Observed MX, SPF and DMARC infrastructure for 671,693 domains of the Tranco top-1M, rebuilt daily from OpenINTEL measurements. Snapshot 2026-07-25.
Domain directory Providers Historical snapshots JSON API Run inbox placement test
What you're looking at. Headline numbers for the analysed Tranco
snapshot: how many domains publish each kind of email-related DNS record, and what share
of DMARC publishers actually enforce their policy (quarantine/reject).
Higher MX vs SPF gap = more domains receive mail than authorise sending; higher SPF vs
DMARC gap = SPF adopted but no policy/feedback enforcement yet.
rua= address and therefore receive no aggregate reports at all — and 117 384 of them (25.04% of all DMARC publishers) pair that with p=none, so the record enforces nothing and reports nowhere. #Each statement is recomputed daily from the full dataset and published under CC BY 4.0 — reuse it, cite "Live Direct Marketing, Email infrastructure of the Tranco top-1M" with a link. Machine-readable version: api/latest.json · llms.txt. Looking for one domain? Domain lookup — mailbox provider, ESPs and DMARC policy of any top-10k website.
Coverage is recomputed from every snapshot. MX vendor attribution excludes
self-hosted domains (22.79%); SPF coverage counts each
distinct include:/redirect= target once per domain. Fully classified
SPF stacks: 72.37% of domains
that delegate through at least one include.
Reading the long series: the vertical dashed line marks the change of the underlying list — OpenINTEL alexa (2016-01-22 … 2022-08-10, ~1.6 M measured names) and tranco (from 2022-08-11, ~1.1 M). Absolute counts across that line are not comparable: they describe different measured populations. Gaps in a line are real gaps — no interpolation is drawn. DMARC series start on 2022-08-11 because the alexa partitions contain no _dmarc queries at all; earlier points are empty, not zero. Snapshots flagged partial (an incomplete day at the source) are excluded from deltas and trends.
Raw baseline indicators computed from the daily time-series — published as-is, no editorial filtering. Updated with every daily scan (latest: 2026-07-25).
| Type | Provider | Share | Δ 30d |
|---|---|---|---|
| Mailbox | Google Workspace | 21.83% | +0.23 pp |
| Mailbox | Microsoft 365 | 16.87% | +0.21 pp |
| Mailbox | 1&1 IONOS | 0.64% | +0.11 pp |
| Mailbox | Hostinger | 1.19% | +0.06 pp |
| Mailbox | Cloudflare Email Routing | 1.63% | +0.05 pp |
| Mailbox | Generic / unmatched (mx*.*) | 2.55% | -0.18 pp |
| Mailbox | Self-Hosted | 22.79% | -0.05 pp |
| ESP | Zendesk | 3.81% | -0.05 pp |
| ESP | HubSpot | 3.17% | -0.05 pp |
| ESP | Mimecast | 1.41% | -0.04 pp |
Domain-level events (ESP switches, DMARC upgrades/downgrades, MTA-STS/BIMI first publications): daily change-feed · Atom · JSON. Machine-readable access for AI agents & pipelines: api/latest.json · llms.txt.
Need a signal we don't publish? Per-domain watchlists, competitor tracking, custom thresholds, webhooks — these are cheap for us to add. Write to support@live-direct-marketing.online and tell us what to watch.
What this block shows. Where each domain hosts incoming mail —
derived from its primary MX record (lowest mx_preference). This is the
receiving side of email: Google Workspace, Microsoft 365, Zoho, on-prem Exchange, etc.
"Generic / unmatched" buckets are common mail.* / mx*.* hostnames
we couldn't attribute to a specific provider; "Unknown / Other" is everything else.
Note: Cloudflare Email Routing also appears in the ESP table below — that is the
same service observed through two different record types (MX here, SPF there), not a
double count of domains.
| # | Mailbox provider | Domains | Share of MX-having domains |
|---|---|---|---|
| 1 | Self-Hosted → | 153 105 | 22.79% |
| 2 | Google Workspace → | 146 623 | 21.83% |
| 3 | Microsoft 365 → | 113 317 | 16.87% |
| 4 | Unknown / Other → | 45 664 | 6.80% |
| 5 | Generic / unmatched (mx*.*) → | 17 106 | 2.55% |
| 6 | Proofpoint → | 12 785 | 1.90% |
| 7 | Generic / unmatched (mail.*) → | 11 827 | 1.76% |
| 8 | Yandex 360 → | 11 188 | 1.67% |
| 9 | Cloudflare Email Routing → | 10 925 | 1.63% |
| 10 | Mimecast → | 10 218 | 1.52% |
| # | Mailbox provider | Domains | Share of MX-having domains |
|---|---|---|---|
| 11 | Hostinger → | 7 960 | 1.19% |
| 12 | Zoho Mail → | 6 963 | 1.04% |
| 13 | Namecheap Email Forwarding → | 6 759 | 1.01% |
| 14 | QQ Mail (Tencent) → | 5 644 | 0.84% |
| 15 | GoDaddy → | 5 129 | 0.76% |
| 16 | OVH Mail → | 4 855 | 0.72% |
| 17 | Amazon WorkMail → | 4 696 | 0.70% |
| 18 | 1&1 IONOS → | 4 266 | 0.64% |
| 19 | Mail.ru for Business → | 3 643 | 0.54% |
| 20 | Barracuda → | 3 595 | 0.54% |
| 21 | Proofpoint Essentials → | 2 943 | 0.44% |
| 22 | Jellyfish (Namecheap) → | 2 832 | 0.42% |
| 23 | SpamExperts (SolarWinds) → | 2 722 | 0.41% |
| 24 | Cisco IronPort → | 2 619 | 0.39% |
| 25 | Beget (RU) → | 2 429 | 0.36% |
| 26 | Mailgun (inbound) → | 2 320 | 0.35% |
| 27 | Rackspace Email → | 2 279 | 0.34% |
| 28 | Alibaba Mail (China) → | 2 129 | 0.32% |
| 29 | Zoho Mail (EU) → | 1 840 | 0.27% |
| 30 | Hosted Email (Rackspace/IONOS) → | 1 738 | 0.26% |
Reading the long series: the vertical dashed line marks the change of the underlying list — OpenINTEL alexa (2016-01-22 … 2022-08-10, ~1.6 M measured names) and tranco (from 2022-08-11, ~1.1 M). Absolute counts across that line are not comparable: they describe different measured populations. Gaps in a line are real gaps — no interpolation is drawn. DMARC series start on 2022-08-11 because the alexa partitions contain no _dmarc queries at all; earlier points are empty, not zero. Snapshots flagged partial (an incomplete day at the source) are excluded from deltas and trends.
