Defaults.Exposed

Defaults.ExposedReports

Null MX Adoption 2026: 14.5 Million Domains Opt Out

Published

Figures as of 2026-08-16 · methodology v9. This is a recurring report; each edition re-measures the same population so the numbers can be tracked over time. All figures are aggregate — we never publish an individual business’s grade or name an individual registrant’s domain.

How many domains actually use null MX?

14,455,076 domains publish a null MX record — the RFC 7505 declaration that a domain sends and receives no email — out of 376,928,781 graded domains in our August 2026 census. That is 3.8% of the graded web, which sounds respectable until you see the cohort it should be measured against. Roughly 207 million graded domains have no mail service at all. Only one in fourteen of them says so properly. The other 192.7 million just stay silent, and silence is the worst possible configuration for a domain that receives no mail.

The standard is eleven years old. RFC 7505 was published in June 2015 (industry context, not census data), and it asks almost nothing of a domain owner: one DNS record, MX 0 ., priority zero, target dot. It costs nothing, takes a minute, and tells every mail server on earth “don’t bother.” Adoption at 7.0% of the population it was written for, a decade in, is the story.

Key numbers

What is a null MX record?

A null MX is a single DNS record: MX 0 . — priority 0, exchange ”.”. Under RFC 7505 it means the domain does not accept email, full stop. A sending mail server that sees it can reject the message instantly with a permanent error, and the sender finds out in seconds that their mail will never arrive.

Compare that with what happens when a no-mail domain publishes nothing. The sending server finds no MX, falls back to trying the domain’s A record (a legacy behaviour older than most of the people configuring mail today), fails to connect, and queues the message for retry. Standard mail-server defaults keep retrying for several days before giving up (protocol behaviour, industry knowledge — not a census measurement). The sender waits days to learn what a null MX would have told them in milliseconds. Misdirected invoices, password resets sent to a typo’d domain, replies to a decommissioned brand — all of it hangs in a queue, going nowhere, telling nobody.

That is the whole pitch. One record converts days of ambiguity into an instant, honest no.

The mail landscape of the graded web

Here is where all 376.9 million graded domains sit. One denominator throughout this article: the 376,928,781 graded domains of the August 2026 round (the census also scanned 432 million domains in total; ungraded dispositions are excluded here).

CohortDomainsShare of graded
Working MX records (real mail service)169,774,83945.0%
No MX record at all (silent no-mail)192,698,86651.1%
Null MX — explicit no-mail (RFC 7505)14,455,0763.8%
Total graded376,928,781100%

Two readings of that table matter.

First, the no-mail web is enormous. 54.9% of graded domains — parked names, brand-protection registrations, redirect shells, single-page projects — have no mail service. More than half the registered, resolving web neither sends nor receives a single message. That cohort is exactly who RFC 7505 was written for.

Second, inside that cohort, explicit beats silent 14.5M to 192.7M — a ratio of 1 to 13.3 in the wrong direction. The standard lost to the default, and the default is “do nothing.”

Fourteen and a half million is not nothing, to be fair. Our census can’t attribute adoption from a single count, but a number that size almost certainly reflects infrastructure providers and registrars deploying null MX automatically on parked and mail-less zones, rather than fourteen million individual owners reading an RFC (interpretation, not a measured attribution). Where a provider makes it the default, adoption happens. Where an owner has to know the record exists, it mostly doesn’t.

Why does a no-mail domain need any DNS records for email?

Because spoofing doesn’t care whether you receive mail. Anyone can put your domain in the From: line of an email. Receiving systems check SPF and DMARC — published by your domain — to decide whether to believe it. A no-mail domain with no SPF and no DMARC is a free costume: it will never send a legitimate message, and nothing it publishes tells the world that.

The census puts numbers on how bad this is. Of the 192,698,866 silent no-MX domains, approximately 81.6% — roughly 157 million — publish neither SPF nor DMARC. Call it what it is: 157 million domains that will never send an email and are configured so that anyone else can send email as them.

