What is technographic data?
Updated 24 September 2026 // by Mark Glazer, ReplyLead // what a company runs, as targeting data
- 9,847,723business domains resolved in the ReplyLead census (19 July 2026)
- 8,384,502of them had an MX record
- 28.48%of those are hosted on Microsoft 365
- 25.84%on Google Workspace
Technographic data describes the technology a company runs: its CRM, its email provider, its analytics, its hosting, the tools its job ads mention. Where firmographic data says what a company is, technographics say what it uses - and in B2B sales, what a company uses is often the most direct evidence of what it will buy next. The one technographic field that is measurable at census scale is the mail environment: in ReplyLead's 19 July 2026 census, 8,384,502 of 9,847,723 resolved business domains had an MX record, and of those 28.48% were hosted on Microsoft 365 and 25.84% on Google Workspace.
It is also operational data, not just targeting data: the single technographic field every cold email sender depends on is the recipient's mail provider, because it decides which filtering stack judges your message.
Domain technology signal scan
Enter a company domain. Your browser reads its public DNS records directly from Google and Cloudflare resolvers - TXT, MX, CNAME, NS and DMARC - and reports the technology signals that are actually observable: AI vendors, mail environment, hosting and CDN, CMS, help desk, careers and email-marketing tools. The same method behind a live ReplyLead client project. Nothing is stored, and every result shows its evidence and its confidence.
Enter a company domain and run the scan; the observable DNS technology signals appear here, each with its evidence and confidence.
Method: DNS-over-HTTPS lookups (TXT, MX, CNAME, NS, DMARC) against dns.google and cloudflare-dns.com, run in your browser. Verification records and the hosts a domain's subdomains point to are public by design. A record means a tool was provisioned; it is strong evidence, not proof of active production use. Two honest limits: absence is never proof of non-use (Claude or GPT reached through AWS Bedrock or Google Vertex leaves no DNS trace), and technologies embedded only in page JavaScript - analytics tags, ad pixels, chat widgets - are not in DNS. Reading those means fetching the page source server-side, which a browser cannot do across origins.
What technographic data covers
A technographic profile is a list of observed or inferred tools, usually grouped by layer:
- Revenue stack: CRM, sales engagement, marketing automation, billing.
- Communication stack: email provider, calendaring, chat and meeting tools.
- Web stack: CMS, analytics, tag managers, e-commerce platform, hosting and CDN.
- Product and data stack: cloud provider, databases, BI tools, developer tooling.
- Security and IT posture: identity provider, device management, email security gateway.
For a seller, each layer answers a different question: what the company already pays for, what it is likely comparing, what it would have to rip out to buy you, and which team owns the decision.
Where technographics come from, and how wrong they get
There is no registry of what companies run. Every technographic database is assembled from observable traces: script tags and headers on the public website, DNS and mail records, job postings that name tools, case studies and reviews, and marketplace integrations. That means coverage is best for web-visible tools and thinnest for internal ones - a website reveals its analytics stack to anyone who looks, while nothing public says which BI tool the finance team uses.
It also means technographics decay the same way firmographic fields do: tools get replaced, trials expire, job ads describe an aspiration rather than an installation. Treat a technographic field as evidence with a date on it, weigh it by how directly it was observed, and verify at the moment of use anything your campaign logic depends on.
The technographic field cold email cannot ignore
Most technographic targeting is optional. One field is not: the recipient's mail environment. Whether an address is hosted on Google Workspace, Microsoft 365 or behind a dedicated security gateway determines which filtering stack evaluates your message, and it is directly observable from DNS - no vendor database required. We measured it at census scale: across 9,058,780 B2B mailboxes, the receiving landscape splits between Google, Microsoft and gateway-fronted environments, and our own sending infrastructure is built around that fact - separate Google and Microsoft sending pools, run at very different daily volumes, so one degraded pool cannot stop a programme. You can check any domain's environment with the mail provider lookup.
ReplyLead first-party dataThe receiving landscape, and what each slice means for a campaign
In our 19 July 2026 census snapshot, 8,384,502 business domains had an MX record (of 9,847,723 resolved). The per-provider figures below are computed on that snapshot, not on the current population, which is published with the full method on who actually receives B2B email. Mail capability across all 9,847,723 domains of that snapshot is broken down in our mail-capability index. Click a provider to see the outbound decision it drives - this is the same reading we apply before a single email is sent.
Outbound implication
Microsoft 365 - 28.48%
The single largest receiving environment. Microsoft applies tenant-level external-recipient throttling and Defender filtering, so mailboxes here tolerate far less volume than Google. We run a separate M365 sending pool at a low daily rate.
~1-2 cold sends / mailbox / day
Domain-level shares, not weighted by company size. The gateway bar is nine security products summed (a category, shown striped). Full method, the size effect and every provider: the complete provider census.
How technographics are used in practice
- Fit filters. If your product integrates with two CRMs, companies running them are a different list from companies running anything else. That is a technographic filter applied at list build time.
- Displacement targeting. Selling against a specific tool means building the list of its visible users. This is the sharpest use of technographics and the one most sensitive to stale data.