What this block shows. The slice of domains whose mailbox cannot be attributed to a named provider — regional hosters, self-built Postfix/Exim, corporate gateways, niche ESPs. Researchers ask for this specifically because it captures the deliverability reality outside the Google / Microsoft monoculture. The detailed report drills down into Top-1000 most common unmatched hosts, 100 hand-picked curiosities (longest one-off names) and a TLD breakdown.
The same metrics cut by list position. Enforcement is a function of how big the site is: the gradient from the top of the list to the tail is the finding, not the average. "Not in current list" = domains measured in this snapshot that are absent from today's Tranco file (list rotation).
| # | Tier | Domains with MX | SPF | DMARC enforced | Self-hosted |
|---|---|---|---|---|---|
| 1 | Tranco top-1k | 694 | 93.66% | 73.05% | 11.67% |
| 2 | top-1k … 10k | 6 509 | 92.89% | 56.46% | 14.30% |
| 3 | top-10k … 100k | 64 804 | 91.17% | 43.34% | 17.65% |
| 4 | top-100k … 1M | 481 059 | 89.91% | 29.81% | 22.80% |
| 5 | not in current list | 118 627 | 87.75% | 19.10% | 26.09% |
What this block shows. Outbound mass-mailing platforms each domain authorises in its SPF record — the marketing-automation, transactional-email and customer-engagement layer (SendGrid, Mailchimp, Mailgun, Klaviyo, HubSpot, Salesforce Marketing Cloud, etc.). One domain can use several ESPs, so percentages sum to more than 100% of SPF-publishing domains.
| # | ESP | Domains | Share of SPF-publishing domains |
|---|---|---|---|
| 1 | Amazon SES → | 39 095 | 6.16% |
| 2 | SendGrid (Twilio) → | 30 049 | 4.74% |
| 3 | Mailgun → | 26 021 | 4.10% |
| 4 | Zendesk → | 24 194 | 3.81% |
| 5 | Mailchimp → | 23 315 | 3.68% |
| 6 | Mandrill → | 21 223 | 3.35% |
| 7 | HubSpot → | 20 099 | 3.17% |
| 8 | Salesforce → | 16 492 | 2.60% |
| 9 | Mailjet (Sinch) → | 13 485 | 2.13% |
| 10 | Cloudflare Email Routing → | 11 530 | 1.82% |
| # | ESP | Domains | Share of SPF-publishing domains |
|---|---|---|---|
| 11 | Brevo (ex-Sendinblue) → | 9 151 | 1.44% |
| 12 | Mimecast → | 8 939 | 1.41% |
| 13 | MailerSend → | 8 165 | 1.29% |
| 14 | Namecheap Forwarding → | 7 030 | 1.11% |
| 15 | MailChannels → | 6 815 | 1.07% |
| 16 | Proofpoint → | 5 932 | 0.94% |
| 17 | Elastic Email → | 4 507 | 0.71% |
| 18 | Constant Contact → | 3 694 | 0.58% |
| 19 | Unisender (RU) → | 3 693 | 0.58% |
| 20 | Campaign Monitor → | 3 565 | 0.56% |
| 21 | Marketo (Adobe) → | 3 299 | 0.52% |
| 22 | Zoho Campaigns → | 3 282 | 0.52% |
| 23 | Emsd1 (transactional) → | 3 033 | 0.48% |
| 24 | Postmark → | 2 989 | 0.47% |
| 25 | SendPulse → | 2 940 | 0.46% |
| 26 | Exclaimer (signatures) → | 2 728 | 0.43% |
| 27 | Zoho ZeptoMail → | 2 682 | 0.42% |
| 28 | SparkPost → | 2 679 | 0.42% |
| 29 | Help Scout → | 2 317 | 0.37% |
| 30 | Salesforce Marketing Cloud → | 2 227 | 0.35% |
Reading the long series: the vertical dashed line marks the change of the underlying list — OpenINTEL alexa (2016-01-22 … 2022-08-10, ~1.6 M measured names) and tranco (from 2022-08-11, ~1.1 M). Absolute counts across that line are not comparable: they describe different measured populations. Gaps in a line are real gaps — no interpolation is drawn. DMARC series start on 2022-08-11 because the alexa partitions contain no _dmarc queries at all; earlier points are empty, not zero. Snapshots flagged partial (an incomplete day at the source) are excluded from deltas and trends.
What this block shows. SaaS apps that send mail FROM a
customer's domain on the customer's behalf — productivity, support, payments, HR,
e-commerce and other business apps appearing as include: targets in the
customer's SPF. Distinct from ESPs (mass-mailing platforms) and mailbox providers
(where the inbox lives).
| # | SaaS app | Domains | Share of SPF-publishing domains |
|---|---|---|---|
| 1 | Shopify → | 5 541 | 0.87% |
| 2 | Pardot (Salesforce) → | 4 962 | 0.78% |
| 3 | CodeTwo Email Signatures 365 → | 4 522 | 0.71% |
| 4 | KnowBe4 → | 3 553 | 0.56% |
| 5 | Statuspage (Atlassian) → | 2 103 | 0.33% |
| 6 | Trustpilot → | 1 891 | 0.30% |
| 7 | Firebase (Google) → | 1 861 | 0.29% |
| 8 | Atlassian (Jira/Confluence) → | 1 851 | 0.29% |
| 9 | BigCommerce → | 1 545 | 0.24% |
| 10 | Lark / Feishu → | 1 316 | 0.21% |
| # | SaaS app | Domains | Share of SPF-publishing domains |
|---|---|---|---|
| 11 | Sage Intacct → | 1 157 | 0.18% |
| 12 | NetSuite (Oracle) → | 1 135 | 0.18% |
| 13 | Qualtrics → | 1 103 | 0.17% |
| 14 | Oracle Cloud Email → | 1 092 | 0.17% |
| 15 | WordPress.com / WP Cloud → | 982 | 0.15% |
| 16 | SAP SuccessFactors → | 973 | 0.15% |
| 17 | Docebo (LMS) → | 932 | 0.15% |
| 18 | Oracle Cloud → | 847 | 0.13% |
| 19 | One.com (DK hosting) → | 802 | 0.13% |
| 20 | Zoho Books → | 716 | 0.11% |
| 21 | AFAS → | 671 | 0.11% |
| 22 | Greenhouse → | 625 | 0.10% |
| 23 | PayPal Braintree → | 587 | 0.09% |
| 24 | ClickDimensions → | 575 | 0.09% |
| 25 | UKG / UltiPro → | 556 | 0.09% |
| 26 | Autotask (ConnectWise) → | 485 | 0.08% |
| 27 | FormAssembly → | 459 | 0.07% |
| 28 | TOPdesk → | 458 | 0.07% |
| 29 | Freshservice (Freshworks) → | 446 | 0.07% |
| 30 | ConnectWise → | 444 | 0.07% |
Reading the long series: the vertical dashed line marks the change of the underlying list — OpenINTEL alexa (2016-01-22 … 2022-08-10, ~1.6 M measured names) and tranco (from 2022-08-11, ~1.1 M). Absolute counts across that line are not comparable: they describe different measured populations. Gaps in a line are real gaps — no interpolation is drawn. DMARC series start on 2022-08-11 because the alexa partitions contain no _dmarc queries at all; earlier points are empty, not zero. Snapshots flagged partial (an incomplete day at the source) are excluded from deltas and trends.
