (mail.*) → | 12 048 | 1.79% |
| 8 | Cloudflare Email Routing → | 11 450 | 1.70% |
| 9 | Yandex 360 → | 10 872 | 1.61% |
| 10 | Mimecast → | 9 828 | 1.46% |
Show rows 11 – 30
| # | Mailbox provider | Domains | Share of MX-having domains |
|---|---|---|---|
| 11 | Hostinger → | 8 632 | 1.28% |
| 12 | Namecheap Email Forwarding → | 7 397 | 1.10% |
| 13 | Zoho Mail → | 6 986 | 1.04% |
| 14 | QQ Mail (Tencent) → | 5 417 | 0.80% |
| 15 | GoDaddy → | 5 305 | 0.79% |
| 16 | OVH Mail → | 5 144 | 0.76% |
| 17 | Amazon WorkMail → | 4 557 | 0.68% |
| 18 | 1&1 IONOS → | 4 532 | 0.67% |
| 19 | Mail.ru for Business → | 3 551 | 0.53% |
| 20 | Barracuda → | 3 428 | 0.51% |
| 21 | Proofpoint Essentials → | 2 969 | 0.44% |
| 22 | Jellyfish (Namecheap) → | 2 730 | 0.40% |
| 23 | SpamExperts (SolarWinds) → | 2 672 | 0.40% |
| 24 | Beget (RU) → | 2 570 | 0.38% |
| 25 | Cisco IronPort → | 2 537 | 0.38% |
| 26 | Rackspace Email → | 2 212 | 0.33% |
| 27 | Mailgun (inbound) → | 2 153 | 0.32% |
| 28 | Alibaba Mail (China) → | 1 980 | 0.29% |
| 29 | Zoho Mail (EU) → | 1 912 | 0.28% |
| 30 | Hosted Email (Rackspace/IONOS) → | 1 855 | 0.27% |
Trend — last 30 day(s) · Top mailbox providers
Reading the long series: the vertical dashed line marks the change of the underlying list — OpenINTEL alexa (2016-01-22 … 2022-08-10, ~1.6 M measured names) and tranco (from 2022-08-11, ~1.1 M). Absolute counts across that line are not comparable: they describe different measured populations. Gaps in a line are real gaps — no interpolation is drawn. DMARC series start on 2022-08-11 because the alexa partitions contain no _dmarc queries at all; earlier points are empty, not zero. Snapshots flagged partial (an incomplete day at the source) are excluded from deltas and trends.
Long-tail / Unknown MX — the rest of the internet
What this block shows. The slice of domains whose mailbox cannot be attributed to a named provider — regional hosters, self-built Postfix/Exim, corporate gateways, niche ESPs. Researchers ask for this specifically because it captures the deliverability reality outside the Google / Microsoft monoculture. The detailed report drills down into Top-1000 most common unmatched hosts, 100 hand-picked curiosities (longest one-off names) and a TLD breakdown.
Authentication by Tranco tier
The same metrics cut by list position. Enforcement is a function of how big the site is: the gradient from the top of the list to the tail is the finding, not the average. "Not in current list" = domains measured in this snapshot that are absent from today's Tranco file (list rotation).
| # | Tier | Domains with MX | SPF | DMARC enforced | Self-hosted |
|---|---|---|---|---|---|
| 1 | Tranco top-1k | 693 | 94.08% | 73.16% | 12.55% |
| 2 | top-1k … 10k | 6 487 | 92.91% | 56.76% | 14.92% |
| 3 | top-10k … 100k | 64 629 | 91.16% | 43.21% | 17.64% |
| 4 | top-100k … 1M | 585 153 | 89.63% | 28.15% | 23.23% |
| 5 | not in current list | 17 665 | 88.33% | 21.34% | 28.51% |
Top ESPs / mass-mailing services
What this block shows. Outbound mass-mailing platforms each domain authorises in its SPF record — the marketing-automation, transactional-email and customer-engagement layer (SendGrid, Mailchimp, Mailgun, Klaviyo, HubSpot, Salesforce Marketing Cloud, etc.). One domain can use several ESPs, so percentages sum to more than 100% of SPF-publishing domains.
| # | ESP | Domains | Share of SPF-publishing domains |
|---|---|---|---|
| 1 | Amazon SES → | 39 009 | 6.10% |
| 2 | SendGrid (Twilio) → | 29 482 | 4.61% |
| 3 | Mailgun → | 25 530 | 3.99% |
| 4 | Zendesk → | 23 839 | 3.73% |
| 5 | Mailchimp → | 22 873 | 3.57% |
| 6 | Mandrill → | 20 696 | 3.23% |
| 7 | HubSpot → | 19 692 | 3.08% |
| 8 | Salesforce → | 16 138 | 2.52% |
| 9 | Mailjet (Sinch) → | 13 502 | 2.11% |
| 10 | Cloudflare Email Routing → | 12 052 | 1.88% |
Show rows 11 – 30
| # | ESP | Domains | Share of SPF-publishing domains |
|---|---|---|---|
| 11 | Brevo (ex-Sendinblue) → | 9 325 | 1.46% |
| 12 | Mimecast → | 8 576 | 1.34% |
| 13 | MailerSend → | 8 239 | 1.29% |
| 14 | Namecheap Forwarding → | 7 671 | 1.20% |
| 15 | MailChannels → | 6 642 | 1.04% |
| 16 | Proofpoint → | 5 902 | 0.92% |
| 17 | Elastic Email → | 4 534 | 0.71% |
| 18 | Unisender (RU) → | 3 682 | 0.58% |
| 19 | Constant Contact → | 3 620 | 0.57% |
| 20 | Campaign Monitor → | 3 541 | 0.55% |
| 21 | Zoho Campaigns → | 3 229 | 0.50% |
| 22 | Marketo (Adobe) → | 3 212 | 0.50% |
| 23 | Postmark → | 2 938 | 0.46% |
| 24 | Emsd1 (transactional) → | 2 920 | 0.46% |
| 25 | SendPulse → | 2 867 | 0.45% |
| 26 | Exclaimer (signatures) → | 2 681 | 0.42% |
| 27 | SparkPost → | 2 642 | 0.41% |
| 28 | Zoho ZeptoMail → | 2 583 | 0.40% |
| 29 | Help Scout → | 2 249 | 0.35% |
| 30 | Salesforce Marketing Cloud → | 2 176 | 0.34% |
Trend — last 30 day(s) · Top ESPs
Reading the long series: the vertical dashed line marks the change of the underlying list — OpenINTEL alexa (2016-01-22 … 2022-08-10, ~1.6 M measured names) and tranco (from 2022-08-11, ~1.1 M). Absolute counts across that line are not comparable: they describe different measured populations. Gaps in a line are real gaps — no interpolation is drawn. DMARC series start on 2022-08-11 because the alexa partitions contain no _dmarc queries at all; earlier points are empty, not zero. Snapshots flagged partial (an incomplete day at the source) are excluded from deltas and trends.
