StackGrade

What email provider does this domain use?

See who hosts a domain's email from its MX records, and which services are allowed to send as it. Free, no signup.

Try: stripe.com github.com spiegel.de linear.app

How we identify the email provider

The MX records say which servers receive mail for a domain. For example, aspmx.l.google.com means Google Workspace, and *.mail.protection.outlook.com means Microsoft 365. If the MX points to a security gateway (Proofpoint, Mimecast, Barracuda), the mailbox provider behind it is not visible in DNS, and we say so.

The SPF record lists services allowed to send as the domain, such as SendGrid, Mailchimp, Salesforce or HubSpot. It shows who may send, not who actually does.

Frequently asked questions

How can I tell if a company uses Google Workspace or Microsoft 365?

Look at its MX records. Google Workspace MX hosts end in google.com or googlemail.com (for example aspmx.l.google.com or smtp.google.com). Microsoft 365 MX hosts end in mail.protection.outlook.com.

Why does it say a security gateway?

Many larger companies route incoming mail through a filtering service such as Proofpoint or Mimecast first. Their MX records point to the gateway, so DNS does not reveal the actual mailbox provider.

Is this information private?

No. MX and SPF records are public DNS records that every mail server on the internet reads to deliver email. This tool reads only those public records.

What does "no mail servers" mean?

The domain has no MX records, so mail sent to it will not be delivered. A "null MX" (0 .) means the owner has explicitly stated the domain does not receive email.

How StackGrade works

Email authentication · 50 pts

SPF (including the 10-lookup limit), DMARC policy, DKIM keys at common selectors, and MX. These decide whether Gmail and Yahoo trust your mail, and whether scammers can spoof you.

Website security · 35 pts

HTTPS redirect, HSTS, Content-Security-Policy, clickjacking protection, X-Content-Type-Options, Referrer-Policy and cookie flags, using Mozilla's public HTTP Observatory scan.

Domain health · 15 pts

Expiry date and registrar transfer lock from the official registry (RDAP). Domain age, email provider, tech stack and hiring signals are shown but not scored.

Honest by design

If a check can't run (the registry has no RDAP, the site blocks scanners, a lookup times out), we show Not checked with the reason and leave it out of the score. We never guess. The full rubric is public.

Privacy

The checks run in your browser, which asks public services directly: Google Public DNS / Cloudflare DNS, the domain's registry RDAP server, Mozilla HTTP Observatory (its scan history is public) and public job boards (Greenhouse, Lever, Ashby, Workable). For the tech-stack scan, the StackGrade API fetches the site's public homepage; the result is kept briefly in memory, never stored. Graded domains are not logged. Details in the privacy policy. Page views are counted with GoatCounter (open source, no cookies, no personal data); only the page path is sent, never the domain you check.