Glossary

    Mailbox Provider: Definition, How It Is Measured, and Where It Breaks

    The short answer

    A mailbox provider operates the mail service that receives, filters and stores mail on behalf of the recipient, so it decides whether your message reaches an inbox. In B2B that means mostly Google Workspace and Microsoft 365, plus smaller hosted providers and security gateways placed in front of them.

    Key takeaways

    • The mailbox provider owns the placement decision, so a sending platform reporting a message as delivered is reporting acceptance at the boundary, not where it was filed.
    • Mailbox provider and email service provider name opposite ends of the same pipe: one is the recipient's supplier and receives, the other is yours and sends.
    • B2B outbound lands on a very concentrated set of receiving providers, so advice about diversifying across receivers does not transfer at all.
    • Google's sender guidelines publish their own terms: keep reported spam rates below 0.10%, never reach 0.30%, and send at a consistent rate rather than in bursts.

    Mailbox Provider: Definition, How It Is Measured, and Where It Breaks

    A mailbox provider is the operator of the mail service that receives, filters and stores mail on behalf of the recipient. It runs the servers your message is delivered to, applies the filtering, and decides whether what you sent appears in an inbox, in a spam folder, or nowhere at all. In cold outbound it is the only party in the chain with the authority to make that decision.

    Your sending platform can report a message as delivered. What that means is that a mailbox provider accepted it. Where it went afterwards was never your platform's call.

    Who they are and what they do on receipt

    In B2B the population is narrow. Most business mail in the addressable market is handled by Google Workspace or Microsoft 365, with the remainder spread across smaller hosted providers, a long tail of regional hosts, and a shrinking number of organisations running their own mail servers. You do not have to take that on trust for your own list: resolve the MX records for a sample of your target domains and the concentration is visible in a few minutes, on your list rather than on an average.

    What happens when your message arrives is a chain of judgments, and they are made in a rough order.

    Connection and authentication. The receiving server looks at the connecting host, its address reputation, and its behaviour, then evaluates SPF, DKIM and DMARC. Failures here are cheap for the receiver to act on, which is why they get acted on first. The setup that keeps this half clean is covered in SPF, DKIM and DMARC for cold email, and the Microsoft-specific rollout in setting up DMARC on Microsoft 365.

    Sender reputation. The provider holds a history against your sending domain and your addresses: how much you send, how steadily, how many of your recipients report you, how many addresses you write to do not exist. This is where most cold email is actually decided, and none of it is visible in your own tooling.

    Recipient-side signals. Whether people at that organisation have written to you, replied to you, or marked you as spam. A provider watching an individual mailbox has information nobody else in the chain has.

    Content and links. The message itself, its structure, the domains it links to, and how closely it resembles mail the provider has already classified.

    That third item deserves a note, because the word "delivered" in a campaign dashboard is doing far less work than it appears to. Acceptance happens at the boundary, during the delivery conversation, and it is a statement that the receiving system is willing to take custody of the message. Filing is a separate decision made afterwards, inside the provider, with no reply sent back to you. A message accepted and then filed into a spam folder produces exactly the same result in your reporting as one accepted and placed in an inbox. Every metric a sending platform can show you is measured before the decision you care about has been taken.

    Organisation-level policy. In B2B this is the one people forget. A Google Workspace or Microsoft 365 tenant is administered by the customer, and administrators add their own rules on top of the provider's: quarantine policies, allow and block lists, external-sender warnings, and third-party gateways placed in front of the mailbox entirely. Two recipients at the same provider can therefore get different outcomes from the same message.

    1. Step 1Connection and authentication

      The connecting host, its reputation, and the SPF, DKIM and DMARC results. Cheapest checks, applied first.

    2. Step 2Sender reputation

      The provider's private history of your domain: volume, steadiness, complaints, and how many of your addresses do not exist.

    3. Step 3Recipient-side signals

      Whether this organisation has written to you, replied, or reported you before.

    4. Step 4Content and links

      Message structure, the domains in the body, and resemblance to mail already classified.

    5. Step 5Tenant policy

      Rules the customer's own administrator added, including gateways in front of the mailbox. Same provider, different outcome.

    The order a mailbox provider works through when your message arrives.

    Google is unusual in publishing its expectations plainly. Its sender guidelines tell senders to "Keep spam rates reported in Postmaster Tools below 0.10% and avoid ever reaching a spam rate of 0.30% or higher," warn that "Over time, user spam reports can lower your domain's reputation," and instruct senders to "Send email at a consistent rate. Avoid sending email in bursts."

    0.10%Keep reported spam rates below this

    Google's sender guidelines, measured in Postmaster Tools

    0.30%Avoid ever reaching this

    Same page, stated as a level to never hit rather than a target

    The two spam-rate figures Google's own sender guidelines publish, in Postmaster Tools terms.

    Those are the receiving side's own published terms, and reading the numbers behind them is what Google Postmaster Tools for cold email is for. Note the shape of the advice: it is about volume, steadiness and complaints, which are properties of how a programme is run rather than of any individual message.

    Where the term breaks: two words for opposite ends of one pipe

    "Mailbox provider" and "email service provider" are used interchangeably in a great deal of writing, and they name opposite ends of the same pipe.

    The mailbox provider receives and judges. The email service provider sends on your behalf. One is the recipient's supplier and answers to the recipient. The other is your supplier and answers to you. They have opposed incentives on almost every question that matters, which is exactly why conflating them produces bad decisions.

