Who Hosts the Internet's Email? Mostly Not Google or Microsoft (July 2026)
Published · updated
Figures as of 2026-07-29 · methodology v8. Part of the July 2026 domain security census. Aggregate census data; we never publish an individual domain’s status or grade. See how we grade.
More than half of the internet’s email domains trust their mail to no household name. At least, none that the DNS can name. This edition we graded 297 million domains. 163 million of them declare a mail server. For each one we asked a single question: who receives this domain’s mail? The most common answer is not a brand at all. It is Self-hosted / other: the vast long tail of businesses running their own mail servers, plus small hosting companies, ISPs and regional providers. Together they receive mail for 52.8% of those mail-declaring domains. The largest named provider, Google Workspace, handles 12.7%.
Keep one thing in mind throughout: we count domains, not messages. A parked domain with one dusty mailbox counts once. So does a hundred-thousand-seat enterprise. By message volume, the big suites loom far larger. But a domain is what an attacker spoofs and a DNS zone defends. Counted that way, the majority answer is nobody famous.
The received wisdom says email finished consolidating into two clouds years ago. The DNS says otherwise.
Who actually receives mail for the internet’s domains?
Almost every domain that wants to receive email publishes MX records. These are the DNS entries that name the servers that should receive its mail. A small minority skip them and rely on a legacy fallback: mail delivered to the domain’s own address record. We count declared MX records only. We resolve those records across the census and attribute each receiving server to the organisation that operates it. Some services are white-labelled — one company runs them under another’s brand. Where we can identify the underlying operator, the operator gets the credit. Here is the 2026-07-29 ranking, by share of domains that declare a mail server:
| Provider | Share of domains with mail servers |
|---|---|
| Self-hosted / other | 52.8% |
| Google Workspace | 12.7% |
| Microsoft 365 | 8.6% |
| GoDaddy | 5.7% |
| Namecheap | 4.6% |
| IONOS | 3.9% |
| Hostinger | 2.82% |
| OVH | 1.59% |
The full breakdown lives on the email provider market share stats page. For the evergreen market picture, start with our June email hosting market share baseline. This article reports what the 2026-07-29 census found.
Add the two big cloud suites together: Google Workspace at 12.7% and Microsoft 365 at 8.6%. The long tail on its own still receives mail for more domains than both combined.
The next tier is mostly registrar-bundled mail: GoDaddy at 5.7% and Namecheap at 4.6%. This email typically arrived in the same shopping basket as the domain itself. For a large slice of the internet, the email provider was never a choice. It was a default. Defaults are our whole beat. Not sure which bucket your own domain landed in? The free check reads your MX records and tells you.
Self-hosted email: a patching responsibility, not a product
What is actually inside that 52.8%? Everything. Corporate mail servers run by dedicated teams. University systems older than their students. An ISP’s shared platform serving thousands of small firms. A hosting panel’s bundled mailbox. A box in a cupboard that has forwarded invoices since the previous owner left.
One honest caveat about the label. This bucket holds every mail server we could not tie to a named major provider. So it mixes genuine self-hosting with thousands of small hosts and ISPs that look the same from the outside.
The market-share table hides an operational truth: every genuinely self-hosted mail server is a named human’s job to patch. Cloud suites patch their whole fleet centrally, on their own schedule, whether customers think about it or not. The ISPs and hosting panels in this bucket do the same at smaller scale. A domain running its own box is different. It gets patched one server at a time, when someone remembers. If someone still works there. And mail-server software keeps suffering serious, widely exploited flaws. The Microsoft Exchange ProxyLogon wave and the Exim bugs each exposed hundreds of thousands of servers at once. Every fix had to be applied server by server, across a large share of the internet’s email estate.
None of this makes self-hosting wrong. It makes it a job. Where that job has a named owner, the domain is in a manageable position. The worrying case is the server that nobody still employed can log into. From the outside, your DNS and mail setup can hint at which kind yours resembles. Run the free check and see what yours shows.
Is a big email provider safer than self-hosted email?
It cuts both ways. Concentration buys competence. The big suites employ world-class operations teams, patch quickly and centrally, and encrypt mail in transit by default. But concentration also builds a shared single point of failure. An outage, a policy change or a compromise at a provider carrying 12.7% of domains could touch all of them in the same hour. And a login page shared by that many domains is an obvious template for phishers to counterfeit.
