Null MX Adoption 2026: 14.5 Million Domains Opt Out
Published
Figures as of 2026-08-16 · methodology v9. This is a recurring report; each edition re-measures the same population so the numbers can be tracked over time. All figures are aggregate — we never publish an individual business’s grade or name an individual registrant’s domain.
How many domains actually use null MX?
14,455,076 domains publish a null MX record — the RFC 7505 declaration that a domain sends and receives no email — out of 376,928,781 graded domains in our August 2026 census. That is 3.8% of the graded web, which sounds respectable until you see the cohort it should be measured against. Roughly 207 million graded domains have no mail service at all. Only one in fourteen of them says so properly. The other 192.7 million just stay silent, and silence is the worst possible configuration for a domain that receives no mail.
The standard is eleven years old. RFC 7505 was published in June 2015 (industry context, not census data), and it asks almost nothing of a domain owner: one DNS record, MX 0 ., priority zero, target dot. It costs nothing, takes a minute, and tells every mail server on earth “don’t bother.” Adoption at 7.0% of the population it was written for, a decade in, is the story.
Key numbers
- 14,455,076 domains publish a null MX record (RFC 7505) — 3.8% of the 376,928,781 graded domains in the August 2026 census.
- 207,153,942 graded domains (54.9%) have no working mail service — either a null MX or no MX record at all.
- Only 7.0% of no-mail domains declare it explicitly with null MX; the other 192,698,866 simply publish no MX record.
- For every domain that formally opts out of email, 13.3 domains stay silent with no MX record of any kind.
- 81.6% of silent no-MX domains also lack both SPF and DMARC — roughly 157 million domains with no mail service and no anti-spoofing protection either.
- 169,774,839 domains (45.0% of the graded web) have real, working MX records.
What is a null MX record?
A null MX is a single DNS record: MX 0 . — priority 0, exchange ”.”. Under RFC 7505 it means the domain does not accept email, full stop. A sending mail server that sees it can reject the message instantly with a permanent error, and the sender finds out in seconds that their mail will never arrive.
Compare that with what happens when a no-mail domain publishes nothing. The sending server finds no MX, falls back to trying the domain’s A record (a legacy behaviour older than most of the people configuring mail today), fails to connect, and queues the message for retry. Standard mail-server defaults keep retrying for several days before giving up (protocol behaviour, industry knowledge — not a census measurement). The sender waits days to learn what a null MX would have told them in milliseconds. Misdirected invoices, password resets sent to a typo’d domain, replies to a decommissioned brand — all of it hangs in a queue, going nowhere, telling nobody.
That is the whole pitch. One record converts days of ambiguity into an instant, honest no.
The mail landscape of the graded web
Here is where all 376.9 million graded domains sit. One denominator throughout this article: the 376,928,781 graded domains of the August 2026 round (the census also scanned 432 million domains in total; ungraded dispositions are excluded here).
| Cohort | Domains | Share of graded |
|---|---|---|
| Working MX records (real mail service) | 169,774,839 | 45.0% |
| No MX record at all (silent no-mail) | 192,698,866 | 51.1% |
| Null MX — explicit no-mail (RFC 7505) | 14,455,076 | 3.8% |
| Total graded | 376,928,781 | 100% |
Two readings of that table matter.
First, the no-mail web is enormous. 54.9% of graded domains — parked names, brand-protection registrations, redirect shells, single-page projects — have no mail service. More than half the registered, resolving web neither sends nor receives a single message. That cohort is exactly who RFC 7505 was written for.
Second, inside that cohort, explicit beats silent 14.5M to 192.7M — a ratio of 1 to 13.3 in the wrong direction. The standard lost to the default, and the default is “do nothing.”
Fourteen and a half million is not nothing, to be fair. Our census can’t attribute adoption from a single count, but a number that size almost certainly reflects infrastructure providers and registrars deploying null MX automatically on parked and mail-less zones, rather than fourteen million individual owners reading an RFC (interpretation, not a measured attribution). Where a provider makes it the default, adoption happens. Where an owner has to know the record exists, it mostly doesn’t.