What this block shows. The policy each DMARC-publishing domain
advertises at _dmarc.<domain>: none = monitor only,
quarantine = mark as spam on fail, reject = drop on fail,
invalid = a syntactically broken record. "Enforced %" treats only
quarantine / reject with pct=100 as actually
enforcing.
Reading the long series: the vertical dashed line marks the change of the underlying list — OpenINTEL alexa (2016-01-22 … 2022-08-10, ~1.6 M measured names) and tranco (from 2022-08-11, ~1.1 M). Absolute counts across that line are not comparable: they describe different measured populations. Gaps in a line are real gaps — no interpolation is drawn. DMARC series start on 2022-08-11 because the alexa partitions contain no _dmarc queries at all; earlier points are empty, not zero. Snapshots flagged partial (an incomplete day at the source) are excluded from deltas and trends.
Reading the long series: the vertical dashed line marks the change of the underlying list — OpenINTEL alexa (2016-01-22 … 2022-08-10, ~1.6 M measured names) and tranco (from 2022-08-11, ~1.1 M). Absolute counts across that line are not comparable: they describe different measured populations. Gaps in a line are real gaps — no interpolation is drawn. DMARC series start on 2022-08-11 because the alexa partitions contain no _dmarc queries at all; earlier points are empty, not zero. Snapshots flagged partial (an incomplete day at the source) are excluded from deltas and trends.
A three-way split instead of the usual enforced/not-enforced binary.
Enforcing — p=quarantine or p=reject.
Monitoring — p=none with a working rua=
address: a legitimate rollout phase, someone is reading the reports.
Inert — p=none with no reporting address at all:
the record enforces nothing and reports nowhere.
Maturity split of 468 749 DMARC-publishing domains:
49.31% enforcing,
25.61% monitoring,
25.04% inert.
Under DMARCbis (RFC 9989/9990/9991) the pct= tag no longer exists, so the
same snapshot yields 49.31% enforcing
against 46.95% under RFC 7489 — both are published, the
RFC 7489 figure keeps the 2016 series continuous.
DMARCbis adoption is still marginal: 249 domains
(0.05%) publish np=,
63 publish psd=.
960 records carry a rua= tag that
parses to no usable address at all.
| # | DMARC reporting destination | Domains | Share of DMARC publishers |
|---|---|---|---|
| 1 | Self-hosted / Other | 216 885 | 46.27% |
| 2 | Cloudflare DMARC | 27 249 | 5.81% |
| 3 | Valimail | 14 399 | 3.07% |
| 4 | Proofpoint EFD | 12 709 | 2.71% |
| 5 | Brevo (ex-Sendinblue) | 12 492 | 2.66% |
| 6 | dmarcian | 9 908 | 2.11% |
| 7 | Postmark DMARC | 7 461 | 1.59% |
| 8 | DMARC Analyzer | 7 005 | 1.49% |
| 9 | DMARC Advisor | 3 227 | 0.69% |
| 10 | DMARC Digests | 2 914 | 0.62% |
| # | DMARC reporting destination | Domains | Share of DMARC publishers |
|---|---|---|---|
| 11 | PowerDMARC | 2 450 | 0.52% |
| 12 | Agari (Fortra) | 2 312 | 0.49% |
| 13 | URIports | 2 174 | 0.46% |
| 14 | DMARCLY | 1 988 | 0.42% |
| 15 | Barracuda | 1 573 | 0.34% |
| 16 | Google Workspace | 932 | 0.20% |
| 17 | EasyDMARC | 854 | 0.18% |
| 18 | MailHardener | 731 | 0.16% |
| 19 | Red Sift OnDMARC | 579 | 0.12% |
| 20 | Cisco Secure Email | 436 | 0.09% |
| 21 | Validity (Return Path) | 317 | 0.07% |
| 22 | Microsoft 365 | 301 | 0.06% |
| 23 | Netcraft | 290 | 0.06% |
| 24 | TDMARC | 227 | 0.05% |
| 25 | MXToolbox | 44 | 0.01% |
Which sending platforms sit on top of which inbound stack. Cell = domains whose primary MX belongs to that mailbox provider and whose SPF authorises that ESP; the percentage is of that provider's domains. A domain may use several ESPs, so rows do not sum to 100%.