    Mailbox providerthe receiving side
    • Runs the mailbox your message is delivered to
    • Chosen and paid for by the recipient
    • Decides inbox, spam folder or nothing
    • Holds reputation about you that you cannot see
    • Its published guidance is a rule you follow
    Email service providerthe sending side
    • Sends messages on your behalf
    • Chosen and paid for by you
    • Reports what it handed over, never where it landed
    • Holds your campaign data and your own reporting
    • Its published guidance is a vendor's advice about its product
    The conflation that produces most of the bad advice in this area.

    The practical damage runs both ways. Advice written for bulk senders about warming an IP with a sending platform gets applied to a cold programme where the receiving side never sees a dedicated address at all. Guidance written by a receiving provider about steady volume gets read as a suggestion from a vendor rather than as the rule of the party making the decision. And a sender who is unhappy with placement escalates to the party that cannot fix it, because the platform's support desk has no more visibility into a receiving provider's judgment than you do.

    The clean test when you read a claim about "the provider" is to ask who is paying whom. If the recipient pays for it, it is a mailbox provider and its published guidance is closer to a rule. If you pay for it, it is a vendor, and its guidance is worth what any vendor's is.

    The second break: B2B lands on almost nothing

    Most published deliverability writing grew up in consumer email marketing, where a list spreads across many providers, and where the standard advice therefore includes some version of diversifying across receiving providers and watching for one going bad.

    Cold B2B outbound has no such spread. A target list of businesses resolves overwhelmingly onto a very concentrated set of receiving providers, and the two large ones dominate it. Two things follow, and neither is small.

    Advice about provider diversification does not transfer at all. You cannot spread risk across receivers, because your prospects chose their own mail provider and most of them chose the same one. Whatever balancing you do is on your own side of the pipe, across sending domains and mailboxes, and it changes nothing about who is judging you.

    And one provider's judgment of you is close to being the whole outcome. If the dominant receiver in your list decides your sending domain is untrustworthy, that is not a segment of your programme degrading. It is most of it, at once, with the remainder too small to carry the campaign. The asymmetry also runs the other way: a single provider's view moving in your favour lifts almost everything. This is why a cold programme should read its signals per receiving provider rather than as one campaign-wide average, and why an average that looks acceptable can be hiding a total block at the receiver that holds most of your list.

    It also explains a pattern that confuses people. Deliverability tooling built for the consumer world reports placement across a spread of seed accounts at many providers. For a B2B list, most of those results describe receivers you will barely ever write to.

    There is a further wrinkle in the concentration, which is that the MX record does not always name the party doing the judging. A large number of business tenants place a hosted security gateway in front of their mailbox provider, so the servers that accept your message belong to a security vendor and the mailbox behind them belongs to Google or Microsoft. Two different organisations are then filtering the same message on different criteria, and the one that rejects you is often not the one whose published guidance you have been reading. When a rejection message names a vendor you do not recognise, that is what has happened, and the reply text is the only place the reason appears.

    The visibility available to you also varies sharply by receiver, which shapes how much you can learn. Google publishes a feedback surface that reports domain reputation, spam rates and authentication results for senders above its reporting thresholds. The other large B2B receiver offers nothing equivalent on the same terms, so a programme sending mostly into it is working with far less signal and has to lean harder on what its own campaigns return: delivery failures, refusal text, replies and meetings.

    What this means for a live programme

    You are optimising for a small number of judges, and the largest of them publishes its rules. That is a better position than it sounds, because it makes most of the work concrete: authenticate properly, keep the address list clean enough that failures stay rare, keep complaints low, and send at a steady rate rather than in bursts. Those are the receiving provider's own stated terms, and the diagnostic order when placement goes wrong is in the cold email deliverability guide.

    Volume steadiness is where our own operating shape and the providers' guidance meet. One message per campaign, sent once on one premise, produces a predictable and modest amount of mail from a given domain into a given receiver, and a later approach to the same person is a separate campaign with its own premise and its own list. A programme that repeatedly returns to the same inbox concentrates far more volume and far more complaint risk on exactly the small set of receivers that decide the whole outcome. The sending ceilings each provider publishes for its own customers, which constrain the sending side of the same equation, are collected in email sending limits by provider.

    The last thing worth internalising is the asymmetry of information. The mailbox provider knows your complaint rate, your invalid-address rate, your volume pattern and your history. You know what you sent and what came back. Closing part of that gap is possible on the Google side through its published tooling, and much harder elsewhere, which is a reason to treat the signals you can read as precious rather than as a formality.

    Two receiving providers decide most of the outcome, and our pay-per-qualified-meeting outbound exists for teams who would rather not spend their week negotiating with them.

    Verified as of August 2026. Verify current terms with the vendor before relying on them.

    Questions

    Frequently asked questions.

    Frequently asked questions
    What is the difference between a mailbox provider and an email service provider?
    A mailbox provider receives and judges mail for the recipient, who pays for it. An email service provider sends mail for you, and you pay for it. They sit at opposite ends of the same pipe with opposed incentives. A useful test when reading advice about the provider is to ask who is paying whom.
    Which mailbox providers matter for B2B cold email?
    Business mail is heavily concentrated on Google Workspace and Microsoft 365, with a tail of smaller hosted providers and self-hosted servers. Rather than trusting a market share figure, resolve the MX records for a sample of your own target domains. The concentration on your particular list is visible within minutes.
    Can my sending platform tell me where my message landed?
    No. It can report that a receiving system accepted the message at the boundary. Filing into an inbox or a spam folder happens afterwards, inside the provider, with no reply sent back. An accepted message filed as spam looks identical in your reporting to one placed in an inbox.
    Why do two people at the same provider get different results?
    Because business tenants are administered by the customer. Google Workspace and Microsoft 365 administrators add quarantine policies, allow and block lists, external-sender warnings, and sometimes a third-party security gateway in front of the mailbox entirely. The same message can therefore be filed differently at two organisations using the same provider.