/ developer & network toolbox
← all tools

$ whomail

server-side

Email Host Lookup

Find out who hosts email for a domain: Google Workspace, Microsoft 365, a security gateway or a self-hosted server, plus every service allowed to send.

emailhost — invoker.tools

About the Email Host Lookup

This email host lookup answers one question: which company actually handles email for a domain? Type a domain or a full email address and the tool reads the domain's MX records, its SPF record and its autodiscover CNAME, then matches every hostname against a fingerprint table of more than 70 mail services. The result is a plain answer such as "hosted by Microsoft 365" or "filtered by Mimecast, most likely delivered to Google Workspace", with the evidence for each conclusion shown next to it.

MX records tell you where incoming mail goes, but the raw hostnames are rarely self-explanatory. kpn-com.i-v1.mx.microsoft is Microsoft 365, mxa-00148501.gslb.pphosted.com is Proofpoint, hsmx01.antispameurope.com is Hornetsecurity and filter10.antispamcloud.com is SpamExperts. When a security gateway sits in front of the mailbox, the MX only shows the filter; the real mailbox provider then usually shows up in the SPF record, because the domain has to authorise it to send. This lookup combines both signals and says how confident it is.

The SPF record also reveals every other service allowed to send as the domain: newsletter platforms, CRMs, helpdesks, invoicing tools and transactional mail APIs. That list is often the fastest way to understand a company's mail setup before a migration, a deliverability investigation or a DMARC rollout.

Only public DNS is queried, from our server against public resolvers. Nothing is stored and no mail is sent to the domain.

How to use it

  1. Enter a domain (example.com) or paste a complete email address; everything before the @ is ignored.
  2. Click find email host to read MX, SPF and autodiscover for the domain.
  3. Read the headline: the mailbox provider, or the security gateway when the mailbox is hidden behind one.
  4. Check the confidence label. High means the MX itself identifies the provider; medium means it was inferred from SPF or autodiscover.
  5. Review each MX host and which service it belongs to, plus the reverse DNS of the primary mail server.
  6. Scan the sending services list to see which platforms may send mail as the domain.

Examples

  • MX smtp.google.com or aspmx.l.google.com: the domain uses Google Workspace (Gmail).
  • MX example-com.mail.protection.outlook.com or example-com.o-v1.mx.microsoft: Microsoft 365 / Exchange Online. The .mx.microsoft form is Microsoft's newer DNSSEC-capable MX.
  • MX points to pphosted.com (Proofpoint) and SPF includes spf.protection.outlook.com: mail is filtered by Proofpoint and delivered to Microsoft 365.
  • MX route1.mx.cloudflare.net: Cloudflare Email Routing receives the mail and forwards it to another inbox, so the final mailbox is not visible in DNS.
  • MX mail.example.com with a PTR in the company's own IP range and no known provider: a self-hosted mail server.

How the provider is detected

  • MX records: each mail server hostname is matched against known patterns per provider. This is the strongest signal because it is where mail is physically delivered.
  • SPF includes: include: and redirect= domains name the services allowed to send. A mailbox provider that appears here but not in MX is usually sitting behind a gateway.
  • Autodiscover CNAME: autodiscover.example.com pointing to autodiscover.outlook.com is a strong hint of Microsoft 365, even when a filter hides the MX.
  • Reverse DNS of the primary MX: for unknown servers the PTR name often reveals the hosting company or shows a self-hosted setup.

Mailbox host, security gateway, forwarding: what the labels mean

A mailbox host stores the mail and runs the inboxes: Google Workspace, Microsoft 365, Zoho, Fastmail, a hosting provider. A security gateway (Mimecast, Proofpoint, Barracuda, Hornetsecurity, SpamExperts, Cloudflare Email Security) receives mail first, scans it for spam, phishing and malware, and then relays it to the mailbox host. Forwarding services (Cloudflare Email Routing, ImprovMX, Forward Email) accept mail for a domain without hosting inboxes and pass it on to another address. Sending services only appear in SPF: they send newsletters, invoices or transactional mail on the domain's behalf but never receive its mail.

Why you would want to know who hosts a domain's email

  • Planning a migration: you need the current provider to pick the right import path (Google, Microsoft, IMAP).
  • Debugging bounces and spam placement: gateway and mailbox provider each have their own logs and quirks.
  • Setting up DKIM and DMARC: every sending service in SPF also needs DKIM alignment before p=reject is safe.
  • Investigating phishing: check whether a lookalike domain can even receive replies, and where they would go.
  • Supporting a customer: knowing it is Microsoft 365 or a local hosting provider saves the first round of questions.

Frequently asked questions

How can I find out who hosts email for a domain?

Look up the domain's MX records and match the hostnames to a provider. This tool does that automatically and also reads SPF and autodiscover, so it can see the mailbox provider even when a spam filter sits in front of it.

Can I find the email host from an email address?

Yes. Paste the full address; the tool uses the part after the @ and looks up that domain's mail servers.

Why does it show Mimecast or Proofpoint instead of Microsoft 365?

The MX points to the security gateway, because that is where mail arrives first. If the domain's SPF record or autodiscover CNAME names Microsoft 365 or Google, the tool reports that as the likely mailbox behind the filter with medium confidence.

What does it mean when no provider is recognised?

The mail server is either self-hosted, run by a smaller hosting company that is not in the fingerprint table, or uses a custom hostname. The reverse DNS of the MX address is shown to help identify it.

Does the lookup contact the mail server or send an email?

No. It only reads public DNS records (MX, TXT and CNAME) through public resolvers. It never connects to the mail server and never sends a message.

Is the list of sending services complete?

It shows the services named in the SPF record, including one redirect hop. Services that send with their own domain in the envelope sender do not need to be in SPF and will not appear; DMARC aggregate reports are the complete source for that.

More email / dns tools