SaaS senders (Notion, Slack, Zendesk, Atlassian, Stripe…)
What this block shows. SaaS apps that send mail FROM a
customer's domain on the customer's behalf — productivity, support, payments, HR,
e-commerce and other business apps appearing as include: targets in the
customer's SPF. Distinct from ESPs (mass-mailing platforms) and mailbox providers
(where the inbox lives).
| # | SaaS app | Domains | Share of SPF-publishing domains |
|---|---|---|---|
| 1 | Shopify → | 5 540 | 0.87% |
| 2 | Pardot (Salesforce) → | 4 743 | 0.74% |
| 3 | CodeTwo Email Signatures 365 → | 4 486 | 0.70% |
| 4 | KnowBe4 → | 3 397 | 0.53% |
| 5 | Statuspage (Atlassian) → | 2 028 | 0.32% |
| 6 | BigCommerce → | 1 911 | 0.30% |
| 7 | Trustpilot → | 1 887 | 0.29% |
| 8 | Firebase (Google) → | 1 839 | 0.29% |
| 9 | Atlassian (Jira/Confluence) → | 1 767 | 0.28% |
| 10 | Lark / Feishu → | 1 286 | 0.20% |
Show rows 11 – 30
| # | SaaS app | Domains | Share of SPF-publishing domains |
|---|---|---|---|
| 11 | Sage Intacct → | 1 133 | 0.18% |
| 12 | NetSuite (Oracle) → | 1 128 | 0.18% |
| 13 | Oracle Cloud Email → | 1 088 | 0.17% |
| 14 | Qualtrics → | 1 088 | 0.17% |
| 15 | WordPress.com / WP Cloud → | 1 013 | 0.16% |
| 16 | SAP SuccessFactors → | 948 | 0.15% |
| 17 | Docebo (LMS) → | 916 | 0.14% |
| 18 | Oracle Cloud → | 830 | 0.13% |
| 19 | One.com (DK hosting) → | 829 | 0.13% |
| 20 | Zoho Books → | 721 | 0.11% |
| 21 | AFAS → | 667 | 0.10% |
| 22 | Greenhouse → | 622 | 0.10% |
| 23 | PayPal Braintree → | 558 | 0.09% |
| 24 | ClickDimensions → | 552 | 0.09% |
| 25 | UKG / UltiPro → | 513 | 0.08% |
| 26 | Autotask (ConnectWise) → | 471 | 0.07% |
| 27 | Odoo → | 449 | 0.07% |
| 28 | TOPdesk → | 448 | 0.07% |
| 29 | FormAssembly → | 444 | 0.07% |
| 30 | k.io (workspace) → | 435 | 0.07% |
Trend — last 30 day(s) · Top SaaS senders
Reading the long series: the vertical dashed line marks the change of the underlying list — OpenINTEL alexa (2016-01-22 … 2022-08-10, ~1.6 M measured names) and tranco (from 2022-08-11, ~1.1 M). Absolute counts across that line are not comparable: they describe different measured populations. Gaps in a line are real gaps — no interpolation is drawn. DMARC series start on 2022-08-11 because the alexa partitions contain no _dmarc queries at all; earlier points are empty, not zero. Snapshots flagged partial (an incomplete day at the source) are excluded from deltas and trends.
DMARC adoption
What this block shows. The policy each DMARC-publishing domain
advertises at _dmarc.<domain>: none = monitor only,
quarantine = mark as spam on fail, reject = drop on fail,
invalid = a syntactically broken record. "Enforced %" treats only
quarantine / reject with pct=100 as actually
enforcing.
Trend — last 30 day(s) · DMARC enforced %
Reading the long series: the vertical dashed line marks the change of the underlying list — OpenINTEL alexa (2016-01-22 … 2022-08-10, ~1.6 M measured names) and tranco (from 2022-08-11, ~1.1 M). Absolute counts across that line are not comparable: they describe different measured populations. Gaps in a line are real gaps — no interpolation is drawn. DMARC series start on 2022-08-11 because the alexa partitions contain no _dmarc queries at all; earlier points are empty, not zero. Snapshots flagged partial (an incomplete day at the source) are excluded from deltas and trends.
Trend — last 30 day(s) · DMARC policies
Reading the long series: the vertical dashed line marks the change of the underlying list — OpenINTEL alexa (2016-01-22 … 2022-08-10, ~1.6 M measured names) and tranco (from 2022-08-11, ~1.1 M). Absolute counts across that line are not comparable: they describe different measured populations. Gaps in a line are real gaps — no interpolation is drawn. DMARC series start on 2022-08-11 because the alexa partitions contain no _dmarc queries at all; earlier points are empty, not zero. Snapshots flagged partial (an incomplete day at the source) are excluded from deltas and trends.
Does the DMARC record actually do anything?
A three-way split instead of the usual enforced/not-enforced binary.
Enforcing — p=quarantine or p=reject.
Monitoring — p=none with a working rua=
address: a legitimate rollout phase, someone is reading the reports.
Inert — p=none with no reporting address at all:
the record enforces nothing and reports nowhere.
Maturity split of 477 655 DMARC-publishing domains:
49.45% enforcing,
25.32% monitoring,
25.19% inert.
Under DMARCbis (RFC 9989/9990/9991) the pct= tag no longer exists, so the
same snapshot yields 49.45% enforcing
against 47.18% under RFC 7489 — both are published, the
RFC 7489 figure keeps the 2016 series continuous.
DMARCbis adoption is still marginal: 372 domains
(0.08%) publish np=,
85 publish psd=.
