We scan 50,000 domains every day to see how the world actually configures email. Public DNS lookups, nothing sent, nothing stored.
I was looking at this morning's provider numbers and it reframed how I think about cold email entirely.
Here's who actually receives your mail:
Other / self-hosted: 32.4%
Google Workspace: 28.2%
Microsoft 365: 22.7%
Proofpoint: 5.6%
Mimecast: 3.1%
Everyone else: under 2% each
Google and Microsoft together are 50.9%.
So when you send a campaign to 500 companies, you're not really facing 500 decisions. You're facing about four systems, and half your list sits behind two of them.
That changes what "improving deliverability" even means.
Most cold email advice treats spam filtering as one thing. Write better subject lines, warm the domain, avoid spam words, done.
But your list isn't one audience. It's three completely different environments stacked together, and your results are the blended average of all of them.
If half your list is Google and half is Microsoft, and one of those is quietly eating your mail, your open rate looks mediocre and you have no idea why. The problem isn't your copy. You're reading one number for two different games.
The fix isn't technical. It's segmentation you're probably not doing.
Google and Microsoft: 50.9%. Your baseline. Whatever you optimize, optimize for these two, not because they're strictest but because they're most of your list. If you only change one thing after reading this, split your results by provider and look at them separately.
Security gateways: about 10%. Proofpoint, Mimecast, Cisco, Barracuda. These aren't mailbox providers. They're security products a company chose, paid for, and configured. Somebody made a decision to put them there.
You can see it in how those domains behave. In today's data, 61.8% of Proofpoint domains are on DMARC reject, versus 26.9% of Google Workspace domains. These are organizations treating email security as policy, not as a default they inherited.
Practical read: if your prospect sits behind one of these, cold email is a harder channel. Not impossible. Harder. Adjust your expectations rather than your subject line.
Self-hosted and other: 32.4%. The biggest single bucket and the least predictable. Small hosts, agency setups, legacy servers, someone's cPanel from 2014. Filtering ranges from nonexistent to aggressive with no pattern. Some of your best deliverability lives here. So do your strangest bounces.
You've probably read that Gmail and Yahoo require SPF, DKIM and DMARC above 5,000 sends a day, and that Microsoft added the same rules in May 2025.
True. But those rules apply to their consumer services. Gmail, Outlook., Hotmail, Live.
If you're doing B2B cold email to business domains, you're hitting Google Workspace and Microsoft 365 tenants, and those specific rules technically don't cover you.
I'd still do all three anyway. Consumer standards have a way of becoming business standards, and it's a one-time afternoon of setup. But it's worth knowing what's actually mandatory versus what's recommended, because a lot of cold email content blurs that line to sell you something.
None of this requires touching DNS.
Check the MX of your list before you send. Free, no signup, tells you who you're really talking to: https://deliverability.mailtester.ninja/tools/mx-lookup
Split your reporting by provider. Google, Microsoft, gateways, everything else. Four numbers instead of one.
Treat the gateway segment separately. Different expectations, probably a different channel.
Stop optimizing against a blended average. That's the whole point.
And check your own setup while you're at it. Not your prospects. You. Most people have never actually looked: https://deliverability.mailtester.ninja/test
That's the actual business, for the record: https://mailtester.ninja/.
Now that we've got that out of the way.
None of this fixes a bad list, and a clean list doesn't fix any of this. Different problems that look identical from the outside, because both show up as "my campaign underperformed."
Verification tells you the address exists. It doesn't tell you the message will land. Anyone selling you the second thing while delivering the first is overselling. Including us, if we ever do it.
Full dataset updates daily and is free to reuse with attribution: https://deliverability.mailtester.ninja/
One thing I'm curious about. Does anyone here actually segment campaign reporting by receiving provider? Or is that as rare as I suspect?
I hadn't considered checking MX records before evaluating campaign performance. That's a practical tip. It would be interesting to see reply rates broken down by provider as well, not just opens.
Great write-up Danila, the gateway-as-a-behavioral-signal point is spot on. But gotta love Aryan asking for your email for the third time in a thread about cold email deliverability! 😂
A little bit of fun on this beautiful day héhé :p
This is a really interesting way to look at cold email deliverability.
Most people optimize the email itself (copy, subject lines, sending volume), but ignore the infrastructure behind the recipient. Segmenting by receiving provider makes a lot of sense because a 40% open rate on Google Workspace and a 15% open rate on a security gateway are completely different situations.
