The MCP spec lands in 48 hours. I scanned 671,693 domains first. The layer under your email agents is rotting.

The MCP spec lands in 48 hours. I scanned 671,693 domains first. The layer under your email agents is rotting.

MCP 规范将在 48 小时内发布。我先扫描了 671,693 个域名。你邮件代理底层的架构正在腐烂。

AgentMail, Cloudflare Email Service, Resend’s agent SDK. Every AI SDR startup on Product Hunt this month. The pitch is always the same: “one API call and your agent has an inbox.” Cool. I went and measured the ground they’re all standing on. 671,693 domains with MX records. 634,220 with SPF. 468,749 with DMARC. Daily forward-DNS scan of the Tranco top-1M, snapshot 2026-07-25.

AgentMail、Cloudflare 邮件服务、Resend 的代理 SDK。本月 Product Hunt 上的每一个 AI SDR(销售开发代表)初创公司,推销的话术总是如出一辙:“只需一个 API 调用,你的代理就拥有了收件箱。” 听起来很酷。我去测量了他们赖以生存的基础。在 671,693 个拥有 MX 记录的域名中,634,220 个配置了 SPF,468,749 个配置了 DMARC。这是基于 2026 年 7 月 25 日 Tranco 前 100 万域名快照进行的每日正向 DNS 扫描结果。

Here’s the number that should ruin your afternoon: Last month the internet added 9,173 net new DMARC domains. DMARC enforcement went DOWN 0.42 percentage points. Read it again. More people published DMARC. Less of the internet is protected. Three out of four of those new records were a p=none sticker. That is not adoption. That is dilution wearing an adoption costume.

下面这个数字可能会让你整个下午心情糟糕:上个月互联网净增了 9,173 个 DMARC 域名。但 DMARC 的强制执行率反而下降了 0.42 个百分点。再读一遍:更多人发布了 DMARC 记录,但互联网的保护程度却降低了。这些新记录中,四分之三只是贴了个 p=none 的标签。这根本不是普及,这只是披着普及外衣的稀释。

Gut punch #1: a quarter of all DMARC records are load-bearing nothing

重击 #1:四分之一的 DMARC 记录毫无实际作用

Break the 468,749 DMARC-publishing domains down by what the record actually does: 将这 468,749 个发布了 DMARC 的域名按其实际功能拆解如下:

CategoryDomainsShare
Enforcing (p=quarantine / p=reject)~231,10049.31%
Monitoring (p=none, but reports flow)~120,00025.61%
Inert (p=none, no working rua=)117,38425.04%
Invalid / other~2000.04%

That third row is my favourite thing on the internet right now. 117,384 domains publish a DMARC record with p=none and no working aggregate report address. It blocks nothing. It reports nothing. It is a TXT record whose entire function is to make a compliance checkbox turn green. v=DMARC1; p=none; Twenty characters of pure theatre. Somebody billed for that. (It is, verbatim, the single most common DMARC record on the internet: 58,997 domains carry exactly that string.)

第三行是我目前在互联网上最喜欢的东西。117,384 个域名发布了 p=none 且没有有效聚合报告地址(rua)的 DMARC 记录。它不拦截任何东西,也不报告任何东西。这只是一条 TXT 记录,其唯一功能就是让合规性检查框变绿。v=DMARC1; p=none; 这二十个字符纯粹是一场戏。有人还为此收了费。(这确实是互联网上最常见的 DMARC 记录:58,997 个域名完全使用了这一字符串。)

And it gets funnier when you zoom out from “inert” to “blind”: 35.51% of all DMARC-publishing domains — 166,442 of them — have no working rua= address. 166,442 domains published an email authentication policy and then unplugged the telemetry. Some of them are on p=reject. Think about that: they are actively bouncing mail and they cannot see whose. If a partner integration breaks tomorrow, they find out via an angry phone call in three weeks. You would never ship a service with the metrics endpoint deleted. A third of the web ships its email policy exactly that way.

当你从“惰性”扩展到“盲目”时,情况就更搞笑了:35.51% 的 DMARC 域名(即 166,442 个)没有有效的 rua= 地址。166,442 个域名发布了邮件认证策略,然后拔掉了遥测系统的插头。其中一些甚至设置了 p=reject。想想看:他们正在积极地拒收邮件,却无法看到是谁的邮件被拒。如果明天的合作伙伴集成出现故障,他们要等到三周后接到愤怒的投诉电话才会发现。你绝不会在删除了指标端点的情况下发布服务,但三分之一的互联网正是这样发布其邮件策略的。

Gut punch #2: security is a function of how famous you are

重击 #2:安全性取决于你的知名度

Split DMARC enforcement by Tranco rank tier: 按 Tranco 排名层级划分 DMARC 执行情况:

TierEnforced
top 1k73.05%
1k–10k56.46%
10k–100k43.34%
100k–1M29.81%
Not in the current list19.10%

The head of the internet is 3.8× more defended than the tail. Every “email authentication is basically solved in 2026” take you have read was written by someone who checked google.com, stripe.com and their own employer, all of which live in that first row. Step outside the top 1k and most domains are wide open. Your agent’s prospects live in the tail. Your agent’s customers live in the tail. Your vendors, your webhooks, your billing provider’s regional subsidiary — tail, tail, tail.

互联网头部受到的保护是尾部的 3.8 倍。你读过的每一篇关于“2026 年邮件认证已基本解决”的文章,都是由那些只检查了 google.com、stripe.com 和他们自己雇主公司的人写的,而这些公司都处于第一行。一旦走出前 1000 名,大多数域名都是完全敞开的。你代理的潜在客户在尾部,你的客户在尾部,你的供应商、Webhook、计费提供商的区域子公司——全都在尾部。

Gut punch #3: self-hosting email is not dead. It is #1.

