Skip to content

Mail-Flux Behavior Detected

It indicates that the domain frequently changes its MX (Mail Exchange) records. Such behavior is often associated with spam, phishing, or malicious email infrastructure designed to evade detection and blocking.

Also surfaces as:
Aggressive Mail-Flux Activity
Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'Mail-Flux Behavior Detected' mean?

It indicates that the domain frequently changes its MX (Mail Exchange) records. Such behavior is often associated with spam, phishing, or malicious email infrastructure designed to evade detection and blocking.

Why it matters02

What does 'Aggressive Mail-Flux Activity' mean?

It refers to excessive and rapid MX record rotation within short time intervals, suggesting the domain is part of a dynamic and evasive email delivery or phishing infrastructure.

How analysts use it03

Why is frequent MX record change considered suspicious?

Legitimate domains rarely modify their MX records frequently. Threat actors rotate MX servers to distribute load, hide malicious sources, and prolong campaign lifespans.

Often paired with:alert_only
Evidence shape

What Mail-Flux Behavior Detected looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "too_many_mx_change",
  "name": "Mail-Flux Behavior Detected",
  "group": "dns_history",
  "subgroup": "dns_records_mx_ns",
  "direction": "malicious",
  "evidence": {
    "ns_provider": "cloudflare.com",
    "ns_provider_tier": "paid_public",
    "ns_stability_days": 412,
    "mx_provider": "google.com",
    "mx_provider_tier": "paid_mail"
  }
}
See in API reference
Siblings

Peers in DNS Records (MX/NS)

8 other signals share the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Double-Flux Behavior Detected

It indicates that both IP and NS (nameserver) records of a domain are changing frequently, a behavior known as 'Double-F

MaliciousCore
Self-Managed Mail Infrastructure Detected

It means the domain operates its own mail exchange (MX) servers instead of relying on trusted third-party providers like

MaliciousCore
Self-Managed Name Server Detected

It indicates that the domain operates using its own name server infrastructure rather than a reputable third-party DNS p

Malicious
Free or Disposable Mail Service Used

It indicates that the domain relies on free or temporary mail providers. Such behavior is common among malicious or low-

Malicious
Show 4 more in DNS Records (MX/NS)
In the wild

See Mail-Flux Behavior Detected fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Mail-Flux Behavior Detected. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.