979 records carry a rua= tag that
parses to no usable address at all.
| # | DMARC reporting destination | Domains | Share of DMARC publishers |
|---|---|---|---|
| 1 | Self-hosted / Other | 220 927 | 46.25% |
| 2 | Cloudflare DMARC | 28 050 | 5.87% |
| 3 | Valimail | 14 292 | 2.99% |
| 4 | Brevo (ex-Sendinblue) | 13 389 | 2.80% |
| 5 | Proofpoint EFD | 12 553 | 2.63% |
| 6 | dmarcian | 10 236 | 2.14% |
| 7 | Postmark DMARC | 7 371 | 1.54% |
| 8 | DMARC Analyzer | 6 856 | 1.44% |
| 9 | DMARC Advisor | 3 126 | 0.65% |
| 10 | DMARC Digests | 2 836 | 0.59% |
Show rows 11 – 25
| # | DMARC reporting destination | Domains | Share of DMARC publishers |
|---|---|---|---|
| 11 | PowerDMARC | 2 432 | 0.51% |
| 12 | Agari (Fortra) | 2 251 | 0.47% |
| 13 | URIports | 2 158 | 0.45% |
| 14 | DMARCLY | 1 896 | 0.40% |
| 15 | Barracuda | 1 528 | 0.32% |
| 16 | Google Workspace | 976 | 0.20% |
| 17 | EasyDMARC | 837 | 0.18% |
| 18 | MailHardener | 724 | 0.15% |
| 19 | Red Sift OnDMARC | 571 | 0.12% |
| 20 | Cisco Secure Email | 397 | 0.08% |
| 21 | Validity (Return Path) | 306 | 0.06% |
| 22 | Microsoft 365 | 290 | 0.06% |
| 23 | Netcraft | 289 | 0.06% |
| 24 | TDMARC | 216 | 0.05% |
| 25 | MXToolbox | 41 | 0.01% |
Mailbox provider × sending platform
Which sending platforms sit on top of which inbound stack. Cell = domains whose primary MX belongs to that mailbox provider and whose SPF authorises that ESP; the percentage is of that provider's domains. A domain may use several ESPs, so rows do not sum to 100%.
| Mailbox provider | Amazon SES | SendGrid (Twilio) | Zendesk | Mailchimp | Mailgun | HubSpot | Mandrill | Salesforce | Cloudflare Email Routing | Mailjet (Sinch) |
|---|---|---|---|---|---|---|---|---|---|---|
| Self-Hosted | 2 850 1.86% | 1 468 0.96% | 775 0.51% | 1 408 0.92% | 1 579 1.03% | 402 0.26% | 1 167 0.76% | 378 0.25% | 101 0.07% | 1 285 0.84% |
| Google Workspace | 14 628 10.04% | 11 667 8.01% | 11 093 7.61% | 9 074 6.23% | 9 721 6.67% | 9 569 6.57% | 8 339 5.72% | 4 225 2.90% | 332 0.23% | 3 452 2.37% |
| Microsoft 365 | 9 647 8.50% | 9 217 8.12% | 6 948 6.12% | 7 396 6.52% | 6 336 5.58% | 6 466 5.70% | 6 526 5.75% | 7 049 6.21% | 45 0.04% | 4 214 3.71% |
| Proofpoint | 841 6.62% | 684 5.39% | 746 5.88% | 460 3.62% | 333 2.62% | 459 3.62% | 485 3.82% | 1 104 8.70% | 1 0.01% | 252 1.99% |
| Cloudflare Email Routing | 244 2.13% | 74 0.65% | 65 0.57% | 31 0.27% | 123 1.07% | 11 0.10% | 20 0.17% | 5 0.04% | 11 214 97.94% | 99 0.86% |
| Yandex 360 | 153 1.41% | 37 0.34% | 31 0.29% | 72 0.66% | 209 1.92% | 2 0.02% | 67 0.62% | 1 0.01% | 7 0.06% | 26 0.24% |
| Mimecast | 980 9.97% | 1 019 10.37% | 752 7.65% | 671 6.83% | 521 5.30% | 768 7.81% | 637 6.48% | 1 138 11.58% | 1 0.01% | 200 2.04% |
| Hostinger | 47 0.54% | 43 0.50% | 10 0.12% | 7 0.08% | 61 0.71% | 4 0.05% | 4 0.05% | 0 0.00% | 8 0.09% | 29 0.34% |
| Namecheap Email Forwarding | 14 0.19% | 10 0.14% | 4 0.05% | 2 0.03% | 20 0.27% | 0 0.00% | 6 0.08% | 0 0.00% | 4 0.05% | 9 0.12% |
| Zoho Mail | 403 5.77% | 175 2.51% | 96 1.37% | 118 1.69% | 319 4.57% | 19 0.27% | 100 1.43% | 4 0.06% | 41 0.59% | 107 1.53% |
Reverse DNS: the failure nobody publishes
What this block shows. Every MX hostname in the snapshot was resolved to its addresses, and those addresses resolved back. A missing PTR is one of the very few things visible in DNS that makes large providers reject mail outright — a diagnosis, not a statistic.
No PTR, by mailbox provider
Run it yourself and it breaks; hand it to a provider and it does not. The dictionary classifies a domain as self-hosted when its MX lives under its own apex.
No PTR, by list position
The gradient is weaker than for DMARC: the top of the list holds many large self-hosted operators, and they break it too.
No PTR, worst ccTLDs
Zones with at least 500 domains in the snapshot. A whole ccTLD sitting high here usually means a handful of local hosters, not thousands of independent mistakes.
Top 100 most-used DMARC records (verbatim)
The literal record string copied verbatim from DNS — useful to spot copy-pasted
"starter" policies and identify reporting endpoints (the rua= /
ruf= tags) shared across many domains.