重击 #3:自建邮件服务器并没有死,它排名第一。

The received wisdom of the last decade: nobody self-hosts email anymore, it’s Google and Microsoft, give up. Inbound mail hosting across those 671,693 domains: 过去十年的普遍认知是:没人再自建邮件服务器了,全是 Google 和 Microsoft,放弃吧。但在那 671,693 个域名中,入站邮件托管情况如下:

RankProviderShare
1Self-hosted22.79%
2Google Workspace21.83%
3Microsoft 36516.87%

Self-hosted is the single largest category. Bigger than Google. 153,105 domains running their own MX in the year the entire industry told you it was impossible. Google + Microsoft together are 38.70%, which is a genuinely alarming concentration number and the one everybody quotes. Nobody quotes the row above it, because it makes a decade of “just move to Workspace” content look like marketing. Two things are true at once: the duopoly is real, and the graveyard everybody describes is full of living people.

自建服务器是最大的单一类别,比 Google 还要大。在整个行业都告诉你这不可能的年份里,有 153,105 个域名在运行自己的 MX 记录。Google 和 Microsoft 合计占 38.70%,这是一个确实令人担忧的集中度数字,也是每个人都在引用的数据。没人引用上面那一行,因为它会让过去十年“迁移到 Workspace”的内容看起来像是一场营销。两件事同时成立:双头垄断是真实的,而每个人口中的“坟墓”里其实挤满了活人。

Gut punch #4: one domain in four has a stranger in its SPF allowlist

重击 #4:四分之一的域名在 SPF 白名单中包含陌生人

I extracted every SPF include: / redirect= target across those 634,220 SPF-publishing domains and matched them against open dictionaries of ESPs, SaaS senders and security gateways. Classification coverage: 82.66% of include targets. That leaves 80,991 unique include targets that no public dictionary can name. And the per-domain view is worse: only 72.37% of domains that delegate through an include: come back fully classified — more than one in four has at least one entry in its sending allowlist that cannot be identified.

我提取了那 634,220 个发布了 SPF 的域名中所有的 include: / redirect= 目标,并将它们与 ESP(邮件服务提供商)、SaaS 发送方和安全网关的公开字典进行了匹配。分类覆盖率为 82.66%。这意味着有 80,991 个唯一的 include 目标是任何公开字典都无法识别的。按域名查看的情况更糟:只有 72.37% 通过 include: 授权的域名能被完全分类——超过四分之一的域名在其发送白名单中至少有一个无法识别的条目。

This is the part that should actually scare you, and it is 100% the agent story. Every agentic email product onboards you the same way: “add our include: to your SPF and you’re done.” You paste it. It stacks onto the eleven that are already there from the CRM, the ticketing tool, the marketing automation, the e-sign vendor, the abandoned 2021 webinar platform nobody has admin access to anymore. An include: is not a config line. It is a standing grant of permission to send mail as you. Forever. There is no expiry. There is no audit log. There is no “this include has not been used in 400 days” dashboard, anywhere, from anyone. And SPF hard-caps at 10 DNS lookups. Blow past it and the whole record fails — not degrades, fails. Which means the way most teams discover their SPF is over budget is that legitimate mail stops arriving and nobody knows why, because — see gut punch #1 — the rua= was never wired up.

这才是真正应该让你感到害怕的部分,而且这完全是代理(Agent)带来的问题。每一个代理邮件产品都用同样的方式引导你:“把我们的 include 添加到你的 SPF 中,就完成了。” 你粘贴了它。它堆叠在 CRM、工单工具、营销自动化、电子签名供应商以及那个没人有管理员权限的 2021 年废弃网络研讨会平台留下的那十一个条目之上。include: 不是一行简单的配置,它是永久授权对方以你的名义发送邮件的许可。没有过期,没有审计日志,没有任何地方、任何人提供“此 include 已 400 天未使用”的仪表盘。而且 SPF 硬性限制为 10 次 DNS 查询。一旦超过,整个记录就会失效——不是降级,是直接失效。这意味着大多数团队发现 SPF 超限的方式是合法邮件停止送达,且没人知道原因,因为——参考重击 #1——rua= 从未配置过。

Why agents turn this from “tech debt” into “outage”

为什么代理会将这从“技术债务”变成“服务中断”

A human SDR ramps slowly. Writes differently on Tuesday than on Thursday. Gets bored, gets sick, takes PTO. All of that accidental noise is what sender reputation is calibrated against. An agent fleet does none of that: 人类 SDR 的工作节奏很慢。周二和周四的写作风格不同。会感到无聊、生病、休假。所有这些偶然的“噪音”正是发送方信誉校准的依据。而代理集群完全不会这样:

  • Volume concentration. Ten humans’ worth of output leaves through one domain, one auth path, one reputation bucket. 流量集中。 十个人的工作量通过一个域名、一个认证路径、一个信誉桶发出。
  • Content convergence. One model, one system prompt, one voice. Filters cluster on exactly that. 内容趋同。 一个模型、一个系统提示词、一种语调。过滤器正是针对这些进行聚类拦截的。
  • Ramp velocity. Reputation builds over quarters. An agent goes zero to full throttle the afternoon you deploy it. 启动速度。 信誉的建立需要几个季度。而代理在你部署的当天下午就从零直接全速运行。

Bolt that onto a domain with p=none, no rua=, and twelve unaudited include: grants, and you have not built an outbound channel. You have built a very fast way to set your domain on fire, with the smoke alarm removed. 将这些叠加在一个 p=none、没有 rua= 且有十二个未经审计的 include: 授权的域名上,你构建的根本不是外发渠道。你构建的是一种让你的域名迅速起火,同时还拆掉了烟雾报警器的方法。