Check a domain
How it works
Read the MX hostnames
Gateways announce themselves — pphosted.com is Proofpoint, mimecast.com is Mimecast.
Identify the vendor
Each has its own reputation network and its own tolerance for unfamiliar senders.
Segment your list
Gateway-protected domains are a different audience from natively filtered ones.
Adjust the approach
Lower volume, warmer domains, cleaner authentication, plainer copy, fewer links.
Why the gateway matters more than the mailbox
When a company puts Proofpoint or Mimecast in front of Microsoft 365, inbound mail is filtered twice. The gateway runs its own reputation checks, content analysis and link inspection before Microsoft ever sees the message. Get blocked at the gateway and Microsoft's own filtering never enters the picture.
These systems are also networked. Proofpoint sees mail across its entire customer base, so a sending domain that trips filters at one customer can find itself treated with suspicion at every other Proofpoint customer. That is a very different risk profile from the per-tenant reputation you deal with on native Google or Microsoft filtering.
What to do with the information
Segment. Gateway-protected domains and natively filtered domains behave differently enough that mixing them into one campaign makes your metrics meaningless — a poor reply rate could be your copy, or it could be that a third of the list sits behind Mimecast and never saw the email.
For the gateway segment specifically: send from domains that have been warming for longer, keep per-inbox volume lower, make sure authentication is flawless because gateways check it more strictly than Google does, and keep the message plain. Heavy HTML, multiple links, tracking pixels and attachments all raise the score against you.
It is also worth being realistic. Enterprise prospects behind aggressive gateways are harder to reach by cold email regardless of what you do. If your entire target list is gateway-protected enterprise, cold email may be the wrong primary channel and worth pairing with something else.
What each gateway does differently
| Gateway | MX signature | What it means for cold mail |
|---|---|---|
| Proofpoint | *.pphosted.com | Networked reputation across its whole customer base. Trip filters at one customer and expect trouble at others. |
| Mimecast | *.mimecast.com | Aggressive link rewriting and attachment sandboxing. Heavy HTML and tracking pixels score badly. |
| Barracuda | *.barracudanetworks.com | Common in mid-market and education. Strong emphasis on sender IP and domain reputation. |
| Cisco Secure Email | *.iphmx.com | Frequent in large enterprise and government. Conservative defaults. |
| Microsoft Defender | *.mail.protection.outlook.com | Native rather than third-party, but stricter on cold traffic than Google. |
| Sophos / Trend / others | varies | Smaller footprint. Behaviour close to the mid-market pattern. |
| No gateway | provider MX only | Native filtering only. The most reachable segment of any list. |
Segmenting a list by gateway
Mixing gateway-protected and natively filtered domains in one campaign makes the results unreadable. A 2% reply rate across a mixed list could mean weak copy, or it could mean a third of the list never had the message delivered at all — and you cannot tell which from the aggregate.
Split them and the numbers start meaning something. Run the native segment as normal. For the gateway segment, send from your oldest and best-warmed domains, keep per-inbox volume lower, and strip the message back — plain text, one link, no tracking pixel, no attachment. Gateways check authentication more strictly than Google does, so anything less than clean SPF, DKIM and DMARC alignment is a wasted send.
When to accept the channel is wrong
Worth saying plainly: enterprise prospects behind aggressive gateways are hard to reach by cold email no matter how good your infrastructure is. If your entire target list sits behind Proofpoint and Mimecast, the honest read is that cold email should be one channel among several rather than the primary one. Better to know that before spending three months proving it.
Frequently asked questions
Which gateways does this detect?
Proofpoint, Mimecast, Barracuda, Cisco Secure Email, Sophos, Forcepoint, Trend Micro, SpamExperts, Hornetsecurity, FortiMail, Check Point and Avanan, and MailRoute — identified from MX hostname patterns. If a domain uses something unusual, the tool reports the provider it found and no gateway rather than guessing.
Does a gateway mean my email will not get through?
No. It means the bar is higher and the margin for error is smaller. Well-authenticated mail from a warmed domain sending modest volume still lands. What fails is fresh domains, high volume, sloppy authentication and heavily formatted messages.
Why does no gateway show up for a large company?
Plenty of large organisations rely on native Microsoft Defender or Google filtering, which is genuinely capable. No gateway does not mean no filtering — it means filtering happens inside the mail provider rather than in front of it.
Should I remove gateway-protected domains from my list?
Not automatically — they are often the most valuable prospects. Segment them, send from your best-warmed infrastructure, keep volume conservative and measure them separately. Deleting them removes the hardest-to-reach buyers your competitors also cannot reach.
How do I tell if a company uses Proofpoint or Mimecast?
Their MX records give it away — Proofpoint resolves to a pphosted.com host and Mimecast to mimecast.com, with the real mailbox provider hidden behind. Paste the domain above and the gateway is identified for you, or read the raw MX records with the MX checker.
Does a security gateway mean my email will not get through?
No, but it raises the bar. Gateways run their own reputation and content checks before the mailbox provider sees anything, and they check authentication more strictly. Clean SPF, DKIM and DMARC alignment, a well-warmed sending domain and a plain message get through routinely — heavy HTML from a fresh domain does not.
Why does no gateway show up for a large company?
Plenty of large organisations rely on native Microsoft Defender or Google filtering without a third-party layer, and some route through a gateway that does not advertise itself in MX at all. A clean result means no gateway was detectable from DNS, not that inbound mail is unfiltered.
Should I remove gateway-protected domains from my list?
Segment them rather than delete them. They are usually the larger, better-funded prospects, so removing them removes your best accounts. Give them your oldest domains, lower volume and your plainest message, and measure them separately so their reply rate does not distort the rest of the campaign.
Does a gateway affect how my domain reputation is judged?
With Proofpoint especially, yes. Its reputation data spans its entire customer base, so a sending domain that trips filters at one customer can be treated with suspicion at every other Proofpoint customer. That is a wider blast radius than the per-tenant reputation you deal with on native filtering.
Last reviewed
What to run next
The checks that most often follow this one.
More in this category
Guides that go deeper
When the tools tell you something is wrong
The diagnostics here are free and always will be. When the fix is bigger than a DNS record, this is the work I do.
Deliverability rescue
Mail landing in spam, replies gone quiet, or a domain suddenly blocked. I find the actual cause rather than guessing, and fix it.
- Authentication and alignment failures
- Blocklist delistings and reputation repair
- Gateway and filter-level blocks
- A written report on what broke and why
Email & sending infrastructure
Sending domains, inboxes, authentication and warmup, built to survive volume instead of burning down in a month.
- Domain and inbox fleets at any scale
- SPF, DKIM, DMARC and tracking domains
- Google Workspace and Microsoft 365 inboxes
- Handover documentation you actually own
Domain, DNS & migration
Changing registrar, mail provider or host without a day of downtime or a week of mail silently failing.
- Registrar and nameserver moves
- Workspace and Microsoft 365 migrations
- MX, SSL and subdomain cutover
- Staged rollout with rollback at every step
Monitoring & retainer
Infrastructure drifts. Records get edited, certificates expire, domains get listed. Ongoing eyes on the fleet.
- Scheduled checks across every domain
- Alerts before your clients notice
- Monthly reporting
- Priority response when something breaks
Start with a call
Bring a domain and the symptom. I will tell you what is actually wrong and whether you need me at all — plenty of people leave that call able to fix it themselves.
Thirty minutes, no pitch
We will run the checks together on your actual domains, and you will leave knowing what is broken, what it takes to fix, and what it should cost. If that is a job you can do in-house, I will say so.