| Mailbox provider | Amazon SES | SendGrid (Twilio) | Zendesk | Mailchimp | Mailgun | HubSpot | Mandrill | Salesforce | Cloudflare Email Routing | Mailjet (Sinch) |
|---|---|---|---|---|---|---|---|---|---|---|
| Self-Hosted | 2 753 1.80% | 1 481 0.97% | 776 0.51% | 1 424 0.93% | 1 612 1.05% | 402 0.26% | 1 191 0.78% | 387 0.25% | 105 0.07% | 1 269 0.83% |
| Google Workspace | 14 707 10.03% | 11 845 8.08% | 11 269 7.69% | 9 284 6.33% | 9 881 6.74% | 9 782 6.67% | 8 623 5.88% | 4 314 2.94% | 324 0.22% | 3 546 2.42% |
| Microsoft 365 | 9 746 8.60% | 9 426 8.32% | 7 038 6.21% | 7 507 6.62% | 6 435 5.68% | 6 564 5.79% | 6 666 5.88% | 7 201 6.35% | 49 0.04% | 4 204 3.71% |
| Proofpoint | 835 6.53% | 687 5.37% | 728 5.69% | 454 3.55% | 335 2.62% | 465 3.64% | 497 3.89% | 1 101 8.61% | 1 0.01% | 248 1.94% |
| Yandex 360 | 162 1.45% | 39 0.35% | 29 0.26% | 72 0.64% | 214 1.91% | 2 0.02% | 73 0.65% | 1 0.01% | 8 0.07% | 30 0.27% |
| Cloudflare Email Routing | 227 2.08% | 75 0.69% | 74 0.68% | 29 0.27% | 133 1.22% | 13 0.12% | 18 0.16% | 6 0.05% | 10 687 97.82% | 97 0.89% |
| Mimecast | 1 022 10.00% | 1 063 10.40% | 791 7.74% | 703 6.88% | 542 5.30% | 828 8.10% | 653 6.39% | 1 192 11.67% | 0 0.00% | 199 1.95% |
| Hostinger | 42 0.53% | 38 0.48% | 8 0.10% | 6 0.08% | 49 0.62% | 4 0.05% | 6 0.08% | 0 0.00% | 7 0.09% | 27 0.34% |
| Zoho Mail | 405 5.82% | 179 2.57% | 93 1.34% | 123 1.77% | 317 4.55% | 19 0.27% | 105 1.51% | 3 0.04% | 44 0.63% | 103 1.48% |
| Namecheap Email Forwarding | 14 0.21% | 10 0.15% | 4 0.06% | 2 0.03% | 19 0.28% | 0 0.00% | 6 0.09% | 0 0.00% | 3 0.04% | 9 0.13% |
The literal record string copied verbatim from DNS — useful to spot copy-pasted
"starter" policies and identify reporting endpoints (the rua= /
ruf= tags) shared across many domains.
| # | DMARC record | Domains |
|---|---|---|
| 1 | v=DMARC1; p=none; | 58 997 |
| 2 | v=DMARC1; p=none | 33 310 |
| 3 | v=DMARC1; p=none; rua=mailto:rua@dmarc.brevo.com | 9 171 |
| 4 | v=DMARC1; p=quarantine; | 5 096 |
| 5 | v=DMARC1; p=quarantine | 4 085 |
| 6 | v=DMARC1; p=reject; | 3 949 |
| 7 | v=DMARC1;p=none; | 3 809 |
| 8 | v=DMARC1; p=quarantine; adkim=r; aspf=r; rua=mailto:dmarc_rua@onsecureserver.net; | 3 620 |
| 9 | v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com | 3 159 |
| 10 | v=DMARC1; p=quarantine; adkim=s; aspf=s | 3 076 |
| 11 | v=DMARC1; p=reject | 2 918 |
| 12 | v=DMARC1; p=none; aspf=r; adkim=r; | 2 432 |
| 13 | v=DMARC1; p=quarantine; pct=100 | 2 402 |
| 14 | v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s; | 2 144 |
| 15 | v=DMARC1; p=none; sp=none; rua=mailto:dmarc@mailinblue.com!10m; ruf=mailto:dmarc@mailinblue.com!10m; rf=afrf; pct=100; ri=86400 | 2 123 |
| 16 | v=DMARC1;p=none | 1 824 |
| 17 | v=DMARC1; p=none; aspf=r; sp=none | 1 766 |
| 18 | v=DMARC1; p=reject; sp=reject; rua=mailto:dmarc.report@axa.com; | 1 556 |
| 19 | v=DMARC1; p=none; adkim=r; aspf=r; | 1 556 |
| 20 | v=DMARC1; p=reject; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com; | 1 480 |
| 21 | v=DMARC1;p=quarantine;pct=100;fo=1 | 1 274 |
| 22 | v=DMARC1;p=reject; | 1 273 |
| 23 | v=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.email | 1 266 |
| 24 | v=DMARC1; p=none; rua=mailto:dmarc_agg@vali.email | 1 263 |
| 25 | v=DMARC1;p=none;sp=none;adkim=r;aspf=r;pct=100;fo=0;rf=afrf;ri=86400 | 1 247 |
| # | DMARC record | Domains |
|---|---|---|
| 26 | v=DMARC1; p=none; sp=none | 1 070 |
| 27 | v=DMARC1; p=none; sp=none; | 1 039 |
| 28 | v=DMARC1; p=reject; adkim=r; aspf=r; rua=mailto:dmarc_rua@onsecureserver.net; | 1 004 |
| 29 | v=DMARC1; p=none; rua=mailto:dmarc_agg@vali.email; | 982 |
| 30 | v=DMARC1; p=reject; rua=mailto:report@dmarc.amazon.com; ruf=mailto:report@dmarc.amazon.com | 890 |
| 31 | v=DMARC1; p=none; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com | 888 |
| 32 | v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s | 824 |
| 33 | v=DMARC1; p=quarantine; rua=mailto:dmarc_agg@vali.email | 762 |
| 34 | v=DMARC1; p=none; pct=100 | 737 |
| 35 | v=DMARC1; p=quarantine; fo=1; ruf=mailto:dmarc@qiye.163.com; rua=mailto:dmarc_report@qiye.163.com | 736 |
| 36 | v=DMARC1; p=reject; pct=100 | 735 |
| 37 | v=DMARC1;p=quarantine;sp=none;adkim=r;aspf=r;pct=100;fo=0;rf=afrf;ri=86400 | 692 |
| 38 | v=DMARC1; p=reject; rua=mailto:dmarc_rua@onsecureserver.net; adkim=r; aspf=r; | 686 |
| 39 | v=DMARC1; p=none; fo=1; ruf=mailto:dmarc@qiye.163.com; rua=mailto:dmarc_report@qiye.163.com | 674 |
