Check a domain

How it works

two very different paths to the inbox
NATIVEyou → Google/Microsoft filter → inboxEASIER
GATEWAYyou → Proofpoint → Microsoft → inboxHARDER
GATEWAY SEESreputation, content, attachments, linksSTRICT
TYPICAL EFFECTlower volume tolerance per inboxTHROTTLE
WHAT HELPSolder domains, clean auth, low volumePATIENCE
A gateway is a second filter with its own reputation system, applied before the provider's own.
01

Read the MX hostnames

Gateways announce themselves — pphosted.com is Proofpoint, mimecast.com is Mimecast.

02

Identify the vendor

Each has its own reputation network and its own tolerance for unfamiliar senders.

03

Segment your list

Gateway-protected domains are a different audience from natively filtered ones.

04

Adjust the approach

Lower volume, warmer domains, cleaner authentication, plainer copy, fewer links.

Why the gateway matters more than the mailbox

When a company puts Proofpoint or Mimecast in front of Microsoft 365, inbound mail is filtered twice. The gateway runs its own reputation checks, content analysis and link inspection before Microsoft ever sees the message. Get blocked at the gateway and Microsoft's own filtering never enters the picture.

These systems are also networked. Proofpoint sees mail across its entire customer base, so a sending domain that trips filters at one customer can find itself treated with suspicion at every other Proofpoint customer. That is a very different risk profile from the per-tenant reputation you deal with on native Google or Microsoft filtering.

What to do with the information

Segment. Gateway-protected domains and natively filtered domains behave differently enough that mixing them into one campaign makes your metrics meaningless — a poor reply rate could be your copy, or it could be that a third of the list sits behind Mimecast and never saw the email.

For the gateway segment specifically: send from domains that have been warming for longer, keep per-inbox volume lower, make sure authentication is flawless because gateways check it more strictly than Google does, and keep the message plain. Heavy HTML, multiple links, tracking pixels and attachments all raise the score against you.

It is also worth being realistic. Enterprise prospects behind aggressive gateways are harder to reach by cold email regardless of what you do. If your entire target list is gateway-protected enterprise, cold email may be the wrong primary channel and worth pairing with something else.

What each gateway does differently

GatewayMX signatureWhat it means for cold mail
Proofpoint*.pphosted.comNetworked reputation across its whole customer base. Trip filters at one customer and expect trouble at others.
Mimecast*.mimecast.comAggressive link rewriting and attachment sandboxing. Heavy HTML and tracking pixels score badly.
Barracuda*.barracudanetworks.comCommon in mid-market and education. Strong emphasis on sender IP and domain reputation.
Cisco Secure Email*.iphmx.comFrequent in large enterprise and government. Conservative defaults.
Microsoft Defender*.mail.protection.outlook.comNative rather than third-party, but stricter on cold traffic than Google.
Sophos / Trend / othersvariesSmaller footprint. Behaviour close to the mid-market pattern.
No gatewayprovider MX onlyNative filtering only. The most reachable segment of any list.

Segmenting a list by gateway

Mixing gateway-protected and natively filtered domains in one campaign makes the results unreadable. A 2% reply rate across a mixed list could mean weak copy, or it could mean a third of the list never had the message delivered at all — and you cannot tell which from the aggregate.

Split them and the numbers start meaning something. Run the native segment as normal. For the gateway segment, send from your oldest and best-warmed domains, keep per-inbox volume lower, and strip the message back — plain text, one link, no tracking pixel, no attachment. Gateways check authentication more strictly than Google does, so anything less than clean SPF, DKIM and DMARC alignment is a wasted send.

When to accept the channel is wrong

Worth saying plainly: enterprise prospects behind aggressive gateways are hard to reach by cold email no matter how good your infrastructure is. If your entire target list sits behind Proofpoint and Mimecast, the honest read is that cold email should be one channel among several rather than the primary one. Better to know that before spending three months proving it.

Frequently asked questions

Which gateways does this detect?

Proofpoint, Mimecast, Barracuda, Cisco Secure Email, Sophos, Forcepoint, Trend Micro, SpamExperts, Hornetsecurity, FortiMail, Check Point and Avanan, and MailRoute — identified from MX hostname patterns. If a domain uses something unusual, the tool reports the provider it found and no gateway rather than guessing.

Does a gateway mean my email will not get through?

No. It means the bar is higher and the margin for error is smaller. Well-authenticated mail from a warmed domain sending modest volume still lands. What fails is fresh domains, high volume, sloppy authentication and heavily formatted messages.

Why does no gateway show up for a large company?

Plenty of large organisations rely on native Microsoft Defender or Google filtering, which is genuinely capable. No gateway does not mean no filtering — it means filtering happens inside the mail provider rather than in front of it.

Should I remove gateway-protected domains from my list?

Not automatically — they are often the most valuable prospects. Segment them, send from your best-warmed infrastructure, keep volume conservative and measure them separately. Deleting them removes the hardest-to-reach buyers your competitors also cannot reach.

How do I tell if a company uses Proofpoint or Mimecast?

Their MX records give it away — Proofpoint resolves to a pphosted.com host and Mimecast to mimecast.com, with the real mailbox provider hidden behind. Paste the domain above and the gateway is identified for you, or read the raw MX records with the MX checker.

Does a security gateway mean my email will not get through?

No, but it raises the bar. Gateways run their own reputation and content checks before the mailbox provider sees anything, and they check authentication more strictly. Clean SPF, DKIM and DMARC alignment, a well-warmed sending domain and a plain message get through routinely — heavy HTML from a fresh domain does not.

Why does no gateway show up for a large company?

Plenty of large organisations rely on native Microsoft Defender or Google filtering without a third-party layer, and some route through a gateway that does not advertise itself in MX at all. A clean result means no gateway was detectable from DNS, not that inbound mail is unfiltered.

Should I remove gateway-protected domains from my list?

Segment them rather than delete them. They are usually the larger, better-funded prospects, so removing them removes your best accounts. Give them your oldest domains, lower volume and your plainest message, and measure them separately so their reply rate does not distort the rest of the campaign.

Does a gateway affect how my domain reputation is judged?

With Proofpoint especially, yes. Its reputation data spans its entire customer base, so a sending domain that trips filters at one customer can be treated with suspicion at every other Proofpoint customer. That is a wider blast radius than the per-tenant reputation you deal with on native filtering.

Last reviewed

Related tools

What to run next

The checks that most often follow this one.

Reputation & monitoring

More in this category

Read more

Guides that go deeper

Services

When the tools tell you something is wrong

The diagnostics here are free and always will be. When the fix is bigger than a DNS record, this is the work I do.

Get in touch

Start with a call

Bring a domain and the symptom. I will tell you what is actually wrong and whether you need me at all — plenty of people leave that call able to fix it themselves.

Thirty minutes, no pitch

We will run the checks together on your actual domains, and you will leave knowing what is broken, what it takes to fix, and what it should cost. If that is a job you can do in-house, I will say so.

Based inRangpur, Bangladesh — all time zones
RepliesWithin one business day
LicensingWorkspace below list price
Back to top