Why does a no-mail domain need any DNS records for email?
Because spoofing doesn’t care whether you receive mail. Anyone can put your domain in the From: line of an email. Receiving systems check SPF and DMARC — published by your domain — to decide whether to believe it. A no-mail domain with no SPF and no DMARC is a free costume: it will never send a legitimate message, and nothing it publishes tells the world that.
The census puts numbers on how bad this is. Of the 192,698,866 silent no-MX domains, approximately 81.6% — roughly 157 million — publish neither SPF nor DMARC. Call it what it is: 157 million domains that will never send an email and are configured so that anyone else can send email as them.
A null MX doesn’t fix spoofing by itself. It handles delivery, not authentication. The well-understood full opt-out for a no-mail domain is three records — null MX, an SPF record of v=spf1 -all, and DMARC p=reject (standard operational guidance, industry knowledge) — and every one of them is free. The 14.5 million null MX publishers have at least taken the first step. The 192.7 million silent domains haven’t taken any.
Why hasn’t RFC 7505 caught on?
Three honest reasons, none of them technical.
Nobody feels the pain. The cost of a missing null MX lands on other people’s mail queues. The domain owner never sees the misdirected messages spinning for days, so nothing prompts them to act. Records get deployed when their absence hurts the person who controls the zone. This one doesn’t.
Awareness is near zero outside mail-operations circles. SPF and DMARC at least appear in compliance checklists and deliverability guides. Null MX appears almost nowhere. A domain owner who has never sent mail from a domain has usually never thought about that domain’s mail posture at all.
And the default does something that looks like the right thing. No MX record means mail eventually fails, and “eventually fails” is easy to mistake for “handled.” The difference between a 5-day timeout and an instant rejection is invisible until you’re the one waiting on it.
None of these change the arithmetic. One record, one minute, free. The barrier is awareness, not cost.
Is 14.5 million a lot or a little?
Both, depending on the yardstick — so here are the yardsticks.
Against the whole graded web it’s 3.8%, which makes null MX a small but measurable adoption of a record most domain owners have never heard of.
Against its addressable population it’s 7.0%, and that is the honest number. RFC 7505 exists for exactly one cohort: domains with no mail service. That cohort is 207 million strong, and 93.0% of it hasn’t adopted a free, one-line standard in eleven years. If you want a clean case study in how far a correct, cheap, zero-maintenance standard gets on its own merits without a forcing function — no browser warning, no compliance mandate, no provider default at the registries that matter — this is it. Compare TLS, which had browsers shaming HTTP pages, or DMARC, which had Google and Yahoo turning it into a bulk-sender requirement. Null MX has no enforcer. 7.0% is what no-enforcer adoption looks like.
How we measured this
- Population and denominator: 376,928,781 graded domains from the August 2026 census round (figures as of 2026-08-16, methodology v9). The census scanned 432,127,908 domains in total; this article uses the graded-only basis throughout. Our live site’s headline grade distribution uses a different basis that counts dead domains as F — the two are deliberately not mixed here.
- Null MX count: 14,455,076 domains whose MX records matched the RFC 7505 pattern (a record with priority 0 and a ”.” target, with no valid mail exchanger alongside) in census DNS evidence.
- Working-MX and no-MX cohorts: our mx-record check passes a domain that has either valid MX records or a correct null MX (a null MX is a correct configuration, not a failure). 184,229,915 graded domains pass that check; subtracting the null MX cohort gives 169,774,839 with real mail service, and the remaining 192,698,866 graded domains have no MX record at all.
- Limits of the no-MX figure: the silent cohort is computed as graded-minus-passing, so it includes a small number of domains whose MX lookup failed at scan time and could not be classified either way. Treat the boundary between “silent” and “working” as accurate to well within a percentage point, not to the last domain.