- Personalization with restraint. Naming a prospect's stack can demonstrate homework or read as surveillance; the difference is whether the observation is public and relevant. Copy should use technographic facts the way a good seller would in conversation - as context, not as a party trick.
- Routing and deliverability. Segmenting sends by recipient mail environment is operational technographics: it changes sending pool, volume and expectations before a word of copy is written.
How a technology signal becomes a cold-email campaign
A signal on its own is trivia. The value is the path from a signal to a message a specific person wants to receive. Pick a signal type to walk the whole route.
Firmographic, technographic, intent: the data stack in one view
The three data layers answer successive questions. Firmographics: can this company buy? Technographics: what does it already run, and does that make us relevant? Intent signals: is it looking right now? Cold email programmes are usually built on the first two, because they are observable and auditable; intent data is probabilistic and priced accordingly. Whatever the mix, the record still has to resolve to a real person with a verified address - data layers rank prospects, but only verification at send time protects the sending domains.
We turn signals like these into booked meetings
The detection, the ICP gate, the decision-maker, the campaign route and the copy - run end to end, paid mostly from the revenue that closes.
How our lists are built Apply to work with usWhen this page does not apply
- You need vendor-grade technographics for software categories. This page observes what DNS exposes (mail environment, hosting, verification records); CRM or analytics coverage needs a data vendor, and the checks for choosing one are on lead list building.
- You want the full provider census by company size or industry. That breakdown, its method and the CSV are on the provider census page; this page uses the domain-level shares only.
- You are reading this months from now. The shares are a snapshot of 19 July 2026; the census is re-resolved periodically and the current figures are on the census page.
- You need a compliance read, not a targeting read. Whether an address may be contacted is a legal question answered on is cold email legal, not a technographic one.
How this page was built and checked
The definitions and examples are ReplyLead's own, written from running outbound programs. Every number on the page comes from the ReplyLead MX census: 9,847,723 business domains resolved on 19 July 2026, of which 8,384,502 had an MX record; provider shares are computed on that MX-bearing set and are not weighted by company size. The scan tool reads public DNS records (TXT, MX, CNAME, NS, DMARC) through the Google and Cloudflare DNS-over-HTTPS resolvers in your browser; a record shows a tool was provisioned, not that it is in active use, and absence is not proof of non-use. We did not buy or test any technographic vendor for this page. Last checked 24 September 2026.
Common questions
What is technographic data in simple terms?
It is a profile of the technology a company uses - CRM, mail provider, analytics, hosting - assembled from public traces like website code, DNS records and job postings. Sellers use it to judge fit and relevance the way firmographics are used to judge size and industry.
What are examples of technographic data?
A record might say: runs HubSpot, hosts email on Google Workspace, site on WordPress with GA4, job ads mention Snowflake. Each item is evidence of what the company pays for and how it operates - and each was observed at a point in time, so each can be stale.
How is technographic data collected?
Mostly from what companies expose publicly: script tags and headers on their websites, DNS and mail-exchange records, integration marketplaces, reviews and job postings. Internal tools that leave no public trace are inferred or missing, which is why coverage quality varies sharply by category.
Why does technographic data matter for cold email?
Twice over. As targeting, it identifies companies where your product is relevant. As operations, the recipient's mail environment - Google, Microsoft or a security gateway - decides which filters judge the message, which is why we measured it across 9,058,780 B2B mailboxes and run separate sending pools per environment.
Sources and check dates
ReplyLead's own data behind every figure on this page (archived with DOI 10.5281/zenodo.22920956):
- The provider census: who actually receives B2B email: the 28.48% / 25.84% / 16.09% / 14.80% / 6.76% shares and the 8,384,502 MX-bearing domains.
- B2B Email Infrastructure Index 2026 Q3: mail capability across all 9,847,723 resolved domains.
- Mail provider lookup: the same DNS read for a single domain.
Outside primary sources for the method (what MX and DMARC records are, how the two mail environments are identified, and the two public resolvers the tool queries), each read on the date shown:
- Google Public DNS: JSON API for DNS over HTTPS: the dns.google resolver the scan tool queries. checked 24 September 2026.
- Cloudflare 1.1.1.1: DNS over HTTPS, JSON format: the cloudflare-dns.com resolver the scan tool queries. checked 24 September 2026.
- RFC 5321, Simple Mail Transfer Protocol (IETF): MX records name the hosts that receive a domain's mail, which is what the census and the tool read. checked 24 September 2026.
- RFC 7489, Domain-based Message Authentication, Reporting and Conformance (IETF): the DMARC TXT record the tool reads at _dmarc.<domain>. checked 24 September 2026.
- Google Workspace Admin Help: set up MX records: the MX values that identify a Google Workspace mail environment. checked 24 September 2026.
- Microsoft Learn: add DNS records to connect your domain (Microsoft 365): the MX value that identifies a Microsoft 365 mail environment. checked 24 September 2026.
We read the receiving landscape before we send into it
Separate Google and Microsoft sending pools, environment-aware volumes, and lists verified at build time - cold email and LinkedIn outbound, run for you on a revenue-share model.
See the provider census Apply to work with us