| # | DMARC record | Domains |
|---|---|---|
| 1 | v=DMARC1; p=none; | 60 652 |
| 2 | v=DMARC1; p=none | 33 960 |
| 3 | v=DMARC1; p=none; rua=mailto:rua@dmarc.brevo.com | 9 758 |
| 4 | v=DMARC1; p=quarantine; | 5 160 |
| 5 | v=DMARC1; p=reject; | 4 152 |
| 6 | v=DMARC1; p=quarantine | 4 092 |
| 7 | v=DMARC1; p=quarantine; adkim=r; aspf=r; rua=mailto:dmarc_rua@onsecureserver.net; | 4 068 |
| 8 | v=DMARC1;p=none; | 3 787 |
| 9 | v=DMARC1; p=reject; sp=reject; rua=mailto:dmarc.report@axa.com; | 3 496 |
| 10 | v=DMARC1; p=quarantine; adkim=s; aspf=s | 3 109 |
| 11 | v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com | 3 080 |
| 12 | v=DMARC1; p=reject | 2 978 |
| 13 | v=DMARC1; p=none; aspf=r; adkim=r; | 2 478 |
| 14 | v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s; | 2 223 |
| 15 | v=DMARC1; p=quarantine; pct=100 | 2 217 |
| 16 | v=DMARC1; p=none; sp=none; rua=mailto:dmarc@mailinblue.com!10m; ruf=mailto:dmarc@mailinblue.com!10m; rf=afrf; pct=100; ri=86400 | 2 074 |
| 17 | v=DMARC1;p=none | 1 824 |
| 18 | v=DMARC1; p=none; aspf=r; sp=none | 1 767 |
| 19 | v=DMARC1; p=none; adkim=r; aspf=r; | 1 681 |
| 20 | v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com; | 1 539 |
| 21 | v=DMARC1;p=none;sp=none;adkim=r;aspf=r;pct=100;fo=0;rf=afrf;ri=86400 | 1 311 |
| 22 | v=DMARC1;p=reject; | 1 284 |
| 23 | v=DMARC1; p=none; rua=mailto:dmarc_agg@vali.email | 1 281 |
| 24 | v=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.email | 1 277 |
| 25 | v=DMARC1;p=quarantine;pct=100;fo=1 | 1 207 |
Show rows 26 – 100
| # | DMARC record | Domains |
|---|---|---|
| 26 | v=DMARC1; p=none; sp=none | 1 139 |
| 27 | v=DMARC1; p=none; sp=none; | 1 112 |
| 28 | v=DMARC1; p=reject; fo=1; ri=3600; rua=mailto:ewai10d2@ag.eu.dmarcian.com; ruf=mailto:ewai10d2@fr.eu.dmarcian.com | 1 072 |
| 29 | v=DMARC1; p=reject; adkim=r; aspf=r; rua=mailto:dmarc_rua@onsecureserver.net; | 992 |
| 30 | v=DMARC1; p=none; rua=mailto:dmarc_agg@vali.email; | 943 |
| 31 | v=DMARC1; p=reject; rua=mailto:report@dmarc.amazon.com; ruf=mailto:report@dmarc.amazon.com | 897 |
| 32 | v=DMARC1; p=none; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com | 857 |
| 33 | v=DMARC1; p=reject; rua=mailto:dmarc_rua@onsecureserver.net; adkim=r; aspf=r; | 760 |
| 34 | v=DMARC1; p=quarantine; rua=mailto:dmarc_agg@vali.email | 751 |
| 35 | v=DMARC1; p=none; pct=100 | 745 |
| 36 | v=DMARC1; p=reject; pct=100 | 743 |
| 37 | v=DMARC1; p=quarantine; fo=1; ruf=mailto:dmarc@qiye.163.com; rua=mailto:dmarc_report@qiye.163.com | 722 |
| 38 | v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s | 715 |
| 39 | v=DMARC1;p=quarantine;sp=none;adkim=r;aspf=r;pct=100;fo=0;rf=afrf;ri=86400 | 708 |
| 40 | v=DMARC1; p=reject; rua=mailto:mailauth-reports@google.com | 647 |
| 41 | v=DMARC1; p=none; fo=1; ruf=mailto:dmarc@qiye.163.com; rua=mailto:dmarc_report@qiye.163.com | 639 |
| 42 | v=DMARC1; p=none; sp=none; rf=afrf; pct=100; ri=86400 | 571 |
| 43 | v=DMARC1;p=quarantine | 558 |
| 44 | v=DMARC1; p=quarantine; pct=100; | 541 |
| 45 | v=DMARC1;p=reject;sp=reject;adkim=s;aspf=s | 514 |
| 46 | v=DMARC1; p=quarantine; rua=mailto:dmarc_agg@vali.email; | 513 |
| 47 | v=DMARC1; p=none; rua=mailto:mailauth-reports@qq.com | 492 |
| 48 | v=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.email; | 468 |
| 49 | v=DMARC1; p=reject; pct=100; | 465 |
| 50 | v=DMARC1; p=none; sp=none; adkim=r; aspf=r | 438 |
| 51 | v=DMARC1; p=none; adkim=r; aspf=r | 430 |
| 52 | v=DMARC1; p=none; pct=100; | 374 |
| 53 | v=DMARC1; p=reject; adkim=s; aspf=s; | 369 |
| 54 | v=DMARC1; p=reject; rua=mailto:dmarc.report@axa.com; | 358 |
| 55 | v=DMARC1; p=quarantine; adkim=r; aspf=r | 348 |
| 56 | v=DMARC1; p=reject; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com; fo=1 | 337 |
| 57 | v=DMARC1;p=reject | 332 |
| 58 | v=DMARC1; p=reject; sp=none; rf=afrf; pct=100; ri=86400 | 327 |
| 59 | v=DMARC1;p=quarantine; | 325 |
| 60 | v=DMARC1; p=reject; sp=reject; pct=100; fo=1; ri=3600; rua=mailto:dmarcrecord@gmail.com; ruf=mailto:dmarcrecord@gmail.com; | 321 |
| 61 | v=DMARC1 | 318 |
| 62 | v=DMARC1; p=none; aspf=r; adkim=r | 312 |
| 63 | v=DMARC1; p=none; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com; | 310 |
| 64 | v=DMARC1; p=none; fo=1 | 308 |
| 65 | v=DMARC1; p=reject; adkim=s; aspf=s | 305 |
| 66 | v=DMARC1;p=reject;fo=1;rua=mailto:dmarc_rua@emaildefense.proofpoint.com;ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com | 302 |
| 67 | v=DMARC1;p=reject;sp=none;adkim=r;aspf=r;pct=100;fo=0;rf=afrf;ri=86400 | 295 |
| 68 | v=DMARC1; p=quarantine; rua=mailto:rua@dmarc.brevo.com | 291 |
| 69 | v=DMARC1; p=none; rua=mailto:dmarc@smtp.mailtrap.live; ruf=mailto:dmarc@smtp.mailtrap.live; rf=afrf; pct=100 | 290 |
| 70 | v=DMARC1;p=none;sp=none;pct=50;adkim=r;aspf=r; | 286 |
| 71 | v=DMARC1; p=reject; rua=mailto:tnoff9hr@ag.eu.dmarcadvisor.com; aspf=s; adkim=s; | 279 |