A null MX doesn’t fix spoofing by itself. It handles delivery, not authentication. The well-understood full opt-out for a no-mail domain is three records — null MX, an SPF record of v=spf1 -all, and DMARC p=reject (standard operational guidance, industry knowledge) — and every one of them is free. The 14.5 million null MX publishers have at least taken the first step. The 192.7 million silent domains haven’t taken any.

Why hasn’t RFC 7505 caught on?

Three honest reasons, none of them technical.

Nobody feels the pain. The cost of a missing null MX lands on other people’s mail queues. The domain owner never sees the misdirected messages spinning for days, so nothing prompts them to act. Records get deployed when their absence hurts the person who controls the zone. This one doesn’t.

Awareness is near zero outside mail-operations circles. SPF and DMARC at least appear in compliance checklists and deliverability guides. Null MX appears almost nowhere. A domain owner who has never sent mail from a domain has usually never thought about that domain’s mail posture at all.

And the default does something that looks like the right thing. No MX record means mail eventually fails, and “eventually fails” is easy to mistake for “handled.” The difference between a 5-day timeout and an instant rejection is invisible until you’re the one waiting on it.

None of these change the arithmetic. One record, one minute, free. The barrier is awareness, not cost.

Is 14.5 million a lot or a little?

Both, depending on the yardstick — so here are the yardsticks.

Against the whole graded web it’s 3.8%, which makes null MX a small but measurable adoption of a record most domain owners have never heard of.

Against its addressable population it’s 7.0%, and that is the honest number. RFC 7505 exists for exactly one cohort: domains with no mail service. That cohort is 207 million strong, and 93.0% of it hasn’t adopted a free, one-line standard in eleven years. If you want a clean case study in how far a correct, cheap, zero-maintenance standard gets on its own merits without a forcing function — no browser warning, no compliance mandate, no provider default at the registries that matter — this is it. Compare TLS, which had browsers shaming HTTP pages, or DMARC, which had Google and Yahoo turning it into a bulk-sender requirement. Null MX has no enforcer. 7.0% is what no-enforcer adoption looks like.

How we measured this

FAQ

What does a null MX record look like? A single DNS MX record with priority 0 and a ”.” as the target: MX 0 . — nothing else. Under RFC 7505 (published 2015, industry context) it declares the domain accepts no email, and receiving servers reject messages to it instantly instead of retrying for days. As of August 2026, 14,455,076 domains publish one.

Should I add a null MX to my domain? If the domain genuinely sends and receives no email — parked names, redirects, brand registrations — yes, and pair it with SPF v=spf1 -all and DMARC p=reject so the domain can’t be spoofed either (standard guidance, industry knowledge). All three records are free. If the domain handles any mail at all, a null MX will break it; this is strictly an opt-out for no-mail domains.

How much of the web has no email service? 54.9% of graded domains — 207,153,942 of 376,928,781 in our August 2026 census — have no working mail service: 192.7 million publish no MX record at all and another 14.5 million publish an explicit null MX. Just under half the graded web (45.0%) has real MX records.

Does a null MX stop email spoofing? No. Null MX governs delivery to the domain; spoofing abuses the From: address on mail sent by others, which SPF and DMARC control. Census data shows why the distinction matters: approximately 81.6% of silent no-MX domains publish neither SPF nor DMARC, leaving roughly 157 million never-sending domains open to impersonation.

Why do so few no-mail domains use null MX? Adoption sits at 7.0% of the no-mail cohort after eleven years. The record has no forcing function: the pain of its absence lands on other people’s mail servers, no browser or regulator demands it, and most owners of mail-less domains have never audited those domains’ mail posture. Where adoption exists at scale, it most likely arrives via providers deploying it as a default rather than owners acting individually (interpretation, not a measured attribution).

