One mail server and no spare? MX records across 157,848,360 mail domains
In the September 2026 census, 157,848,360 graded domains publish at least one MX (Mail Exchange) record that names a usable mail host, and 77,200,110 of them publish exactly one: 44.4% of mail domains under gTLDs and 57.3% under ccTLDs. A single record can still lead to many servers, because one host name can resolve to several machines. Microsoft 365 gives each customer domain one MX name, and 97.9% of the domains whose mail it receives publish that record and no other. Google’s current setup is also one name, smtp.google.com. When we looked them up on 27 September 2026, smtp.google.com returned 5 IPv4 addresses and a Microsoft 365 MX name returned 4.
The single records most likely to mean a single machine are the 30,518,952 that name the domain itself or a host under it, such as mail.example.com. They make up 39.5% of the one-record domains. For 23,993,875 one-record domains, the address the census got for the mail host is also an address of the website on the bare domain, so mail and web arrive at the same place.
Figure 1. What a single MX record names. The blue bar is the group most likely to be one server: a host named under the domain itself.
How the count was taken
The census reads MX records only for domains it grades. It doesn’t query dead names, and it skips the query when its pre-scan lookup found no MX, so everything here is about graded domains where the census captured MX records. There are 173,425,853 of them.
That count includes domains that take no mail at all. RFC 7505 (Request for Comments) lets a domain say so with a single record, MX 0 ., which names no host. 13,774,582 domains publish only records of that kind: 13,629,384 in the exact RFC 7505 form and 145,198 with a preference other than 0 or more than one such record. Another 1,802,911 point their MX records only at localhost or at names under .invalid, and 1,786,091 of those use localhost. Neither can receive mail from anyone: RFC 6761 has localhost always mean the sender’s own machine, and names under .invalid never resolve.
Both groups are left out, because counting them would put domains with no mail server into the one-record group. What remains is the base for every share on this page: 157,848,360 domains with at least one MX record naming a usable host. Records of either kind that sit beside usable ones are dropped too, and the usable ones counted. 5,551 domains publish a Null MX beside other records, which RFC 7505 forbids, and 58,380 list localhost or an .invalid name beside a usable host.
The main shares are also given for gTLDs and ccTLDs separately, because .com alone holds 47.8% of all mail domains. 101,970,388 mail domains sit under gTLDs and 55,671,535 under ccTLDs. The 206,437 mail domains under internationalised TLDs (Top-Level Domains) are in the totals and aren’t split out.
One record, two, or five
Each column is a share of that column’s mail domains.
| MX records | All TLDs | gTLDs | ccTLDs |
|---|---|---|---|
| 1 | 48.9% | 44.4% | 57.3% |
| 2 | 27.6% | 28.5% | 25.8% |
| 3 | 7.4% | 7.7% | 6.7% |
| 4 | 1.7% | 1.0% | 3.0% |
| 5 | 13.5% | 17.4% | 6.5% |
| 6 or more | 0.9% | 1.0% | 0.7% |
| Mail domains | 157,848,360 | 101,970,388 | 55,671,535 |
One record is the most common count. The bump at five comes almost entirely from two providers’ standard setups: 61.2% of the domains whose primary MX is at Google Workspace publish exactly five records, and so do 98.5% of those at Namecheap.
Figure 2. How many MX records a mail domain publishes, gTLDs in blue and ccTLDs in orange.
The ten TLDs with the most mail domains, each row a share of that TLD’s own mail domains:
| TLD | Mail domains | One MX record | MX hosts at two or more operators |
|---|---|---|---|
| .com | 75,462,732 | 45.1% | 1.0% |
| .de | 8,862,637 | 60.0% | 4.0% |
| .org | 6,012,999 | 42.4% | 1.0% |
| .net | 5,767,653 | 45.8% | 1.1% |
| .uk | 4,543,573 | 46.1% | 1.8% |
| .nl | 2,875,613 | 67.0% | 3.1% |
| .ru | 2,821,754 | 54.9% | 0.8% |
| .fr | 2,592,935 | 32.6% | 3.5% |
| .br | 2,393,623 | 47.3% | 1.0% |
| .info | 2,190,561 | 47.8% | 0.8% |
What a second record is for
RFC 5321, section 5.1, tells a sending server to try MX hosts in order of preference, lowest number first. Hosts that share a preference are tried in random order, to spread the load. A host with a higher number is a backup, tried when the lower ones don’t answer. Section 4.5.4.1 also has the sender keep retrying, and says the give-up time generally needs to be at least four to five days. For a sender that follows it, a primary that is down for an hour delays mail. A backup that answers in the meantime accepts it sooner.