| 40 | v=DMARC1; p=reject; fo=1; ri=3600; rua=mailto:ewai10d2@ag.eu.dmarcian.com; ruf=mailto:ewai10d2@fr.eu.dmarcian.com | 640 |
| 41 | v=DMARC1; p=reject; rua=mailto:mailauth-reports@google.com | 614 |
| 42 | v=DMARC1; p=none; sp=none; rf=afrf; pct=100; ri=86400 | 560 |
| 43 | v=DMARC1; p=quarantine; pct=100; | 559 |
| 44 | v=DMARC1;p=quarantine | 526 |
| 45 | v=DMARC1; p=quarantine; rua=mailto:dmarc_agg@vali.email; | 523 |
| 46 | v=DMARC1; p=none; rua=mailto:mailauth-reports@qq.com | 520 |
| 47 | v=DMARC1; p=reject; pct=100; | 464 |
| 48 | v=DMARC1; p=reject; rua=mailto:dmarc_agg@vali.email; | 448 |
| 49 | v=DMARC1;p=reject;sp=reject;adkim=s;aspf=s | 433 |
| 50 | v=DMARC1; p=none; sp=none; adkim=r; aspf=r | 396 |
| 51 | v=DMARC1; p=none; adkim=r; aspf=r | 391 |
| 52 | v=DMARC1; p=none; pct=100; | 368 |
| 53 | v=DMARC1; p=reject; adkim=s; aspf=s; | 367 |
| 54 | v=DMARC1; p=reject; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com; fo=1 | 349 |
| 55 | v=DMARC1; p=reject; adkim=s; aspf=s | 330 |
| 56 | v=DMARC1;p=reject | 329 |
| 57 | v=DMARC1 | 328 |
| 58 | v=DMARC1;p=reject;fo=1;rua=mailto:dmarc_rua@emaildefense.proofpoint.com;ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com | 323 |
| 59 | v=DMARC1;p=quarantine; | 320 |
| 60 | v=DMARC1; p=none; aspf=r; adkim=r | 311 |
| 61 | v=DMARC1; p=reject; sp=none; rf=afrf; pct=100; ri=86400 | 310 |
| 62 | v=DMARC1; p=none; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com; | 310 |
| 63 | v=DMARC1; p=none; fo=1 | 310 |
| 64 | v=DMARC1; p=reject; sp=reject; pct=100; fo=1; ri=3600; rua=mailto:dmarcrecord@gmail.com; ruf=mailto:dmarcrecord@gmail.com; | 305 |
| 65 | v=DMARC1; p=none; rua=mailto:dmarc@smtp.mailtrap.live; ruf=mailto:dmarc@smtp.mailtrap.live; rf=afrf; pct=100 | 300 |
| 66 | v=DMARC1; p=reject; rua=mailto:tnoff9hr@ag.eu.dmarcadvisor.com; aspf=s; adkim=s; | 287 |
| 67 | v=DMARC1;p=none;sp=none;pct=50;adkim=r;aspf=r; | 276 |
| 68 | v=DMARC1; p=reject; rua=mailto:zsrbf6su@ag.eu.dmarcadvisor.com; | 272 |
| 69 | v=DMARC1; p=none; rua=mailto:mailauth-reports@google.com | 269 |
| 70 | v=DMARC1;p=reject;sp=none;adkim=r;aspf=r;pct=100;fo=0;rf=afrf;ri=86400 | 266 |
| 71 | v=DMARC1;p=none;pct=100 | 265 |
| 72 | v=DMARC1; p=quarantine; rua=mailto:rua@dmarc.brevo.com | 254 |
| 73 | v=DMARC1; p=reject; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com;fo=1 | 248 |
| 74 | v=DMARC1;p=none;rua=mailto:dmarc_report@service.aliyun.com | 244 |
| 75 | v=DMARC1; p=quarantine; adkim=s; aspf=s; | 237 |
| 76 | v=DMARC1; p=none; rua=mailto:rua-mpse@mpub.ne.jp | 233 |
| 77 | v=DMARC1; p=quarantine; adkim=r; aspf=r | 231 |
| 78 | v=DMARC1; p=reject; rua=mailto:dmarc_rua@onsecureserver.net; | 220 |
| 79 | v=DMARC1; p=none; rua=mailto:dmarc.rua@edrone.app; ruf=mailto:dmarc.ruf@edrone.app | 217 |
| 80 | v=DMARC1; p=none; sp=none; rua=mailto:dmarc-raports@dhosting.pl | 211 |
| 81 | v=DMARC1; p=reject; rua=mailto:zicaptxt@ag.dmarcian.com; | 204 |
| 82 | v=DMARC1; p=quarantine; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com | 202 |
| 83 | v=DMARC1; p=none; rua=mailto:dmarc@reporting.unisender.com | 201 |
| 84 | v=DMARC1; p=reject; fo=1; ri=3600; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com | 200 |
| 85 | v=DMARC1; p=reject; sp=reject | 188 |
| 86 | v=DMARC1;p=none;rua=mailto:rua@dmarc.brevo.com | 188 |
| 87 | v=DMARC1; p=quarantine; pct=100; adkim=r; aspf=r | 186 |
| 88 | v=DMARC1; p=quarantine; pct=100; rua=mailto:61e7fc8674b33@ag.eu.dmarcly.com; ruf=mailto:61e7fc8674b33@fo.eu.dmarcly.com; sp=quarantine; fo=1; | 185 |
| 89 | v=DMARC1;p=reject;pct=100; | 184 |
| 90 | v=DMARC1; p=quarantine; fo=1; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com; | 184 |
| 91 | v=DMARC1; p=none; pct=100; rua=mailto:dmarc@fbl.optin.com; | 183 |
| 92 | v=DMARC1; p=quarantine; fo=1 | 175 |
| 93 | v=DMARC1; p=reject; rua=mailto:2ynhg3yt@ag.dmarcian.com | 175 |
| 94 | v=DMARC1; p=quarantine; adkim=r; aspf=r; | 172 |
| 95 | v=DMARC1;p=none;pct=100;aspf=r;adkim=r; | 170 |
| 96 | v=DMARC1; p=reject; sp=reject; | 170 |
| 97 | v=DMARC1;p=none;sp=none;adkim=r;aspf=r;pct=100 | 169 |
| 98 | v=DMARC1; p=quarantine; sp=none; pct=100; ri=86400 | 168 |
| 99 | v=DMARC1; p=reject; rua=mailto:a@dmarcreports.facebook.com; | 165 |
| 100 | v=DMARC1; p=reject; pct=100; adkim=s; aspf=s | 164 |
What this block shows. The most popular MX hostnames our dictionary
does not yet attribute to a named mailbox provider. Public list — these feed
back into dictionaries/mx_providers.py for the next iteration so coverage
keeps improving.