| 72 | v=DMARC1; p=none; rua=mailto:mailauth-reports@google.com | 274 |
| 73 | v=DMARC1; p=reject; rua=mailto:zsrbf6su@ag.eu.dmarcadvisor.com; | 265 |
| 74 | v=DMARC1;p=none;pct=100 | 263 |
| 75 | v=DMARC1; p=quarantine; adkim=s; aspf=s; | 247 |
| 76 | v=DMARC1;p=none;rua=mailto:dmarc_report@service.aliyun.com | 247 |
| 77 | v=DMARC1; p=reject; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com;fo=1 | 241 |
| 78 | v=DMARC1; p=none; rua=mailto:rua-mpse@mpub.ne.jp | 231 |
| 79 | v=DMARC1; p=reject; rua=mailto:dmarc_rua@onsecureserver.net; | 222 |
| 80 | v=DMARC1; p=reject; sp=reject; aspf=s; pct=100 | 217 |
| 81 | v=DMARC1; p=none; sp=none; rua=mailto:dmarc-raports@dhosting.pl | 216 |
| 82 | v=DMARC1; p=none; rua=mailto:dmarc.rua@edrone.app; ruf=mailto:dmarc.ruf@edrone.app | 214 |
| 83 | v=DMARC1; p=reject; sp=reject | 207 |
| 84 | v=DMARC1;p=none;sp=none;adkim=r;aspf=r;pct=100 | 204 |
| 85 | v=DMARC1; p=none; rua=mailto:dmarc@reporting.unisender.com | 202 |
| 86 | v=DMARC1; p=quarantine; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com | 200 |
| 87 | v=DMARC1;p=none;rua=mailto:rua@dmarc.brevo.com | 200 |
| 88 | v=DMARC1; p=reject; rua=mailto:zicaptxt@ag.dmarcian.com; | 197 |
| 89 | v=DMARC1; p=reject; fo=1; ri=3600; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com | 196 |
| 90 | v=DMARC1;p=reject;pct=100; | 190 |
| 91 | v=DMARC1; p=quarantine; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com; | 188 |
| 92 | v=DMARC1; p=reject; rua=mailto:2ynhg3yt@ag.dmarcian.com | 186 |
| 93 | v=DMARC1; p=quarantine; pct=100; adkim=r; aspf=r | 180 |
| 94 | v=DMARC1; p=quarantine; pct=100; rua=mailto:61e7fc8674b33@ag.eu.dmarcly.com; ruf=mailto:61e7fc8674b33@fo.eu.dmarcly.com; sp=quarantine; fo=1; | 178 |
| 95 | v=DMARC1; p=reject; sp=reject; | 177 |
| 96 | v=DMARC1; p=quarantine; fo=1 | 176 |
| 97 | v=DMARC1; p=quarantine; adkim=r; aspf=r; | 176 |
| 98 | v=DMARC1; p=reject; ruf=mailto:dmarc@purelymail.com | 174 |
| 99 | v=DMARC1; p=none; pct=100; rua=mailto:dmarc@fbl.optin.com; | 169 |
| 100 | v=DMARC1;p=none;pct=100;aspf=r;adkim=r; | 167 |
Unmatched MX targets — top 100
What this block shows. The most popular MX hostnames our dictionary
does not yet attribute to a named mailbox provider. Public list — these feed
back into dictionaries/mx_providers.py for the next iteration so coverage
keeps improving.
| # | MX target | Domains |
|---|---|---|
| 1 | localhost | 452 |
| 2 | mx.services | 298 |
| 3 | 242 | |
| 4 | zonemx.eu | 228 |
| 5 | mail.parktons.com | 198 |
| 6 | mail1.sbnation.com | 165 |
| 7 | mail.pickelhost.com | 161 |
| 8 | alltheemails.com | 140 |
| 9 | mx.email-messaging.com | 135 |
| 10 | lbmx.bcc.gov.bd | 124 |
| 11 | s.mail.dcsaas.net | 122 |
| 12 | ns4.forevermail.com | 120 |
| 13 | mail.autoline.com.ua | 120 |
| 14 | mx2.z-ns.net | 119 |
| 15 | mxi.alpha-prm.jp | 117 |
| 16 | mail2.recop.jp | 113 |
| 17 | mx1d10.thinline.cz | 112 |
| 18 | mx1b20.thinline.cz | 112 |
| 19 | ms06.cv-library.co.uk | 111 |
| 20 | ms07.cv-library.co.uk | 111 |
| 21 | ms08.cv-library.co.uk | 111 |
| 22 | mx1.ticketsinbound.com | 111 |
| 23 | mx2.ticketsinbound.com | 108 |
| 24 | mx-backup.serveriai.lt | 104 |
| 25 | mail.mpcloud.net | 99 |
Show rows 26 – 100
| # | MX target | Domains |
|---|---|---|
| 26 | mx.maxns.net | 98 |
| 27 | ~ | 91 |
| 28 | mx.aams4.jp | 90 |
| 29 | townsites.dnsmaster.net | 89 |
| 30 | mail-fr.securemail.pro | 88 |
| 31 | mail.vipmailservice.com | 88 |
| 32 | cloudmail.auto-vision.ru | 87 |
| 33 | mx-0.aams4.jp | 87 |
| 34 | mx-1.aams4.jp | 87 |
| 35 | amazon-smtp.amazon.com | 86 |
| 36 | mx1.netim.net | 84 |
| 37 | mx2.netim.net | 84 |
| 38 | mailforward.dnsv.jp | 80 |
| 39 | mailgw01.host.it | 80 |
| 40 | mx1.email-cluster.com | 80 |
| 41 | mx2.email-cluster.com | 80 |
| 42 | mx1-dk.centerasecurity.dk | 79 |
| 43 | mx2-dk.centerasecurity.dk | 79 |
| 44 | mailgw02.host.it | 79 |
| 45 | mx-01.mail-forwarder.io | 78 |
| 46 | failover1.email-cluster.com | 78 |
| 47 | mx.vshosting.eu | 78 |
| 48 | mx-02.mail-forwarder.io | 76 |
| 49 | mx3-dk.centerasecurity.dk | 73 |
| 50 | mx6.kvnbw.de | 73 |
| 51 | mx7.kvnbw.de | 73 |
| 52 | mx8.kvnbw.de | 73 |
| 53 | mx9.kvnbw.de | 73 |
| 54 | posta.mediacenter.hu | 71 |
| 55 | posta2.mediacenter.hu | 71 |
| 56 | posta4.mediacenter.hu | 71 |
| 57 | posta5.mediacenter.hu | 71 |
| 58 | mail.global.frontbridge.com | 71 |
| 59 | posta3.mediacenter.hu | 70 |
| 60 | q01es.mail.s-web.de | 70 |
| 61 | q02es.mail.s-web.de | 70 |
| 62 | r01es.mail.s-web.de | 70 |
| 63 | r02es.mail.s-web.de | 70 |
| 64 | email.webglobe.cz | 69 |
| 65 | email2.webglobe.cz | 69 |
| 66 | gmail22.gadmail.de | 69 |
| 67 | gmail23.gadmail.de | 69 |
| 68 | wmail22.gadmail.de | 69 |
| 69 | email3.webglobe.cz | 68 |
| 70 | email4.webglobe.cz | 68 |
| 71 | wmail23.gadmail.de | 68 |
| 72 | mx.sendcloud.org | 67 |
| 73 | mxa.expediagroup.com | 67 |