- SPF/DMARC overlap: approximately 81.6% of silent no-MX domains publish neither SPF nor DMARC, derived from census overlap data. Because null MX domains pass the MX check, a null MX domain without SPF/DMARC is not counted in the silent-and-unprotected figure.
- Vantage: single scan per domain from our EU measurement infrastructure during the August 2026 round; DNS answers as served at capture time.
- Industry context (RFC publication dates, mail-server retry behaviour, the three-record no-mail pattern, enforcement history for TLS/DMARC) is labelled as such in the text and is not census data.
- Aggregate only. We publish counts and shares, never individual domains.
FAQ
What does a null MX record look like?
A single DNS MX record with priority 0 and a ”.” as the target: MX 0 . — nothing else. Under RFC 7505 (published 2015, industry context) it declares the domain accepts no email, and receiving servers reject messages to it instantly instead of retrying for days. As of August 2026, 14,455,076 domains publish one.
Should I add a null MX to my domain?
If the domain genuinely sends and receives no email — parked names, redirects, brand registrations — yes, and pair it with SPF v=spf1 -all and DMARC p=reject so the domain can’t be spoofed either (standard guidance, industry knowledge). All three records are free. If the domain handles any mail at all, a null MX will break it; this is strictly an opt-out for no-mail domains.
How much of the web has no email service? 54.9% of graded domains — 207,153,942 of 376,928,781 in our August 2026 census — have no working mail service: 192.7 million publish no MX record at all and another 14.5 million publish an explicit null MX. Just under half the graded web (45.0%) has real MX records.
Does a null MX stop email spoofing? No. Null MX governs delivery to the domain; spoofing abuses the From: address on mail sent by others, which SPF and DMARC control. Census data shows why the distinction matters: approximately 81.6% of silent no-MX domains publish neither SPF nor DMARC, leaving roughly 157 million never-sending domains open to impersonation.
Why do so few no-mail domains use null MX? Adoption sits at 7.0% of the no-mail cohort after eleven years. The record has no forcing function: the pain of its absence lands on other people’s mail servers, no browser or regulator demands it, and most owners of mail-less domains have never audited those domains’ mail posture. Where adoption exists at scale, it most likely arrives via providers deploying it as a default rather than owners acting individually (interpretation, not a measured attribution).
What is the difference between null MX and just having no MX record? Both mean no mail is delivered, but the mechanism differs critically. No MX causes the sending server to attempt A-record fallback delivery, fail, and retry for days before bouncing. A null MX signals immediate, permanent rejection — the sender knows instantly. For anyone awaiting a confirmation email sent to a typo’d domain or a retired address, the difference between a 5-day timeout and an instant bounce is significant. The null MX is also an explicit, positive declaration of intent, not an absence.
Does this affect brand protection registrations? Directly. Brand-protection domains — registered to prevent squatting — are among the most common no-mail domains in any corporate portfolio, and they are precisely the targets attackers use for spoofing campaigns. A portfolio of parked brand domains with no SPF, no DMARC, and no null MX is a portfolio of free spoofing vehicles. Adding three DNS records to each one is the minimum defensive posture.
What this means
For IT managers and security teams, the 157 million silent no-MX domains that also lack SPF and DMARC represent the most overlooked attack surface in most corporate domain portfolios. Parked domains, brand registrations, acquired company domains, and legacy properties tend to receive the least attention and the most spoofing abuse. The configuration required to lock down a non-sending domain is three DNS records: null MX (MX 0 .), SPF (v=spf1 -all), and DMARC (v=DMARC1; p=reject; sp=reject). This takes under ten minutes and costs nothing. The question for any security team is whether their domain portfolio audit includes this check for every domain, not just the primary ones.