| # | MX target | Domains |
|---|---|---|
| 1 | localhost | 497 |
| 2 | mx.services | 288 |
| 3 | 241 | |
| 4 | zonemx.eu | 199 |
| 5 | mail1.sbnation.com | 167 |
| 6 | mail.parktons.com | 166 |
| 7 | alltheemails.com | 147 |
| 8 | mx.email-messaging.com | 143 |
| 9 | mail.autoline.com.ua | 141 |
| 10 | mx2.z-ns.net | 140 |
| 11 | mail2.recop.jp | 132 |
| 12 | mx1.ticketsinbound.com | 127 |
| 13 | lbmx.bcc.gov.bd | 127 |
| 14 | mxi.alpha-prm.jp | 126 |
| 15 | ~ | 125 |
| 16 | mx2.ticketsinbound.com | 123 |
| 17 | s.mail.dcsaas.net | 113 |
| 18 | mx1d10.thinline.cz | 111 |
| 19 | mx1b20.thinline.cz | 111 |
| 20 | cloudmail.auto-vision.ru | 99 |
| 21 | mx.maxns.net | 90 |
| 22 | mx-backup.serveriai.lt | 90 |
| 23 | mailforward.dnsv.jp | 88 |
| 24 | mx1-dk.centerasecurity.dk | 85 |
| 25 | mx2-dk.centerasecurity.dk | 85 |
| # | MX target | Domains |
|---|---|---|
| 26 | amazon-smtp.amazon.com | 85 |
| 27 | mail.pickelhost.com | 83 |
| 28 | mx3-dk.centerasecurity.dk | 79 |
| 29 | mx.aams4.jp | 78 |
| 30 | mx-01.mail-forwarder.io | 77 |
| 31 | mail.global.frontbridge.com | 76 |
| 32 | mx.vshosting.eu | 76 |
| 33 | mx1.netim.net | 75 |
| 34 | mx2.netim.net | 75 |
| 35 | mx-0.aams4.jp | 75 |
| 36 | mx-1.aams4.jp | 75 |
| 37 | mx-02.mail-forwarder.io | 75 |
| 38 | void.blackhole.mx | 74 |
| 39 | mx1.email-cluster.com | 73 |
| 40 | mx2.email-cluster.com | 73 |
| 41 | mail-fr.securemail.pro | 73 |
| 42 | mx.sendcloud.org | 71 |
| 43 | mail.mpcloud.net | 71 |
| 44 | email.webglobe.cz | 70 |
| 45 | email2.webglobe.cz | 70 |
| 46 | failover1.email-cluster.com | 70 |
| 47 | q01es.mail.s-web.de | 70 |
| 48 | q02es.mail.s-web.de | 70 |
| 49 | r01es.mail.s-web.de | 70 |
| 50 | r02es.mail.s-web.de | 70 |
| 51 | email3.webglobe.cz | 69 |
| 52 | email4.webglobe.cz | 69 |
| 53 | mx.spamfilter.io | 68 |
| 54 | mxa.expediagroup.com | 68 |
| 55 | mxb.expediagroup.com | 68 |
| 56 | mx1.nepal.gov.np | 68 |
| 57 | mx6.kvnbw.de | 68 |
| 58 | mx7.kvnbw.de | 68 |
| 59 | mx8.kvnbw.de | 68 |
| 60 | mx9.kvnbw.de | 68 |
| 61 | gmail22.gadmail.de | 67 |
| 62 | gmail23.gadmail.de | 67 |
| 63 | wmail22.gadmail.de | 67 |
| 64 | mx2.nepal.gov.np | 67 |
| 65 | wmail23.gadmail.de | 66 |
| 66 | smtp-avas.seeweb.it | 65 |
| 67 | mx4.emailowl.com | 64 |
| 68 | antispam.korea.kr | 64 |
| 69 | posta.mediacenter.hu | 63 |
| 70 | posta2.mediacenter.hu | 63 |
| 71 | posta4.mediacenter.hu | 63 |
| 72 | posta5.mediacenter.hu | 63 |
| 73 | mx5.emailowl.com | 63 |
| 74 | mx1.daouoffice.com | 63 |
| 75 | mx01.statens-it.dk | 63 |
| 76 | mx02.statens-it.dk | 63 |
| 77 | mx03.statens-it.dk | 63 |
| 78 | mx04.statens-it.dk | 63 |
| 79 | mx05.statens-it.dk | 63 |
| 80 | mx06.statens-it.dk | 63 |
| 81 | mx07.statens-it.dk | 63 |
| 82 | mx08.statens-it.dk | 63 |
| 83 | omail22.gadmail.de | 63 |
| 84 | omail23.gadmail.de | 63 |
| 85 | rmail22.gadmail.de | 63 |
| 86 | rmail23.gadmail.de | 63 |
| 87 | posta3.mediacenter.hu | 62 |
| 88 | mx1.oderland.com | 62 |
| 89 | mx2.oderland.com | 62 |
| 90 | mx6.emailowl.com | 62 |
| 91 | smtp.faisco.cn | 62 |
| 92 | mail.vipmailservice.com | 62 |
| 93 | mx1.simplelogin.co | 61 |
| 94 | mx2.simplelogin.co | 61 |
| 95 | townsites.dnsmaster.net | 59 |
| 96 | spamexpert01.host.bg | 59 |
| 97 | spamexpert02.host.bg | 59 |
| 98 | d01es.mail.s-web.de | 59 |
| 99 | d02es.mail.s-web.de | 59 |
| 100 | e01es.mail.s-web.de | 59 |
What this block shows. The most popular SPF include:
targets that don't match any known ESP, mailbox-as-sender, or SaaS pattern yet. Same
feedback loop: top hits get added to dictionaries/esps.py or
dictionaries/saas_senders.py.