| 74 | mxb.expediagroup.com | 67 |
| 75 | smtp-avas.seeweb.it | 66 |
| 76 | mx1.oderland.com | 65 |
| 77 | mx2.oderland.com | 65 |
| 78 | mx01.muumuu-mail.com | 65 |
| 79 | rmail22.gadmail.de | 65 |
| 80 | rmail23.gadmail.de | 65 |
| 81 | mx1.mgn.net | 64 |
| 82 | omail22.gadmail.de | 64 |
| 83 | omail23.gadmail.de | 64 |
| 84 | mta.vshosting.eu | 63 |
| 85 | mx1.simplelogin.co | 63 |
| 86 | mx2.simplelogin.co | 63 |
| 87 | mx4.nameshield.net | 63 |
| 88 | mx2.mgn.net | 63 |
| 89 | mx3.mgn.net | 63 |
| 90 | void.blackhole.mx | 62 |
| 91 | mx1.daouoffice.com | 62 |
| 92 | mx1.alwaysdata.com | 62 |
| 93 | mx2.alwaysdata.com | 62 |
| 94 | smtp.faisco.cn | 61 |
| 95 | mail.bluetie.com | 61 |
| 96 | mx3.oderland.com | 61 |
| 97 | mx4.oderland.com | 61 |
| 98 | mx1.nepal.gov.np | 61 |
| 99 | d01es.mail.s-web.de | 61 |
| 100 | d02es.mail.s-web.de | 61 |
Unmatched SPF includes — top 100
What this block shows. The most popular SPF include:
targets that don't match any known ESP, mailbox-as-sender, or SaaS pattern yet. Same
feedback loop: top hits get added to dictionaries/esps.py or
dictionaries/saas_senders.py.
| # | SPF include | Domains |
|---|---|---|
| 1 | _spf.mail-neoserv.si | 137 |
| 2 | yunyou.top | 132 |
| 3 | _spf.lh.pl | 131 |
| 4 | spf.mailii.org | 131 |
| 5 | spf-bulk.axa.com | 126 |
| 6 | _spf.tld-mx.com | 118 |
| 7 | spf.w4ymail.at | 118 |
| 8 | spf.pitcom.net | 115 |
| 9 | spf.aams4.jp | 115 |
| 10 | _spf.exsilia.net | 113 |
| 11 | _spf.edhost.eu | 113 |
| 12 | _spf1-aws.recop.jp | 113 |
| 13 | relay.guzelhosting.com | 112 |
| 14 | _spf.armada.it | 111 |
| 15 | _spf.cv-library.co.uk | 111 |
| 16 | spf.host-ww.net | 109 |
| 17 | smtp-cluster.plusvps.com | 107 |
| 18 | spf.emailfilter.io | 105 |
| 19 | spf.mailcamp.nl | 105 |
| 20 | spf.shopserve.jp | 104 |
| 21 | mailii.org | 104 |
| 22 | _spf.abcp.ru | 104 |
| 23 | mfg.siteprotect.com | 103 |
| 24 | spf.boldem.cz | 103 |
| 25 | spf.v6send.net | 103 |
Show rows 26 – 100
| # | SPF include | Domains |
|---|---|---|
| 26 | mlrcloud.com | 103 |
| 27 | _spf.localservices.com.br | 102 |
| 28 | spf-2248456.jmsend.com | 102 |
| 29 | spf.cesky-hosting.cz | 102 |
| 30 | _spf.wpopt.net | 102 |
| 31 | spf.betrend.com | 101 |
| 32 | gateways.firstdata.com | 100 |
| 33 | relay.thundermail.uk | 100 |
| 34 | _spf.yourfilter.nl | 100 |
| 35 | spf.satorimail.net | 100 |
| 36 | dospf.simplepart.com | 100 |
| 37 | spf.mijndomeinhosting.nl | 99 |
| 38 | spf.spcloud.jp | 99 |
| 39 | _spf.sendnode.com | 98 |
| 40 | _spf.axa.com | 98 |
| 41 | send.k-crm.jp | 97 |
| 42 | spf.symplicity.com | 96 |
| 43 | amazon.com | 96 |
| 44 | _spf.octadesk.com | 96 |
| 45 | _pmta2.antevenio.com | 96 |
| 46 | mailing.eqs.com | 95 |
| 47 | _spf.academicworks.com | 95 |
| 48 | fmx.etius.jp | 95 |
| 49 | spf.host.it | 95 |
| 50 | _spf.presscloud.com | 94 |
| 51 | relay.email-cluster.com | 92 |
| 52 | _spf01.mykronos.com | 92 |
| 53 | _spf.aid.no | 92 |
| 54 | spf.ssmx.net | 91 |
| 55 | _spf.sent2email.com | 91 |
| 56 | spf.form.run | 91 |
| 57 | _spf.simpleviewinc.com | 91 |
| 58 | spf.qboxmail.com | 91 |
| 59 | verifymyfafsa.com | 90 |
| 60 | senders.mailmasterplus.net | 90 |
| 61 | spf.zoner.fi | 89 |
| 62 | spf.filteredmx.net | 89 |
| 63 | sender.zcsend.jp | 89 |
| 64 | spf.qb-feedback.com | 88 |
| 65 | _spf.shared-server.net | 88 |
| 66 | all._spf.ds.network | 88 |
| 67 | spf.protection.outlook | 87 |
| 68 | spf.esvacloud.com | 87 |
| 69 | _spf.eemsg.mail.mil | 87 |
| 70 | spf.w2solution.com | 87 |
| 71 | ofsys.com | 86 |
| 72 | eversrv.com | 86 |
| 73 | ciphr247.com | 86 |
| 74 | spf2.nlk2.smtps.jp | 86 |
| 75 | spf.redpoints.com | 86 |
| 76 | _spf.goskope.com | 85 |
| 77 | spf | 83 |
| 78 | _spf.newsautodoc.com | 83 |
| 79 | spf-us.appmail.granicusgovaccess.net | 83 |
| 80 | spf.chinaemail.cn | 83 |
| 81 | spf.protect.kvnbw.de | 82 |
| 82 | spf.sosafe.de | 82 |
| 83 | mailmailmail.net | 82 |
| 84 | spf.rpost.net | 82 |
| 85 | custmail.vdata.com | 81 |
| 86 | _spf-c.arukereso.hu | 81 |
| 87 | no-ip.com | 79 |
| 88 | spf.gansend.com | 79 |
| 89 | _spf.herodesk-mails.io | 79 |
| 90 | spfv.global-mail.cn | 79 |
| 91 | spf.sabre.com | 78 |
| 92 | universalspf.org | 78 |
| 93 | x.universalspf.org | 78 |
| 94 | eur.pb-dynmktge.com | 78 |
| 95 | spfref.jackhenry.com | 78 |
| 96 | support.gov.sg | 78 |
| 97 | _spf.zorgmail.nl | 78 |
| 98 | spf.ihs.com.tr | 78 |
| 99 | spf.postbox.yandexcloud.net | 77 |
| 100 | spf.cloud.simtechdev.us | 77 |
Methodology — how the numbers were produced
1. Data source
The dataset is the daily OpenINTEL forward-DNS Tranco snapshot
(University of Twente / SURFnet / SIDN Labs). OpenINTEL queries the entire
Tranco top-1M domain list
daily for MX, TXT, NS, A, AAAA, SOA, CAA, DNSSEC and other records, publishing the
results as Apache Parquet. For pre-2022 history we additionally use OpenINTEL's
alexa source (the legacy Alexa top-1M list, retired 2023).
