Skip to content

Self-Managed Mail Infrastructure Detected

It means the domain operates its own mail exchange (MX) servers instead of relying on trusted third-party providers like Google Workspace, Microsoft 365, or Proofpoint. Self-managed MX setups are often used by threat actors to control phishing or spam email delivery infrastructure.

Also surfaces as:
Newly Activated Self-Managed Mail Infrastructure
Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'Self-Managed Mail Infrastructure Detected' mean?

It means the domain operates its own mail exchange (MX) servers instead of relying on trusted third-party providers like Google Workspace, Microsoft 365, or Proofpoint. Self-managed MX setups are often used by threat actors to control phishing or spam email delivery infrastructure.

Why it matters02

Why is self-managed MX considered a suspicious indicator?

Because legitimate organizations usually prefer managed email solutions that include authentication, encryption, and anti-spam protection. Self-managed MX servers offer full control but lack oversight, making them attractive for malicious email campaigns.

How analysts use it03

What does 'Newly Activated Self-Managed Mail Infrastructure' indicate?

It indicates that the domain has recently created or switched to its own MX servers. Such sudden MX activation often precedes phishing, business email compromise (BEC), or spam campaigns, signaling a potentially malicious infrastructure setup.

Often paired with:block_domain
Evidence shape

What Self-Managed Mail Infrastructure Detected looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "own_mx_usage",
  "name": "Self-Managed Mail Infrastructure Detected",
  "group": "dns_history",
  "subgroup": "dns_records_mx_ns",
  "direction": "malicious",
  "evidence": {
    "ns_provider": "cloudflare.com",
    "ns_provider_tier": "paid_public",
    "ns_stability_days": 412,
    "mx_provider": "google.com",
    "mx_provider_tier": "paid_mail"
  }
}
See in API reference
Siblings

Peers in DNS Records (MX/NS)

8 other signals share the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Self-Managed Name Server Detected

It indicates that the domain operates using its own name server infrastructure rather than a reputable third-party DNS p

Malicious
Double-Flux Behavior Detected

It indicates that both IP and NS (nameserver) records of a domain are changing frequently, a behavior known as 'Double-F

MaliciousCore
Mail-Flux Behavior Detected

It indicates that the domain frequently changes its MX (Mail Exchange) records. Such behavior is often associated with s

Malicious
Stable MX Usage Long Term

It shows the domain has been using the same mail exchange servers for an extended period, reflecting stable and predicta

Safe
Show 4 more in DNS Records (MX/NS)
In the wild

See Self-Managed Mail Infrastructure Detected fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Self-Managed Mail Infrastructure Detected. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.