Blog article

Author Profile Picture

The MTA Landscape Is Shifting: Why Domain Owners Should Start Paying Attention

Mta Digital Funnel With Email Envelopes

Your business most likely sends messages through an email service provider (ESP). Do you know what software actually handles those emails, and whether it meets your organization’s security standards or keeps up with changes in the email ecosystem?

Most CISOs and IT admins can’t answer that question. Not because they’ve been careless, but because nobody asked them to think about it. Using an ESP has always been framed as an outsourcing decision: hand over sending, get deliverability and scale in return. What runs underneath hasn’t historically been the domain owner’s concern.

In light of a string of acquisitions, new players entering the market, and evolving threats, domain owners should now take a closer look.

The Hidden Layer in Your Email Stack

All ESPs rely on a mail transfer agent (MTA), the software that queues, routes, and delivers outbound emails. It runs entirely on the ESP’s side, invisible to the domain owner.

Your ESP’s MTA choice can affect:

  • Deliverability. The MTA layer can quietly affect whether or not your critical communications, billing notices, security alerts, and customer updates are delivered timely and to the inbox.
  • Incident response. When something breaks, that means investigating DNS issues, queue management, ISP rejections, and problematic IPs. Each MTA transition follows the same pattern: the responsible team has to learn new technology, build appropriate monitoring, and shift from maintaining a known system to implementing an unfamiliar one.
  • Security. An MTA is also a security control point: TLS encryption depends on how it’s configured, and DKIM signing happens at this layer too. How your ESP configures its MTA affects your own exposure.
  • Adaptability. Email authentication keeps evolving, from the changes introduced in DMARCbis to the emerging DKIM2 standard. Staying current takes the kind of specialist attention that’s often consumed with integration efforts and minimizing operational costs.

What Has Changed in the MTA Market

The market for enterprise MTA software has gone through both expansion and consolidation over the last 10 years. Today, ESPs have more choices than they ever did before, which should lead to more MTA changes than we saw previously.

Message Systems, the company behind Momentum, acquired Port25 Solutions, its biggest on-premises rival and the company behind PowerMTA, in 2015. Message Systems then created SparkPost, while Momentum and PowerMTA kept shipping under their existing names. MessageBird acquired SparkPost in 2021 for approximately $600 million, and MessageBird was rebranded to Bird in 2024.

Most recently, Infobip announced its acquisition of SocketLabs, an established ESP that authored and maintains its Hurricane MTA, which runs several other ESPs. This move should result in more choice across a broader, global audience.

Consolidation isn’t the whole story, though. While some MTAs are being bought and sold, others are entering the market: Laneful, SignalMTA, and Anypost have all launched recently. Meanwhile, established providers like GreenArrow, Halon, and MailerQ remain major players in the space.

Whether it’s new entrants or shifting ownership, change is the constant – and it’s worth keeping an eye on.

The Open-Source Disruption

The other force reshaping this market is open-source infrastructure, led by KumoMTA. Released under the Apache 2.0 license, KumoMTA is free to run, with revenue coming from paid support tiers rather than sending volume.

It was built by a team of former Message Systems engineers, and it has already picked up real-world adoption: AWeber, Active Campaign, and Postmark have migrated their sending infrastructure to it.

That model undercuts how legacy commercial MTAs, including PowerMTA and Momentum, have priced their software for years. With a genuinely free alternative on the table, commercial vendors are left justifying a fee,  and the market is likely headed to a correction to remain competitive.

The MTA market is moving faster than it has in years, and is likely to continue maturing. Vendors are merging, rebranding, and shifting underlying infrastructure – sometimes more than once in a short time span.

More choice and more competition among MTA vendors is good for the market. It drives innovation and keeps prices honest. But it also means domain owners can no longer assume the infrastructure behind their ESP today is the same as it was a year ago – or that it’ll stay the same a year from now. Knowing which infrastructure choice your ESP has made, and staying alert to when that changes, is becoming part of the job.

The Security Implication

The MTA is what actually sends your email, and that’s where three things matter most: DKIM signing capabilities, configuration support for alignment, and TLS encryption.

In the case of DKIM, a 2048-bit key length is the modern-day standard. Wondering how you find out about what key lengths? DMARC data is the easiest and most comprehensive way to identify weak keys in rotation.

Aligning both SPF and DKIM is critical to email security, as they are the foundation for DMARC, the leading technology to defend against phishing and domain abuse. Though DMARC only requires either DKIM or SPF, the best practice is to configure both.

TLS encryption ensures that messages being sent on your behalf are protected from being intercepted and modified before reaching the intended recipient. Though TLS enforcement happens at the receiving end, it’s important that all legitimate senders help grow adoption, so that more aggressive changes to standards and best practices can be realized.

Not sure where your own domain stands on any of this? Your DMARC data already has the answer.

Questions to Ask Your ESP

This isn’t a case for switching providers or auditing every vendor relationship from scratch. It is a case for closing a blind spot most security teams didn’t know they had.

Three questions are a reasonable place to start:

  1. What MTA software currently powers our outbound sending?
  2. If it has changed, was the change disclosed to us, and when?
  3. If your infrastructure changes, what is your notification process?

None of these questions assumes bad faith on the ESP’s part. They assume, correctly, that infrastructure decisions made upstream now carry consequences for the domain owner downstream – and that it’s worth knowing more about a layer that’s never demanded attention before.

The MTA layer used to be safe to ignore, back when the market underneath it barely changed. Given how much consolidation and change are happening now, that’s no longer true.

Before you take these questions to your ESP, check where your own domain’s DMARC policy and configuration actually stand.

Check your domain

If you’re at risk of impersonation, one of our experts will be in touch to assist.