Cite: Roland van Rijswijk-Deij et al., "A High-Performance, Scalable Infrastructure for Large-Scale Active DNS Measurements", IEEE JSAC 2016.
1b. Where the rest of the analysis lives
Six deep-dive pages are rebuilt by the same daily run and were previously
reachable only through the sitemap:
SPF health (final all qualifier, DNS-lookup
limit, record length) ·
Email security posture (MTA-STS, BIMI, TLS-RPT, DKIM
selectors) ·
SaaS via verification tokens ·
DNS/NS providers ·
Country × ESP ·
Infrastructure & TLS.
2. Sample & cadence
Each report covers a single date — OpenINTEL publishes snapshot D on D+1, so the current UTC date is never treated as an expected snapshot. Freshness means matching the latest date actually present in the OpenINTEL catalogue, typically ~700 k domains with MX records and ~620 k with SPF. The pipeline runs daily at 03:00 UTC, after the usual source-publication window; each daily run produces an HTML report, a JSON summary, an updated time-series, and incremental updates to the domain registry (§ 12). No sub-sampling.
3. Mailbox provider classification
For each domain we read its MX RRset and pick the record with the lowest
mx_preference as the primary mailbox host. The hostname of that
primary MX is matched against an open regex dictionary (dictionaries/mx_providers.py,
currently 328 patterns, hash below). Specific patterns (e.g. .mail.protection.outlook.com)
are tried first; generic fallbacks (mail.*, mx*.*) only after.
Domains whose MX matches no rule are kept as "Unknown / Other" — never dropped — and
exported in Unmatched MX targets for dictionary improvement.
4. ESP / SaaS / forwarder / gateway classification (SPF-based)
For each domain's apex SPF record (TXT starting with v=spf1) we extract every
include: and redirect= target and resolve them against open classification dictionaries (ESPs, mailbox-as-sender, anti-spam gateways, forwarders, SaaS senders, DMARC vendors, NS providers, verification tokens).
Resolution order: PURE_ESP → MAILBOX_AS_SENDER → GATEWAYS → FORWARDERS → bare-apex
substring fallback → SAAS_SENDERS substring iteration. Bare-apex derivation strips
leading _spf., _spf-eu., spf., mail.
prefixes from dict keys to catch subdomain variants
(e.g. _spf.m1.websupport.sk → matches websupport.sk).
Malformed includes (no dot, <4 chars) are filtered.
One domain may use several ESPs simultaneously, so ESP shares sum to more than 100% of SPF-publishing domains. Current SPF-include target coverage: 82.53%, recomputed from this snapshot rather than hard-coded.
Limitation: "flattened" SPF (where include chains were replaced with raw IP ranges to fit the 10-lookup limit) is not detectable from DNS alone — those domains appear ESP-less even when an ESP is in fact used.
5. DMARC (deep)
For each domain we query the _dmarc.<domain> TXT record. Records
starting with v=DMARC1 are parsed for:
p=(apex policy): none / quarantine / reject / invalidsp=(subdomain policy)pct=(rollout percentage)rua=aggregate-report destinations → classified into vendor buckets (Postmark DMARC, Valimail, dmarcian, URIports, EasyDMARC, Red Sift, Proofpoint EFD, Agari/Fortra, …) usingdictionaries/dmarc_vendors.py
A domain is counted as enforced if p=quarantine or
p=reject with pct=100 (or pct absent — defaults to
100).
6. SPF mechanics & health
For every SPF record we additionally extract:
- Final qualifier on the
allmechanism:-all(hard fail),~all(soft fail),?all(neutral),+all(pass-everything — broken / dangerous), or missing - DNS lookup count (
include:,redirect=,a:,mx:,exists:,ptr:) — each mechanism counts as 1 against the spec limit of 10. Records exceeding the limit return PermErr at recipients - Mechanism mix: include-only (modern), raw IP4/IP6 ranges only (legacy/flattened), mixed
- Record byte length: percentiles to flag fragmentation risk (>450 B)
7. Email security maturity
Adoption of modern mail-security TXT records, parsed from the same OpenINTEL parquet:
- MTA-STS: TXT at
_mta-sts.<domain>withv=STSv1— domain advertises required-TLS to its MX - BIMI: TXT at
default._bimi.<domain>withv=BIMI1— brand publishes a verified logo (requiresp=reject) - TLS-RPT (SMTP TLS Reporting): TXT at
_smtp._tls.<domain>withv=TLSRPTv1— domain monitors TLS-failure reports - DKIM selectors: where the OpenINTEL scan includes
*._domainkey.<domain>queries, well-known selectors (google,selector1/2,s1/s2,k1/k2/k3,mailo,mte1, …) are mapped to issuing ESPs
8. DNS provider classification
For each domain's NS RRset, every NS hostname is matched against a suffix dictionary
(dictionaries/ns_providers.py) with patterns for Cloudflare, AWS Route 53,
Azure DNS, Google Cloud DNS, GoDaddy, Akamai, NS1, UltraDNS, Yandex, DNSPod,
Aliyun, OVH, Hetzner, Gandi, registrars, and others. A domain is assigned to its
dominant NS provider; ties resolve to whichever pattern was matched first.
