Skip to content

Stable MX Usage Long Term

It shows the domain has been using the same mail exchange servers for an extended period, reflecting stable and predictable email infrastructure.

Also surfaces as:
Stable MX Usage Consistent ProviderStable MX Usage Since Creation
Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'Stable MX Usage' indicate?

It shows the domain has been using the same mail exchange servers for an extended period, reflecting stable and predictable email infrastructure.

Why it matters02

Why is MX stability important for SOC and CTI teams?

Threat actors frequently rotate MX setups or use disposable mail infrastructure. Long-term MX stability typically aligns with legitimate operational behavior and reduces suspicion in domain triage.

How analysts use it03

How should analysts use this signal?

Use MX stability as a supporting safe indicator. It doesn’t guarantee legitimacy but strengthens a low-risk assessment when combined with other benign signals.

Evidence shape

What Stable MX Usage Long Term looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "stable_mx_usage",
  "name": "Stable MX Usage Long Term",
  "group": "dns_history",
  "subgroup": "dns_records_mx_ns",
  "direction": "safe",
  "evidence": {
    "ns_provider": "cloudflare.com",
    "ns_provider_tier": "paid_public",
    "ns_stability_days": 412,
    "mx_provider": "google.com",
    "mx_provider_tier": "paid_mail"
  }
}
See in API reference
Siblings

Peers in DNS Records (MX/NS)

8 other signals share the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Stable NS Usage Long Term

It shows that the domain has maintained the same nameserver configuration without fluctuations, suggesting predictable a

Safe
Self-Managed Mail Infrastructure Detected

It means the domain operates its own mail exchange (MX) servers instead of relying on trusted third-party providers like

MaliciousCore
Double-Flux Behavior Detected

It indicates that both IP and NS (nameserver) records of a domain are changing frequently, a behavior known as 'Double-F

MaliciousCore
Free or Disposable Mail Service Used

It indicates that the domain relies on free or temporary mail providers. Such behavior is common among malicious or low-

Malicious
Show 4 more in DNS Records (MX/NS)
In the wild

See Stable MX Usage Long Term fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Stable MX Usage Long Term. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.