What is the difference between null MX and just having no MX record? Both mean no mail is delivered, but the mechanism differs critically. No MX causes the sending server to attempt A-record fallback delivery, fail, and retry for days before bouncing. A null MX signals immediate, permanent rejection — the sender knows instantly. For anyone awaiting a confirmation email sent to a typo’d domain or a retired address, the difference between a 5-day timeout and an instant bounce is significant. The null MX is also an explicit, positive declaration of intent, not an absence.

Does this affect brand protection registrations? Directly. Brand-protection domains — registered to prevent squatting — are among the most common no-mail domains in any corporate portfolio, and they are precisely the targets attackers use for spoofing campaigns. A portfolio of parked brand domains with no SPF, no DMARC, and no null MX is a portfolio of free spoofing vehicles. Adding three DNS records to each one is the minimum defensive posture.

What this means

For IT managers and security teams, the 157 million silent no-MX domains that also lack SPF and DMARC represent the most overlooked attack surface in most corporate domain portfolios. Parked domains, brand registrations, acquired company domains, and legacy properties tend to receive the least attention and the most spoofing abuse. The configuration required to lock down a non-sending domain is three DNS records: null MX (MX 0 .), SPF (v=spf1 -all), and DMARC (v=DMARC1; p=reject; sp=reject). This takes under ten minutes and costs nothing. The question for any security team is whether their domain portfolio audit includes this check for every domain, not just the primary ones.

For business owners managing multiple domains, the null MX finding is a prompt to audit the full portfolio rather than just the domains that actively send mail. The domains nobody monitors are the ones attackers exploit. A domain registered five years ago to protect a brand, currently parked, with no mail configuration, is a standing invitation for phishing campaigns that impersonate your business. The spoofed message looks legitimate because the domain has real history, and there is no DMARC record instructing receiving servers to reject it.

For organisations considering compliance with frameworks like NIS2 or aligning with CISA guidance, the three-record no-mail lockdown pattern — null MX, SPF -all, DMARC p=reject — is exactly the posture regulators and advisories describe for non-sending domains. It is free, permanent, and requires no ongoing operational overhead. At 7% adoption after eleven years, the barrier has never been cost or complexity. It has always been awareness.

Data to cite

See where your own domain stands

A no-mail domain done right takes three free DNS records and five minutes. Our census grades real, live domains across externally observable security checks, and most of what a failing domain is missing costs nothing to fix — the barrier is almost never cost, it’s that nobody told the owner it mattered. You can check your domain privately and free, and see exactly which checks you pass.

Check your domain free at defaults.exposed — see instantly whether your domain’s email configuration is locked down against spoofing or silently open for anyone to impersonate. Takes 30 seconds. No account needed.

Read the flagship census report: The State of Domain Security 2026 →

Aggregate data only. Data stored and processed in the EU.


How to cite this report

Press / blog: defaults.exposed (2026). Null MX Adoption 2026: 14.5 Million Domains Opt Out. defaults.exposed August 2026 Domain Security Census (432,127,908 domains scanned, asOf 2026-08-16). Retrieved from https://defaults.exposed/en/articles/null-mx-adoption-report

Academic: defaults.exposed. (2026, August 18). Null MX Adoption 2026: 14.5 Million Domains Opt Out. In defaults.exposed Domain Security Census: August 2026. https://defaults.exposed/en/articles/null-mx-adoption-report

In-line citation: (defaults.exposed, August 2026 Domain Security Census, n=376,928,781)


About the defaults.exposed August 2026 Census

The defaults.exposed Domain Security Census is a recurring independent measurement of the public domain namespace. The August 2026 edition scanned 432,127,908 domains between 1–16 August 2026 and graded 376,928,781 of them using methodology v9. Scans are conducted from EU infrastructure. No individual domain, registrant, or business is named in any report. All figures are aggregate distributions. Data is stored and processed within the EU.

Methodology: defaults.exposed/en/articles/domain-security-scoring-methodology-v9 Full census report: defaults.exposed/en/articles/the-state-of-domain-security-2026

Aggregate data only. Data stored and processed in the EU.