9. SaaS-via-verification-tokens
Many SaaS apps a domain is connected to never appear in SPF (because the SaaS doesn't
send mail FROM the customer domain). To recover this signal we parse apex TXT records for
verification tokens — google-site-verification=…, MS=…,
atlassian-domain-verification=…, stripe-verification=…, plus
149 other patterns in
dictionaries/verification_tokens.py. This produces a
complementary "SaaS density" metric and surfaces apps that the SPF-only view misses.
10. Email infrastructure modernity
Three additional TLS / IPv6 metrics:
- IPv6-on-MX: MX hostname has at least one AAAA record
- DANE / TLSA on MX: TLSA record at
_25._tcp.<mx_host>(where the parquet includes TLSA queries) - CAA: any
0 issue …/0 issuewild …record at apex; CAs aggregated into a market-share view (Let's Encrypt, DigiCert, Sectigo, …)
11. Cross-tabulations
- Country × ESP heatmap: top-15 ccTLDs × top-15 ESPs, cell = % of country's SPF-publishing domains using ESP X. Surfaces regional ESP champions (Brevo / FR, Unisender / RU, MailerLite / LT, Akna / BR, Shoptet / CZ).
- Mailbox × ESP combinations: stacked frequency of common stack pairings — published as Mailbox provider × sending platform.
12. Domain registry & identifiers
Every domain ever observed across snapshots is assigned a stable integer ID
in /var/openintel-cache/registry/domains.sqlite3 (currently
1 956 428 domains). Reports reference domains by ID rather than embedding
strings; clients resolve names from a single gzipped registry dump
(/email-stats/domains.csv.gz, 25.5 MB). This keeps per-report payloads
compact, enables fast set-operation diffs across snapshots, and gives every domain a
first-seen / last-seen timestamp.
13. Daily change-alerts feed
Each daily run computes a domain-level diff vs the previous scan and emits a
change-feed at /email-stats/alerts.html (also as JSON + Atom). Detected
events: ESP added/removed in SPF, DMARC policy upgrade/downgrade, primary-mailbox-provider
change, SPF strict→soft regression, MTA-STS / BIMI first publication. Severity tag is
good / bad / info.
14. Per-entity detail pages
The top-100 ESPs, top-100 SaaS senders and top-80 mailbox providers each have a dedicated
detail page at /email-stats/detail/<kind>/<slug>.html showing KPI
cards, a Chart.js sparkline (from history.json), TLD distribution and a
sample of customer domains.
15. Tier breakdown
Each domain is assigned a tier from its Tranco rank: top-1k / top-10k / top-100k / top-1M, plus unranked for domains measured in the snapshot but absent from the current list file (rotation). Published as Authentication by Tranco tier: SPF, DMARC enforcement and self-hosting per tier.
16. Reproducibility & data hygiene
Dictionary hashes for this run (sha256, first 12 hex):
compliance.py—76d502287abedmarc_vendors.py—8c195eb564fcesps.py—0f7a40a1f7d3mx_providers.py—c29c6e1b1f58ns_providers.py—cc4f43c6651fproviders_meta.py—5dc92db7869fsaas_meta.py—fe611e6e8a68saas_senders.py—1c5ebd9f7c09tld_regions.py—61e8bd3dcca8verification_tokens.py—6ba8313e55ab
Every published report includes the exact OpenINTEL date, dictionary file hashes, and counts of unmatched MX hosts and SPF includes — so any reader can verify or reproduce the figures. Raw OpenINTEL parquet is downloaded into a temporary cache and deleted after analysis; only aggregated, non-redistributable counts are kept long-term (per OpenINTEL data agreement). The domain registry stores names but no record-level content.
16b. Methodology changelog
Every change to a metric definition is recorded in
the methodology changelog and stamped into each
history point as methodology_version — so a step in a series can
always be attributed to a formula change rather than to reality.
17. Limitations to be aware of
- Tranco bias. Top-1M skews toward US/EU and global SaaS; ccTLD-only domains with low traffic may be under-represented. The alexa source used for pre-2022 history has a different composition and a different size: the alexa partition of 2022-04-01 contains 1 637 544 measured apex names against 1 087 498 in tranco on 2026-07-24, so absolute counts are not comparable across the 2022-08-11 boundary — only shares within a snapshot are.
- SPF flattening hides ESP identity (see § 4).
- CNAME chains on MX (e.g.
mail.example.com → mail.example.protection.outlook.com) are not unrolled — only the first MX target is matched. This biases a small share of domains toward "Unknown" when their MX is a CNAME to a known provider. - Vanity MX with white-label provider (Mimecast/Proofpoint customers using their own brand) is not detectable from DNS alone.
- DKIM enumeration is selector-based — only domains whose well-known selectors are scanned by OpenINTEL appear in the DKIM layer.
- Long-tail unmatched: this snapshot contains 81 940 unique unclassified SPF targets. The count is published as a measured coverage KPI rather than a fixed estimate; many are regional hosters, tenant-specific endpoints, malformed records, or single-domain infrastructure.
- Newly-added dictionary entries have no historical sparkline until ≥ 2 daily scans accumulate, since archived raw parquet is purged after parsing per the OpenINTEL data agreement.
Comments & corrections
Spotted a mis-classified MX target, missed ESP, or want to discuss a finding? We publish corrections in the next daily snapshot.
Send feedback to support@live-direct-marketing.onlineInline comments coming soon. For now, email is the fastest path — you'll see your fix reflected in tomorrow's run.
For press and analysts
What this block shows. The dataset is rebuilt every day and published under CC BY 4.0 — use the numbers, the charts and the PDF in your material, with a link back. If you need a cut that is not on this page, ask: we run it against the same snapshot and send it over.
Historical reports
Daily snapshots — last 90 days kept fully, older ones thinned to one point per month. Points marked partial are incomplete days at the source and are excluded from deltas and trends.
217 snapshots since 2016-01-22 — open the list
Generated automatically from OpenINTEL Tranco snapshot 2026-09-02. Aggregates only — raw OpenINTEL data is deleted after analysis per their data agreement.
Last build: 2026-09-04T03:45:11Z.