| # | SPF include | Domains |
|---|---|---|
| 1 | yunyou.top | 142 |
| 2 | _spf1-aws.recop.jp | 133 |
| 3 | _spf.edhost.eu | 126 |
| 4 | _spf.mail-neoserv.si | 119 |
| 5 | spf.mailii.org | 116 |
| 6 | dospf.simplepart.com | 116 |
| 7 | _spf.exsilia.net | 114 |
| 8 | mlrcloud.com | 114 |
| 9 | spf.pitcom.net | 113 |
| 10 | _spf.lh.pl | 113 |
| 11 | spf.w4ymail.at | 111 |
| 12 | _spf.armada.it | 106 |
| 13 | spf.boldem.cz | 105 |
| 14 | spf.cesky-hosting.cz | 105 |
| 15 | _spf.abcp.ru | 104 |
| 16 | spf-2248456.jmsend.com | 103 |
| 17 | spf.aams4.jp | 103 |
| 18 | send.k-crm.jp | 103 |
| 19 | spf.spcloud.jp | 103 |
| 20 | spf.mijndomeinhosting.nl | 102 |
| 21 | spf.betrend.com | 102 |
| 22 | relay.guzelhosting.com | 102 |
| 23 | spf.v6send.net | 102 |
| 24 | _spf.localservices.com.br | 102 |
| 25 | _spf.wpopt.net | 101 |
| # | SPF include | Domains |
|---|---|---|
| 26 | spf.mailcamp.nl | 101 |
| 27 | gateways.firstdata.com | 100 |
| 28 | _spf.ogicom.pl | 100 |
| 29 | fmx.etius.jp | 100 |
| 30 | _spf.octadesk.com | 99 |
| 31 | spf.ssmx.net | 99 |
| 32 | amazon.com | 98 |
| 33 | _spf.presscloud.com | 98 |
| 34 | _pmta2.antevenio.com | 98 |
| 35 | _spf.tld-mx.com | 97 |
| 36 | relay.thundermail.uk | 96 |
| 37 | _spf.simpleviewinc.com | 96 |
| 38 | smtp-cluster.plusvps.com | 96 |
| 39 | spf.emailfilter.io | 95 |
| 40 | _spf.sendnode.com | 95 |
| 41 | mfg.siteprotect.com | 95 |
| 42 | spf.satorimail.net | 95 |
| 43 | _spf.academicworks.com | 94 |
| 44 | _spf01.mykronos.com | 93 |
| 45 | mailii.org | 93 |
| 46 | spf.symplicity.com | 93 |
| 47 | verifymyfafsa.com | 93 |
| 48 | senders.mailmasterplus.net | 93 |
| 49 | spf.protection.outlook | 92 |
| 50 | spf.host-ww.net | 92 |
| 51 | mailing.eqs.com | 92 |
| 52 | spf.shopserve.jp | 92 |
| 53 | spf.form.run | 91 |
| 54 | ofsys.com | 90 |
| 55 | eversrv.com | 89 |
| 56 | spf.qb-feedback.com | 89 |
| 57 | spf.sosafe.de | 89 |
| 58 | _spf.aid.no | 89 |
| 59 | spf | 88 |
| 60 | _spf.sent2email.com | 88 |
| 61 | _spf.shared-server.net | 88 |
| 62 | spf.w2solution.com | 88 |
| 63 | spf.qboxmail.com | 87 |
| 64 | spf.chinaemail.cn | 87 |
| 65 | spf.redpoints.com | 87 |
| 66 | spfref.jackhenry.com | 87 |
| 67 | custmail.vdata.com | 87 |
| 68 | mailmailmail.net | 86 |
| 69 | spf-us.appmail.granicusgovaccess.net | 86 |
| 70 | _spf.herodesk-mails.io | 85 |
| 71 | spf.esvacloud.com | 85 |
| 72 | ciphr247.com | 84 |
| 73 | sender.zcsend.jp | 84 |
| 74 | spf2.nlk2.smtps.jp | 84 |
| 75 | spf.zoner.fi | 83 |
| 76 | spf.263xmail.com | 83 |
| 77 | mail.imismailcenter.com | 82 |
| 78 | relay.email-cluster.com | 82 |
| 79 | _spf.firmstep.com | 82 |
| 80 | _spf.eemsg.mail.mil | 82 |
| 81 | _spf.yourfilter.nl | 82 |
| 82 | spf.byway.it | 81 |
| 83 | no-ip.com | 81 |
| 84 | spf.rpost.net | 81 |
| 85 | _spf-c.arukereso.hu | 81 |
| 86 | spf.mlwrx.com | 80 |
| 87 | spf.gansend.com | 80 |
| 88 | _spf.postaffiliatepro.com | 80 |
| 89 | spf.filteredmx.net | 80 |
| 90 | universalspf.org | 80 |
| 91 | x.universalspf.org | 80 |
| 92 | _spf.goskope.com | 80 |
| 93 | _spf.saashr.com | 79 |
| 94 | email.nimbleams.com | 79 |
| 95 | support.gov.sg | 79 |
| 96 | spf.am.arara.com | 79 |
| 97 | _spf.ungapped.io | 78 |
| 98 | successfactors.eu | 78 |
| 99 | _spf.axa.com | 77 |
| 100 | spf.sabre.com | 77 |
The dataset is the daily OpenINTEL forward-DNS Tranco snapshot
(University of Twente / SURFnet / SIDN Labs). OpenINTEL queries the entire
Tranco top-1M domain list
daily for MX, TXT, NS, A, AAAA, SOA, CAA, DNSSEC and other records, publishing the
results as Apache Parquet. For pre-2022 history we additionally use OpenINTEL's
alexa source (the legacy Alexa top-1M list, retired 2023).
Cite: Roland van Rijswijk-Deij et al., "A High-Performance, Scalable Infrastructure for Large-Scale Active DNS Measurements", IEEE JSAC 2016.
Six deep-dive pages are rebuilt by the same daily run and were previously
reachable only through the sitemap:
SPF health (final all qualifier, DNS-lookup
limit, record length) ·
Email security posture (MTA-STS, BIMI, TLS-RPT, DKIM
selectors) ·
SaaS via verification tokens ·
DNS/NS providers ·
Country × ESP ·
Infrastructure & TLS.
Each report covers a single date — OpenINTEL publishes snapshot D on D+1, so the current UTC date is never treated as an expected snapshot. Freshness means matching the latest date actually present in the OpenINTEL catalogue, typically ~700 k domains with MX records and ~620 k with SPF. The pipeline runs daily at 03:00 UTC, after the usual source-publication window; each daily run produces an HTML report, a JSON summary, an updated time-series, and incremental updates to the domain registry (§ 12). No sub-sampling.
For each domain we read its MX RRset and pick the record with the lowest
mx_preference as the primary mailbox host. The hostname of that
primary MX is matched against an open regex dictionary (dictionaries/mx_providers.py,
currently 328 patterns, hash below). Specific patterns (e.g. .mail.protection.outlook.com)
are tried first; generic fallbacks (mail.*, mx*.*) only after.
Domains whose MX matches no rule are kept as "Unknown / Other" — never dropped — and
exported in Unmatched MX targets for dictionary improvement.
For each domain's apex SPF record (TXT starting with v=spf1) we extract every
include: and redirect= target and resolve them against open classification dictionaries (ESPs, mailbox-as-sender, anti-spam gateways, forwarders, SaaS senders, DMARC vendors, NS providers, verification tokens).
