Skip to content

Free or Disposable Mail Service Used

It indicates that the domain relies on free or temporary mail providers. Such behavior is common among malicious or low-effort infrastructures aiming to avoid traceability.

Also surfaces as:
Recently Activated Free Mail ServiceNo Active Mail Service Detected
Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'Free or Disposable Mail Service Used' mean?

It indicates that the domain relies on free or temporary mail providers. Such behavior is common among malicious or low-effort infrastructures aiming to avoid traceability.

Why it matters02

Why is free mail service usage considered risky?

Free mail providers do not verify domain ownership or identity rigorously, making them attractive for attackers creating phishing or fake business infrastructures.

How analysts use it03

What does 'No Active Mail Service Detected' suggest?

It means the domain does not operate a mail server (MX record missing). This is often seen in domains created solely for malicious redirection or hosting rather than legitimate communication.

Often paired with:alert_only
Evidence shape

What Free or Disposable Mail Service Used looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "free_mail_service",
  "name": "Free or Disposable Mail Service Used",
  "group": "dns_history",
  "subgroup": "dns_records_mx_ns",
  "direction": "malicious",
  "evidence": {
    "ns_provider": "cloudflare.com",
    "ns_provider_tier": "paid_public",
    "ns_stability_days": 412,
    "mx_provider": "google.com",
    "mx_provider_tier": "paid_mail"
  }
}
See in API reference
Siblings

Peers in DNS Records (MX/NS)

8 other signals share the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Paid Mail Service Detected

It indicates that the domain uses a paid or premium email service provider. This is typically associated with legitimate

Safe
Double-Flux Behavior Detected

It indicates that both IP and NS (nameserver) records of a domain are changing frequently, a behavior known as 'Double-F

MaliciousCore
Self-Managed Mail Infrastructure Detected

It means the domain operates its own mail exchange (MX) servers instead of relying on trusted third-party providers like

MaliciousCore
Mail-Flux Behavior Detected

It indicates that the domain frequently changes its MX (Mail Exchange) records. Such behavior is often associated with s

Malicious
Show 4 more in DNS Records (MX/NS)
In the wild

See Free or Disposable Mail Service Used fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Free or Disposable Mail Service Used. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.