soft-shell crabvietnamese mud crabdifferent species of crab
3
9 Comments

We scanned 50,000 domains. Your cold email list is really four systems.

We scan 50,000 domains every day to see how the world actually configures email. Public DNS lookups, nothing sent, nothing stored.

I was looking at this morning's provider numbers and it reframed how I think about cold email entirely.

Here's who actually receives your mail:

Other / self-hosted: 32.4%
Google Workspace: 28.2%
Microsoft 365: 22.7%
Proofpoint: 5.6%
Mimecast: 3.1%
Everyone else: under 2% each

Google and Microsoft together are 50.9%.

So when you send a campaign to 500 companies, you're not really facing 500 decisions. You're facing about four systems, and half your list sits behind two of them.

That changes what "improving deliverability" even means.

  1. You've been testing against an average

Most cold email advice treats spam filtering as one thing. Write better subject lines, warm the domain, avoid spam words, done.

But your list isn't one audience. It's three completely different environments stacked together, and your results are the blended average of all of them.

If half your list is Google and half is Microsoft, and one of those is quietly eating your mail, your open rate looks mediocre and you have no idea why. The problem isn't your copy. You're reading one number for two different games.

The fix isn't technical. It's segmentation you're probably not doing.

  1. The three tiers, in plain terms

Google and Microsoft: 50.9%. Your baseline. Whatever you optimize, optimize for these two, not because they're strictest but because they're most of your list. If you only change one thing after reading this, split your results by provider and look at them separately.

Security gateways: about 10%. Proofpoint, Mimecast, Cisco, Barracuda. These aren't mailbox providers. They're security products a company chose, paid for, and configured. Somebody made a decision to put them there.

You can see it in how those domains behave. In today's data, 61.8% of Proofpoint domains are on DMARC reject, versus 26.9% of Google Workspace domains. These are organizations treating email security as policy, not as a default they inherited.

Practical read: if your prospect sits behind one of these, cold email is a harder channel. Not impossible. Harder. Adjust your expectations rather than your subject line.

Self-hosted and other: 32.4%. The biggest single bucket and the least predictable. Small hosts, agency setups, legacy servers, someone's cPanel from 2014. Filtering ranges from nonexistent to aggressive with no pattern. Some of your best deliverability lives here. So do your strangest bounces.

  1. One thing worth knowing

You've probably read that Gmail and Yahoo require SPF, DKIM and DMARC above 5,000 sends a day, and that Microsoft added the same rules in May 2025.

True. But those rules apply to their consumer services. Gmail, Outlook., Hotmail, Live.

If you're doing B2B cold email to business domains, you're hitting Google Workspace and Microsoft 365 tenants, and those specific rules technically don't cover you.

I'd still do all three anyway. Consumer standards have a way of becoming business standards, and it's a one-time afternoon of setup. But it's worth knowing what's actually mandatory versus what's recommended, because a lot of cold email content blurs that line to sell you something.

  1. What I'd actually do with this

None of this requires touching DNS.

Check the MX of your list before you send. Free, no signup, tells you who you're really talking to: https://deliverability.mailtester.ninja/tools/mx-lookup
Split your reporting by provider. Google, Microsoft, gateways, everything else. Four numbers instead of one.
Treat the gateway segment separately. Different expectations, probably a different channel.
Stop optimizing against a blended average. That's the whole point.
And check your own setup while you're at it. Not your prospects. You. Most people have never actually looked: https://deliverability.mailtester.ninja/test

  1. Honest caveat, since we sell email verification

That's the actual business, for the record: https://mailtester.ninja/.
Now that we've got that out of the way.

None of this fixes a bad list, and a clean list doesn't fix any of this. Different problems that look identical from the outside, because both show up as "my campaign underperformed."

Verification tells you the address exists. It doesn't tell you the message will land. Anyone selling you the second thing while delivering the first is overselling. Including us, if we ever do it.

Full dataset updates daily and is free to reuse with attribution: https://deliverability.mailtester.ninja/

One thing I'm curious about. Does anyone here actually segment campaign reporting by receiving provider? Or is that as rare as I suspect?

posted to Icon for group Growth
Growth
on July 27, 2026
  1. 1

    One of the sharpest deliverability posts I've read, and "you're reading one number for two different games" is the part most people miss and shouldn't. The self-limiting honesty at the end (verification proves the address exists, not that the message lands, "including us if we oversell") does more for trust than any feature claim could.

    To your question, do people segment reporting by receiving provider: almost nobody does. But there's a second-order version of your insight worth naming. It's not just that the segments filter differently, they represent different buying postures, which changes the channel decision, not just the deliverability tactic.