80,648,250 domains publish two or more records. 19.9% of them put every record at one preference, and 80.1% use a primary with one or more backups. Most of those backups sit with the same operator as the primary: in 97.1% of primary-and-backup layouts, every backup belongs to the primary’s operator. A backup at the same operator helps when one of its servers fails. When the operator itself is unreachable, only a host run by someone else can take the mail. 1,877,500 domains have a backup of that kind, 1.2% of all mail domains. It’s more common under ccTLDs, where 5.7% of primary-and-backup layouts have a backup elsewhere, against 1.9% under gTLDs.
That kind of backup has a cost. A backup that accepts mail without knowing which addresses exist on the primary has to bounce the unknown ones later, and those bounces go to whatever sender address the message carried, forged or not.
“Operator” here means the brand in the host’s domain name, with Google’s and Microsoft’s hosts grouped under their mail services. A company that runs MX hosts under two different brand names counts as two operators, and a record naming an IP (Internet Protocol) address is never counted as a backup. 783,269 domains list two or more records that all name the same host.
Figure 3. How the second and later records are arranged, as shares of the domains with two or more MX records.
MX record count by provider
97.9% of domains with Microsoft 365 as their primary MX publish one record. Google Workspace domains split between the five-host setup (61.2%) and the single smtp.google.com record (31.6%). Domains whose primary MX is a host under their own name publish one record in 93.8% of cases. At the large hosting companies one count dominates. GoDaddy, IONOS and Hostinger put almost every domain on two records (99.1%, 99.6% and 99.2%), and Cloudflare Email Routing uses three or more for 99.9%.
Figure 4. MX record count by the provider of the primary MX record. The column on the right is the share with exactly one record.
277,588 domains also carry Google’s domain-verification MX record, a host under mx-verification.google.com, beside their mail records. It counts as a record here, and as Google’s.
Records that can’t work as written
RFC 5321 says the value in an MX record must be a domain name that returns an address when looked up. 45,080 mail domains have at least one MX record set to an IP address, and for 38,348 of them every record is an IP address. Once a domain publishes MX records, a sender following the standard won’t fall back to the domain’s own address, so for those 38,348 domains a standard sender finds no usable host, and RFC 5321 tells it to report an error.
11,217,744 domains name the domain itself as the primary MX host, such as example.com for example.com. That’s allowed, and mail goes to the addresses of the bare domain.
For 4,044,951 domains, the census asked for the IPv4 address of the lowest-preference host and got none. Some of those hosts have only an IPv6 address and some lookups failed at scan time, so the count is an upper limit on primary hosts that don’t exist.
What the census can’t see
- The census keeps the first IPv4 address it gets for the primary host and no more, so it can’t tell a single server from a pool behind one name.
- A backup host may queue mail for the domain, refuse it, or no longer know the domain at all. The records alone don’t say which.
- The census asks for MX only when its pre-scan lookup found some. Of the 141,785,978 graded domains with no MX captured, 227,937 had an MX query that failed.
- A correct record can still point at a server that refuses connections, and the census doesn’t send mail to find out.
See your own
The free scan reads a domain’s MX records live, with the preference of each. The MX guide covers what to change when a record points somewhere it shouldn’t.
Figures as of 5 September 2026, from the September 2026 edition of the defaults.exposed census. The name lookups of smtp.google.com and a Microsoft 365 MX host were made on 27 September 2026. Census numbers move every month; the current values are on the data page.