Curious if you’ve seen any meaningful difference in reply rates between Google Workspace and Microsoft 365 after controlling for list quality?
Honest answer: I can't tell you. We see DNS and SMTP responses, never the campaign. Someone verifies a list, sends it elsewhere, and we're gone before anything lands.
But there's a difference we do see, earlier in the chain.
Microsoft 365 domains are far more likely to be catch-all. They accept everything at the SMTP layer, bad addresses included, and sort it out internally. Google tends to reject unknown recipients outright.
So your Microsoft segment shows a lower bounce rate than your Google segment on a list of identical quality, because Microsoft swallowed the failures instead of reporting them. Which means controlling for list quality using bounce rate doesn't actually control for it.
Your 40% vs 15% example might be understating the gap rather than overstating it.
No idea whether reply rates follow the same pattern. If you've got campaign data, you're better placed to answer that than I am.
Interesting finding. We've seen something similar—having more leads rarely improves results if the data quality and buying intent aren't there. Segmentation usually has a much bigger impact than list size.
Agreed, though I'd separate two things that often get merged.
Segmentation by buying intent is a targeting decision. Segmentation by receiving provider is an infrastructure one. Both matter, but the second is invisible in your CRM, which is probably why almost nobody does it.
Curious what your segmentation is actually based on. Firmographics, behaviour, something else? :))
Answering from an odd corner of your data. I run LeadGrid (leadgrid.eu), which builds local-business lists — trades, clinics, salons — so my lists sit almost entirely in that 32.4% "other" bucket. I essentially never see Proofpoint or Mimecast.
Two things from down there that might be worth a column in your index.
The bucket splits further than "self-hosted." Most local businesses aren't running a mail server in any meaningful sense, they're on whatever their web host bundled, so the MX belongs to a regional hosting company. In Germany it's IONOS, Strato, All-Inkl over and over. Filtering there is the host's default config, which makes it homogeneous per host rather than random. Cluster that residual by hosting provider and I suspect a lot of the unpredictability resolves into maybe fifteen configs.
The second one changed how I build lists. For a real share of these businesses the working inbox and the domain MX aren't the same thing. The site says info@salon-x.de, the owner actually reads a Gmail address that's in the footer of their Facebook page, and mail to the domain sits unopened for months. Verification says the address exists, the MX lookup says Google or the host, both are correct, and the message still goes nowhere. Same gap you drew between "exists" and "will land," one layer earlier — the address is real, the human isn't behind it.
On your actual question: no, I don't split reporting by provider, and I'd guess few people selling into local SMBs do, because our variance lives in whether the address is one the owner reads at all. Different failure mode, and it looks identical from the outside too.
On the hosting cluster: you're probably right, and it's testable. We resolve the MX, then roll everything we don't recognise into "other" and stop looking. If regional hosts dominate that bucket, the filtering isn't random, it's a handful of default configs repeated thousands of times. That turns an unpredictable segment into a known one. Worth checking.
The second point is the one I don't have an answer to.
We can confirm a mailbox accepts mail. We can't tell you a human reads it. For a shop where the domain address is a formality and the owner lives in a Gmail account, we return a clean result on a dead channel. Correct, and useless. Same gap I drew between "exists" and "will land", one layer earlier, and I hadn't seen it framed that way.
I don't think that's fixable on our end. Nothing in the protocol tells you whether anyone is home.
The hosting idea is going on the list. If it works I'll publish it and credit where it came from.
the reframe is genuinely useful, but the practical takeaway is even sharper: if 51% of your list is Google + Microsoft, then "improving deliverability" mostly means passing THEIR two filters, not chasing a hundred edge cases. and those two reward the same thing, sender reputation and engagement, not clever copy tricks. so the highest-leverage move for a cold sender isnt more a/b testing subject lines, its the boring infrastructure: warmed domain, clean SPF/DKIM/DMARC, low volume per inbox, and actually getting replies (engagement is the signal both giants weight most). one question your data raises, that 32% "other/self-hosted" is interesting because those are often smaller shops with stricter or weirder setups, do you see them bounce harder, or is it the opposite because theres no big-provider ML filter in the way? that split might matter more than the google/microsoft one for anyone selling upmarket vs down.
