Start with the mail path

For traditional secure email gateways, MX is usually the strongest public signal because it tells other mail systems where inbound messages should be delivered. Recognized provider domains can identify products such as Proofpoint, Mimecast, Hornetsecurity or Barracuda without probing private systems.

Use provider fingerprints, not broad brand keywords

A reliable detector maps specific infrastructure patterns to a provider and retains the exact hostname as evidence. Loose keyword matching creates expensive false positives. For example, a hostname belonging to Cisco Email Security should not be classified as Salesforce simply because another service uses a related infrastructure provider somewhere else.

SPF answers a different question

SPF describes which systems may send mail on behalf of a domain. Includes can reveal transactional mail providers, support platforms and security services. A provider appearing in SPF may reinforce a gateway finding, but it does not automatically mean the provider handles inbound mail.

Gateways can hide the Workspace

When MX points to a gateway, the backend mailbox platform is obscured. SecuTest therefore searches secondary evidence such as Microsoft Entra ID, Autodiscover and DKIM. The product keeps “Email Security” and “Workspace” as separate dimensions so one does not overwrite the other.

Example

MX → Proofpoint, Entra ID → present, Autodiscover → Microsoft. A reasonable result is “Email Security: Proofpoint” and “Workspace: Microsoft 365 (strong secondary evidence).”

API-based email security is different

Some security products integrate through Microsoft 365 or Google APIs rather than sitting in the SMTP path. Those tools may leave no stable MX fingerprint. From an external-only perspective, “no recognized gateway” therefore means exactly that: no recognized gateway was observed. It does not prove that the organization has no email-security product.

A useful confidence hierarchy

EvidenceUseTypical confidence
Recognized MX provider patternInbound gateway classificationHigh
SPF includeOutbound/provider contextSupporting
Autodiscover / Entra / DKIMBackend Workspace inferenceSupporting to strong in combination
No recognized providerUnknown / not detectedNever equivalent to absent

Why MSPs care

Provider intelligence changes account prioritization. Existing security spend can indicate maturity and displacement potential. No recognized SEG may support a discovery question around protection strategy. A known gateway plus Microsoft 365 may fit a management or migration service. The signal is most valuable when mapped to what your MSP actually sells.

How to detect Proofpoint from MX records →How to identify Microsoft 365 →

Turn the signal into a prospecting workflow.

SecuTest attaches public infrastructure evidence to each prospect so your team can qualify the account without turning an inference into a claim.

Try for Free