Start with the mail path
For traditional secure email gateways, MX is usually the strongest public signal because it tells other mail systems where inbound messages should be delivered. Recognized provider domains can identify products such as Proofpoint, Mimecast, Hornetsecurity or Barracuda without probing private systems.
Use provider fingerprints, not broad brand keywords
A reliable detector maps specific infrastructure patterns to a provider and retains the exact hostname as evidence. Loose keyword matching creates expensive false positives. For example, a hostname belonging to Cisco Email Security should not be classified as Salesforce simply because another service uses a related infrastructure provider somewhere else.
SPF answers a different question
SPF describes which systems may send mail on behalf of a domain. Includes can reveal transactional mail providers, support platforms and security services. A provider appearing in SPF may reinforce a gateway finding, but it does not automatically mean the provider handles inbound mail.
Gateways can hide the Workspace
When MX points to a gateway, the backend mailbox platform is obscured. SecuTest therefore searches secondary evidence such as Microsoft Entra ID, Autodiscover and DKIM. The product keeps “Email Security” and “Workspace” as separate dimensions so one does not overwrite the other.
MX → Proofpoint, Entra ID → present, Autodiscover → Microsoft. A reasonable result is “Email Security: Proofpoint” and “Workspace: Microsoft 365 (strong secondary evidence).”
API-based email security is different
Some security products integrate through Microsoft 365 or Google APIs rather than sitting in the SMTP path. Those tools may leave no stable MX fingerprint. From an external-only perspective, “no recognized gateway” therefore means exactly that: no recognized gateway was observed. It does not prove that the organization has no email-security product.
A useful confidence hierarchy
| Evidence | Use | Typical confidence |
|---|---|---|
| Recognized MX provider pattern | Inbound gateway classification | High |
| SPF include | Outbound/provider context | Supporting |
| Autodiscover / Entra / DKIM | Backend Workspace inference | Supporting to strong in combination |
| No recognized provider | Unknown / not detected | Never equivalent to absent |
Why MSPs care
Provider intelligence changes account prioritization. Existing security spend can indicate maturity and displacement potential. No recognized SEG may support a discovery question around protection strategy. A known gateway plus Microsoft 365 may fit a management or migration service. The signal is most valuable when mapped to what your MSP actually sells.
Turn the signal into a prospecting workflow.
SecuTest attaches public infrastructure evidence to each prospect so your team can qualify the account without turning an inference into a claim.