Email security gateway lookup
See which gateway filters a domain's inbound email — and the mailbox provider behind it when DNS reveals it. Know before you send.
Please enter a valid email (user@company.com) or domain (company.com)
Why it matters for outbound
Inbox placement
A gateway inspects, rewrites and rate-limits mail before it ever reaches the inbox. Knowing a domain is filtered tells you why a message stalled, and which reputation actually has to hold up.
ESP matching
Segment campaigns by the mailbox provider that really hosts the inbox rather than by the MX you can see. Microsoft 365 and Google Workspace do not treat the same message the same way.
Spot filtered accounts first
Filtered domains are usually larger, slower to convert and less tolerant of cold volume. Flag them before a send instead of discovering it in your bounce report.
How it works
MX records name the gateway
When a domain routes inbound mail through a filter, its MX records point at that service — mxa-*.pphosted.com for Proofpoint, *.mimecast.com for Mimecast. That identifies the gateway with certainty.
SPF can reveal the mailbox behind it
The gateway hides who actually hosts the inbox, but the domain still has to authorise its own platform to send. We read the SPF record and, when it names one, report the mailbox provider behind the gateway.
When SPF says nothing, neither do we
SPF include: chains are not followed, so a domain whose platform is nested inside its own include — or hidden behind a macro — reveals nothing at the top level. In that case the mailbox provider is reported as not disclosed rather than guessed.
Gateways detected
Matched on MX records. This list comes straight from our provider database, so it stays in step with what the API actually detects.
The same two fields, for a whole CSV
Upload a CSV of addresses or domains and get two extra columns, mailbox_provider and security_gateway, alongside the usual classification.
input,domain,provider_name,…,mailbox_provider,security_gateway
name@fpl.com,fpl.com,Proofpoint,…,Microsoft 365,Proofpoint
name@stripe.com,stripe.com,Google Workspace,…,Google Workspace,
Frequently asked questions
Is this lookup free?
Yes, and it needs no account. The same result is available through the API, where the free tier covers 100 lookups a month without a credit card.
Does it contact the mail server?
No. The lookup reads public DNS records — MX and SPF — and nothing else. No connection is opened to the mail server, no message is sent, and no address is verified.
How reliable is the mailbox provider behind the gateway?
The gateway itself is read directly from MX records, so it is as reliable as DNS. The mailbox behind it is inferred from the domain's SPF record, which only names a platform some of the time — when it does not, the field is left out rather than guessed.
How is this different from an ESP checker?
A typical ESP checker reports whatever the MX says, so a filtered domain comes back as “Proofpoint” — the name of the filter, not of the email service. This lookup separates the two: the gateway in front, and the mailbox provider behind it.
Check your whole prospect list
Upload a CSV: get the mailbox provider and security gateway of every address, ready to split your campaigns. 100 lookups/month free, no credit card.