For business owners managing multiple domains, the null MX finding is a prompt to audit the full portfolio rather than just the domains that actively send mail. The domains nobody monitors are the ones attackers exploit. A domain registered five years ago to protect a brand, currently parked, with no mail configuration, is a standing invitation for phishing campaigns that impersonate your business. The spoofed message looks legitimate because the domain has real history, and there is no DMARC record instructing receiving servers to reject it.
For organisations considering compliance with frameworks like NIS2 or aligning with CISA guidance, the three-record no-mail lockdown pattern — null MX, SPF -all, DMARC p=reject — is exactly the posture regulators and advisories describe for non-sending domains. It is free, permanent, and requires no ongoing operational overhead. At 7% adoption after eleven years, the barrier has never been cost or complexity. It has always been awareness.
Data to cite
- “14,455,076 domains publish a null MX record (RFC 7505), declaring they accept no email — just 7.0% of the 207 million no-mail domains in the August 2026 census.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “192,698,866 graded domains — 51.1% of the web — have no MX record at all, staying silent when they should declare they accept no mail.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “For every domain that formally opts out of email with a null MX, 13.3 domains stay silent with no MX record of any kind.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “81.6% of silent no-MX domains — roughly 157 million — publish neither SPF nor DMARC, leaving them open to impersonation by anyone who wants to spoof their brand.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “54.9% of graded domains — 207,153,942 of 376,928,781 — have no working mail service but most have never declared this explicitly.” — defaults.exposed August 2026 Domain Security Census (432M domains)
- “Null MX adoption sits at 7.0% of its addressable population after eleven years, demonstrating what no-enforcer adoption looks like for a correct, free, zero-maintenance standard.” — defaults.exposed August 2026 Domain Security Census (432M domains)
Related reading
- The Email Spoofability Index — how spoofable the graded web is, domain by domain cohort.
- Can someone spoof my domain? — the spoofing mechanics this article’s 157 million figure feeds into.
- 119 Million Domains Publish SPF With No Enforcement — the other half of the “published but not protecting” problem.
- The Email Authentication Guide — SPF, DKIM and DMARC from zero, including the no-mail lockdown pattern.
See where your own domain stands
A no-mail domain done right takes three free DNS records and five minutes. Our census grades real, live domains across externally observable security checks, and most of what a failing domain is missing costs nothing to fix — the barrier is almost never cost, it’s that nobody told the owner it mattered. You can check your domain privately and free, and see exactly which checks you pass.
Check your domain free at defaults.exposed — see instantly whether your domain’s email configuration is locked down against spoofing or silently open for anyone to impersonate. Takes 30 seconds. No account needed.
Read the flagship census report: The State of Domain Security 2026 →
Aggregate data only. Data stored and processed in the EU.
How to cite this report
Press / blog: defaults.exposed (2026). Null MX Adoption 2026: 14.5 Million Domains Opt Out. defaults.exposed August 2026 Domain Security Census (432,127,908 domains scanned, asOf 2026-08-16). Retrieved from https://defaults.exposed/en/articles/null-mx-adoption-report
Academic: defaults.exposed. (2026, August 18). Null MX Adoption 2026: 14.5 Million Domains Opt Out. In defaults.exposed Domain Security Census: August 2026. https://defaults.exposed/en/articles/null-mx-adoption-report
In-line citation: (defaults.exposed, August 2026 Domain Security Census, n=376,928,781)
About the defaults.exposed August 2026 Census
The defaults.exposed Domain Security Census is a recurring independent measurement of the public domain namespace. The August 2026 edition scanned 432,127,908 domains between 1–16 August 2026 and graded 376,928,781 of them using methodology v9. Scans are conducted from EU infrastructure. No individual domain, registrant, or business is named in any report. All figures are aggregate distributions. Data is stored and processed within the EU.
Methodology: defaults.exposed/en/articles/domain-security-scoring-methodology-v9 Full census report: defaults.exposed/en/articles/the-state-of-domain-security-2026
Aggregate data only. Data stored and processed in the EU.