    A company that deliberately bought and configured Proofpoint or Mimecast didn't just harden email, they signaled that unsolicited outreach is culturally unwelcome. The DMARC-reject gap you cited (61.8% Proofpoint vs 26.9% Google) isn't only a technical wall, it's a proxy for "this org has an opinion about cold email." So the gateway segment isn't just harder to land in, it's a place where landing might not help, because the org has pre-decided the channel is noise. Different channel entirely, like you said, but the reason is behavioral, not just technical.

    The self-hosted 32.4% bucket is the interesting one strategically. Unpredictable filtering, but the segment least likely to have a formal "no cold email" posture. Your best deliverability AND your least-defended prospects probably overlap there. Might be the segment to lead with, not despite the unpredictability but because the humans behind it haven't institutionalized resistance yet.

    Do you see engagement (replies, not just opens) track the provider split too? Whether the gateway segment actually converts when you do land would tell you if it's worth the effort at all.

    1. 1

      The gateway-as-behavioral-signal read is better than what I wrote, and I'm slightly annoyed I didn't get there myself. You can push it further too: most orgs don't buy Proofpoint proactively. They buy it after an incident. So you're not just looking at a security posture, you're often looking at an organization that has a written policy and a person whose job it is to enforce it. The wall is technical, the decision behind it isn't.

      On the self-hosted bucket, agreed on the strategy, but I'd add a counterweight from our side of things.

      That bucket is the least institutionally defended and the most hazardous for your list at the same time. Legacy servers, abandoned mailboxes, domains nobody has audited since 2014. Nobody's pruning anything. It's where dead addresses and recycled spam traps concentrate, and a trap hit costs you more than a hundred non-replies from a gateway.

      So it's the friendliest segment to reach and the easiest one to hurt yourself in. Different risk, not less risk. I'd still lead with it, just not raw.

      On your question, I have to give you a disappointing answer. I don't know, and structurally I can't. We see DNS and SMTP responses. We never see the campaign. Somebody verifies a list, sends it somewhere else, and we're gone before anything happens. Wrong end of the funnel entirely.

      The people who could answer it are the sending platforms, and I'd genuinely like to see that data. Reply rate split by receiving provider, controlled for company size, would settle whether the gateway segment is worth the effort or just worth skipping. My instinct says the effort is better spent elsewhere, but that's an instinct, and instincts are how you end up with a nice theory and no evidence.

      If you're in a position to check that on your own numbers, I'd read that post.

  2. 1

    The interesting shift is that you're turning deliverability from a sending problem into a segmentation and intelligence problem.

    What would convince you that provider-level segmentation is something teams will build into their workflow, rather than just another diagnostic they check when campaigns underperform?

    1. 1

      You've put your finger on the weak spot, and I think you're right.

      Today it's a diagnostic. People check it after a bad week, not before a campaign. It becomes a workflow the day someone proves that acting on the segment changes outcomes, not just explains them. I can tell you Google and Microsoft behave differently. I can't yet tell you what to do differently beyond adjusting expectations, and I'd be overselling if I pretended otherwise.

      My guess is the sending tools surface it before anyone builds a habit around it. Nobody adopts a workflow that costs them a manual step.

      Have you seen anyone actually test different sequences per provider?

      1. 1

        Appreciate the honesty and context.

        Would be good to continue the conversation as you explore whether this becomes part of the workflow or stays a diagnostic layer.

        What's the best email to reach you on?

        1. 1

          Happy to keep talking, but let's do it here. Nothing I've said is private, and anyone reading the thread later benefits from it.

          If you land on something concrete, or you're in a position to test the segmentation on real sends, post it and tag me. I'll show up.

          My contact is on my profile if you need it for something specific :)

          1. 1

            Appreciate that, Danila.

            Makes sense. I agree the discussion itself is valuable here.

            I think email might be a better place for a more detailed exchange when there’s more context to share, but happy to continue here as well.

            1. 1

              Sounds good. Whenever you've got something concrete on the sending side, here or by email works.

              Still curious about the original question if you ever come across an answer ;)

              1. 1

                Appreciate that, Danila.

                I think this conversation may be easier to continue over email when there's more context to share.

                What's the best email to reach you on?

Trending on Indie Hackers
Stop losing deals in the gap between "sounds good" and getting paid User Avatar 62 comments Building a startup costs $0. Your tooling budget costs $500K. Here's why. User Avatar 49 comments 787 tools for developers. 5 for nurses. Two weeks of tracking 14,000 indie launches. User Avatar 33 comments 🚀 I built Brickbeam — an AI-powered assistant that helps LEGO fans turn their messy piles of bricks into real builds. User Avatar 21 comments 67K impressions in 2 days from a single Daily-Dev post — here's what happened User Avatar 21 comments I’m building LinksRF to make shared-link traffic easier to understand User Avatar 16 comments