One of the sharpest deliverability posts I've read, and "you're reading one number for two different games" is the part most people miss and shouldn't. The self-limiting honesty at the end (verification proves the address exists, not that the message lands, "including us if we oversell") does more for trust than any feature claim could.
To your question, do people segment reporting by receiving provider: almost nobody does. But there's a second-order version of your insight worth naming. It's not just that the segments filter differently, they represent different buying postures, which changes the channel decision, not just the deliverability tactic.
A company that deliberately bought and configured Proofpoint or Mimecast didn't just harden email, they signaled that unsolicited outreach is culturally unwelcome. The DMARC-reject gap you cited (61.8% Proofpoint vs 26.9% Google) isn't only a technical wall, it's a proxy for "this org has an opinion about cold email." So the gateway segment isn't just harder to land in, it's a place where landing might not help, because the org has pre-decided the channel is noise. Different channel entirely, like you said, but the reason is behavioral, not just technical.
The self-hosted 32.4% bucket is the interesting one strategically. Unpredictable filtering, but the segment least likely to have a formal "no cold email" posture. Your best deliverability AND your least-defended prospects probably overlap there. Might be the segment to lead with, not despite the unpredictability but because the humans behind it haven't institutionalized resistance yet.
Do you see engagement (replies, not just opens) track the provider split too? Whether the gateway segment actually converts when you do land would tell you if it's worth the effort at all.
The gateway-as-behavioral-signal read is better than what I wrote, and I'm slightly annoyed I didn't get there myself. You can push it further too: most orgs don't buy Proofpoint proactively. They buy it after an incident. So you're not just looking at a security posture, you're often looking at an organization that has a written policy and a person whose job it is to enforce it. The wall is technical, the decision behind it isn't.
On the self-hosted bucket, agreed on the strategy, but I'd add a counterweight from our side of things.
That bucket is the least institutionally defended and the most hazardous for your list at the same time. Legacy servers, abandoned mailboxes, domains nobody has audited since 2014. Nobody's pruning anything. It's where dead addresses and recycled spam traps concentrate, and a trap hit costs you more than a hundred non-replies from a gateway.
So it's the friendliest segment to reach and the easiest one to hurt yourself in. Different risk, not less risk. I'd still lead with it, just not raw.
On your question, I have to give you a disappointing answer. I don't know, and structurally I can't. We see DNS and SMTP responses. We never see the campaign. Somebody verifies a list, sends it somewhere else, and we're gone before anything happens. Wrong end of the funnel entirely.
The people who could answer it are the sending platforms, and I'd genuinely like to see that data. Reply rate split by receiving provider, controlled for company size, would settle whether the gateway segment is worth the effort or just worth skipping. My instinct says the effort is better spent elsewhere, but that's an instinct, and instincts are how you end up with a nice theory and no evidence.
If you're in a position to check that on your own numbers, I'd read that post.
The interesting shift is that you're turning deliverability from a sending problem into a segmentation and intelligence problem.
What would convince you that provider-level segmentation is something teams will build into their workflow, rather than just another diagnostic they check when campaigns underperform?
You've put your finger on the weak spot, and I think you're right.
Today it's a diagnostic. People check it after a bad week, not before a campaign. It becomes a workflow the day someone proves that acting on the segment changes outcomes, not just explains them. I can tell you Google and Microsoft behave differently. I can't yet tell you what to do differently beyond adjusting expectations, and I'd be overselling if I pretended otherwise.
My guess is the sending tools surface it before anyone builds a habit around it. Nobody adopts a workflow that costs them a manual step.
Have you seen anyone actually test different sequences per provider?
Appreciate the honesty and context.
Would be good to continue the conversation as you explore whether this becomes part of the workflow or stays a diagnostic layer.
What's the best email to reach you on?
Happy to keep talking, but let's do it here. Nothing I've said is private, and anyone reading the thread later benefits from it.
If you land on something concrete, or you're in a position to test the segmentation on real sends, post it and tag me. I'll show up.
My contact is on my profile if you need it for something specific :)
Appreciate that, Danila.
Makes sense. I agree the discussion itself is valuable here.
I think email might be a better place for a more detailed exchange when there’s more context to share, but happy to continue here as well.
Sounds good. Whenever you've got something concrete on the sending side, here or by email works.
Still curious about the original question if you ever come across an answer ;)
Appreciate that, Danila.
I think this conversation may be easier to continue over email when there's more context to share.
What's the best email to reach you on?