Resolution order: PURE_ESP → MAILBOX_AS_SENDER → GATEWAYS → FORWARDERS → bare-apex
substring fallback → SAAS_SENDERS substring iteration. Bare-apex derivation strips
leading _spf., _spf-eu., spf., mail.
prefixes from dict keys to catch subdomain variants
(e.g. _spf.m1.websupport.sk → matches websupport.sk).
Malformed includes (no dot, <4 chars) are filtered.
One domain may use several ESPs simultaneously, so ESP shares sum to more than 100% of SPF-publishing domains. Current SPF-include target coverage: 82.66%, recomputed from this snapshot rather than hard-coded.
Limitation: "flattened" SPF (where include chains were replaced with raw IP ranges to fit the 10-lookup limit) is not detectable from DNS alone — those domains appear ESP-less even when an ESP is in fact used.
For each domain we query the _dmarc.<domain> TXT record. Records
starting with v=DMARC1 are parsed for:
p= (apex policy): none / quarantine / reject / invalidsp= (subdomain policy)pct= (rollout percentage)rua= aggregate-report destinations → classified into vendor buckets
(Postmark DMARC, Valimail, dmarcian, URIports, EasyDMARC, Red Sift,
Proofpoint EFD, Agari/Fortra, …) using dictionaries/dmarc_vendors.pyA domain is counted as enforced if p=quarantine or
p=reject with pct=100 (or pct absent — defaults to
100).
For every SPF record we additionally extract:
all mechanism:
-all (hard fail), ~all (soft fail), ?all
(neutral), +all (pass-everything — broken / dangerous), or missinginclude:, redirect=,
a:, mx:, exists:, ptr:) — each
mechanism counts as 1 against the spec limit of 10. Records exceeding the limit
return PermErr at recipientsAdoption of modern mail-security TXT records, parsed from the same OpenINTEL parquet:
_mta-sts.<domain> with
v=STSv1 — domain advertises required-TLS to its MXdefault._bimi.<domain> with
v=BIMI1 — brand publishes a verified logo (requires
p=reject)_smtp._tls.<domain>
with v=TLSRPTv1 — domain monitors TLS-failure reports*._domainkey.<domain> queries, well-known selectors
(google, selector1/2, s1/s2, k1/k2/k3,
mailo, mte1, …) are mapped to issuing ESPsFor each domain's NS RRset, every NS hostname is matched against a suffix dictionary
(dictionaries/ns_providers.py) with patterns for Cloudflare, AWS Route 53,
Azure DNS, Google Cloud DNS, GoDaddy, Akamai, NS1, UltraDNS, Yandex, DNSPod,
Aliyun, OVH, Hetzner, Gandi, registrars, and others. A domain is assigned to its
dominant NS provider; ties resolve to whichever pattern was matched first.
Many SaaS apps a domain is connected to never appear in SPF (because the SaaS doesn't
send mail FROM the customer domain). To recover this signal we parse apex TXT records for
verification tokens — google-site-verification=…, MS=…,
atlassian-domain-verification=…, stripe-verification=…, plus
149 other patterns in
dictionaries/verification_tokens.py. This produces a
complementary "SaaS density" metric and surfaces apps that the SPF-only view misses.
Three additional TLS / IPv6 metrics:
_25._tcp.<mx_host>
(where the parquet includes TLSA queries)0 issue … / 0 issuewild … record
at apex; CAs aggregated into a market-share view (Let's Encrypt, DigiCert,
Sectigo, …)Every domain ever observed across snapshots is assigned a stable integer ID
in /var/openintel-cache/registry/domains.sqlite3 (currently
1 870 760 domains). Reports reference domains by ID rather than embedding
strings; clients resolve names from a single gzipped registry dump
(/email-stats/domains.csv.gz, 21.1 MB). This keeps per-report payloads
compact, enables fast set-operation diffs across snapshots, and gives every domain a
first-seen / last-seen timestamp.
Each daily run computes a domain-level diff vs the previous scan and emits a
change-feed at /email-stats/alerts.html (also as JSON + Atom). Detected
events: ESP added/removed in SPF, DMARC policy upgrade/downgrade, primary-mailbox-provider
change, SPF strict→soft regression, MTA-STS / BIMI first publication. Severity tag is
good / bad / info.
The top-100 ESPs, top-100 SaaS senders and top-80 mailbox providers each have a dedicated
detail page at /email-stats/detail/<kind>/<slug>.html showing KPI
cards, a Chart.js sparkline (from history.json), TLD distribution and a
sample of customer domains.
Each domain is assigned a tier from its Tranco rank: top-1k / top-10k / top-100k / top-1M, plus unranked for domains measured in the snapshot but absent from the current list file (rotation). Published as Authentication by Tranco tier: SPF, DMARC enforcement and self-hosting per tier.
Dictionary hashes for this run (sha256, first 12 hex):
compliance.py — 76d502287abedmarc_vendors.py — 8c195eb564fcesps.py — 0f7a40a1f7d3mx_providers.py — c29c6e1b1f58ns_providers.py — cc4f43c6651fproviders_meta.py — 5dc92db7869fsaas_meta.py — fe611e6e8a68saas_senders.py — 1c5ebd9f7c09tld_regions.py — 61e8bd3dcca8verification_tokens.py — 6ba8313e55abEvery published report includes the exact OpenINTEL date, dictionary file hashes, and counts of unmatched MX hosts and SPF includes — so any reader can verify or reproduce the figures. Raw OpenINTEL parquet is downloaded into a temporary cache and deleted after analysis; only aggregated, non-redistributable counts are kept long-term (per OpenINTEL data agreement). The domain registry stores names but no record-level content.
Every change to a metric definition is recorded in
the methodology changelog and stamped into each
history point as methodology_version — so a step in a series can
always be attributed to a formula change rather than to reality.
mail.example.com →
mail.example.protection.outlook.com) are not unrolled — only the first MX target
is matched. This biases a small share of domains toward "Unknown" when their MX is a
CNAME to a known provider.Spotted a mis-classified MX target, missed ESP, or want to discuss a finding? We publish corrections in the next daily snapshot.
Send feedback to support@live-direct-marketing.onlineInline comments coming soon. For now, email is the fastest path — you'll see your fix reflected in tomorrow's run.
Daily snapshots — last 90 days kept fully, older ones thinned to one point per month. Points marked partial are incomplete days at the source and are excluded from deltas and trends.