How we classify email domains

What goes into a classification, where the data comes from, and how to tell us one is wrong.

What we observe

Classifications are built from mail infrastructure, not from how a domain name reads. For every domain we record:

  • MX records and their priorities — which servers actually accept mail for the domain
  • The IP addresses those mail servers resolve to, and which other domains share them
  • The nameserver set, which frequently ties together domains registered by one operator
  • Registration data from RDAP: registrar, registrant organisation and country, creation date
  • Whether the domain serves a live website, and what the page identifies itself as
  • SPF and DMARC records, and whether the mail server accepts any address (catch-all)

How a provider is identified

Hostnames change and IP addresses move, so neither can anchor a catalogue. We group mail servers by the registrable domain they belong to — mx1 and mx2 of the same operator become one provider — and a domain reaches a provider through the MX records it publishes. Where a set of unrelated-looking domains all answer on a single mail server, that server is what ties them together, and it is usually the signature of one throwaway operation rather than many independent ones.

Where the data comes from

Most of it we measure ourselves, continuously, from live DNS and RDAP. We also cross-reference public disposable-domain datasets so that a domain flagged by the wider community is not missed. An outside feed decides which domains are worth looking at; what a domain is is decided against our own measurements.

We never classify a domain from customer data. Nothing about who signed up where, or with which address, is published or used to label a third-party domain.

Trust scores

Every domain page shows a 0–100 score with the individual signals that produced it and what each one contributed. A score is a summary of evidence, not a verdict about the people using a domain — a young domain with no website and a high-abuse ending scores low because that combination is frequently abused, not because any particular address on it is fraudulent.

How often it updates

Domain records are re-checked on a rolling 30-day cycle, and the provider catalogue and its statistics are rebuilt daily. New domains appear as soon as we observe mail infrastructure for them. Every domain page shows when the domain was first seen.

Report an incorrect classification

Classifications are automated and they can be wrong — a legitimate business can end up on shared infrastructure with a throwaway service, and providers change what they do. If a domain here is misclassified, email us with the domain name and we will re-review it by hand.

[email protected]

Include the domain and, if you operate it, anything that establishes that — we prioritise those.

Browse the catalogue