The scattered majority is the mirror image. No single failure can take it down. Structurally, the long tail is the most resilient part of the email internet. But security varies enormously from one server to the next. And when the next big vulnerability lands, no central operator can push out the fix.
This edition’s snapshot shows the internet has chosen both. A concentrated minority that shares fate. A scattered majority that shares nothing — sometimes not even best practice. Email is not unique, either: DNS and TLS issuance show the same concentration pattern in this edition’s census.
Does using a big email provider make your domain secure?
This is the part organisations most often get wrong, so let us be blunt: mailbox hosting is not domain security. SPF, DKIM and DMARC are the DNS records that let receiving servers reject strangers sending email as you. They live in your domain’s DNS zone, not in the mailbox product. You control that zone, or whoever you let run your DNS does.
Start with DKIM, the signature DMARC actually checks. Your provider can only sign your outgoing mail with a key that matches your domain once that key is published in your zone. Until then, mail goes out under the provider’s own fallback identity. That does nothing for your domain’s DMARC. DMARC can also pass on aligned SPF alone, but that pass breaks the moment mail is forwarded; DKIM is the check that survives transit. The other two records work the same way. Your SPF record only protects your name if it authorises the right senders, whether you wrote it or a setup wizard did. Your DMARC policy only exists, and only enforces, if you put it there.
So a domain hosted on the biggest suite in the world gains no spoofing protection for its name from the brand alone. Without DMARC enforcement, receivers get no instruction to reject mail impersonating it. That is exactly the position a self-hosted domain is in. Enforcement, not the logo on the mailbox, is what tells receivers to reject the fake. And most domains are not enforcing. Across this census, only 11.84% of graded domains publish an enforcing DMARC policy — quarantine or reject.
For a business, “spoofable” is not abstract. It is a supplier paying an invoice, or payroll changing bank details, because the request arrived under your exact domain name. A single diverted invoice routinely runs to five or six figures. Your provider answers a different question: where your mail is stored and filtered. Who may send as your name is answered in your zone, and only you can answer it.
That is why our grading looks at what your DNS publishes, not whose logo is on your webmail.
What this means for your business
Self-hosting makes you the majority, not a relic — but the patching question above is addressed to you personally. Patching, encryption in transit and staying off spam blocklists all need a named owner. If you cannot say whose job your mail server is, that is the finding.
Using a hosted provider means you have outsourced infrastructure, not identity. SPF, DKIM and DMARC are still your records, in your zone. Leave them unfinished and you undo much of what you are paying for.
If you are choosing or switching: judge providers on deliverability, admin controls, compliance and support — including how they handle the bulk-sender rules Google and Yahoo now enforce. Do not assume a bigger brand means a safer domain; your posture is decided in your DNS either way. Weigh the concentration trade-off deliberately. A major suite means excellent operations and shared fate. The long tail means independence and sole responsibility. Both are defensible. Only the unexamined default is not.
In all three positions the first step is the same: find out what your zone actually publishes today. The free check will tell you.
Quick answers
Are most email domains hosted on Google Workspace or Microsoft 365? No. In our 297 million-domain census (2026-07-29 edition), Self-hosted / other infrastructure — the long tail of self-hosted servers, small hosts, ISPs and regional providers — receives mail for 52.8% of the domains with mail servers. That is more than any single named provider.
What share of the internet’s email domains does Google Workspace host? Google Workspace is the largest named email provider. In the 2026-07-29 edition it receives mail for 12.7% of domains that declare a mail server, ahead of Microsoft 365 at 8.6%.
Does using a major email provider make a domain secure? No. SPF, DKIM and DMARC live in the domain owner’s DNS zone. Some setup wizards add SPF or DKIM entries automatically when the provider also runs your DNS. But DMARC, above all an enforcing policy, remains the domain owner’s decision. A hosted domain still needs these records, wherever its mailboxes live. Any domain’s published records can be checked free at defaults.exposed.
Your own MX record has already answered this article’s question. It names, in public, who receives your mail. The free check reads that record alongside your SPF and DMARC records, checks the common DKIM selectors, and grades what the rest of the internet can already see. Nothing to install, nobody to talk to — just your domain’s email posture and a plain-English list of what to fix first.