Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

ZoomEye can show which internet-facing hosts match a set of search criteria, but a match is only a lead. Calling a host an email security gateway requires corroboration from mail-specific signals, and any count built from search results needs a reproducible query, a recorded observation date, and a validation step. This guide explains what ZoomEye’s documented search functions support, which independent signals should confirm a candidate, and where the method stops being reliable.

What ZoomEye’s documentation supports

ZoomEye’s API v2 documentation, which states an update date of 2024-12-04, describes search across IPv4 and IPv6 devices as well as websites and domains. Matching can reach into protocol content such as HTTP, SSH, and FTP, and into service banners. The documented filters include IP, CIDR, organization, ASN, port, hostname, domain, banner, service, device, product, transport protocol, and time. Operators cover exact matching, conjunction, disjunction, exclusion, and grouping.

These are general asset-search capabilities. The guide does not describe an email-gateway classifier, and it does not establish any particular query as a dependable way to find mail-filtering appliances or cloud filtering services. Any query you build for this purpose is a hypothesis that must be tested.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why a match is an observation, not an identification

A search result records that a service answered in a certain way when it was observed. It does not, by itself, establish three things:

  • Function: that the host is an email security gateway rather than a mail server, a web host, or a generic appliance that exposes a similar banner.
  • Ownership: that the host belongs to a particular organization. Cloud filtering and shared hosting mean one address can serve many unrelated domains.
  • Condition: that the service is vulnerable or misconfigured. An exposed service may be intentional and correctly hardened.

A 2025 NDSS paper, Revealing the Black Box of Device Search Engines, examines device search engine behavior and includes SMTP in its analysis. It is a reason to be cautious about indexed records and the methods behind them. Treat search-engine data as a snapshot of what one collector recorded, not as ground truth about the internet.

#1 Best Overall
FORTINET FortiMail-VM Virtual Appliance for All Supported Platforms. 8 x vCPU cores FML-VM08
  • Fortinet FortiMail-VM virtual appliance for all supported platforms. 8 x vCPU cores
  • Fortinet SW FML-VM08
  • Manufacturer Part: FML-VM08

Corroborating signals before you classify a host

The 2024 study Unfiltered: Measuring Cloud-based Email Filtering Bypasses identifies organizations that accept mail delivery by combining several signals rather than relying on one. A search hit becomes a candidate only when it is checked against the following independent evidence.

MX and A records

Mail routing starts in DNS. Check the MX records for the domains in your scope, then resolve each MX target to its A records. If a ZoomEye hit’s IP address matches a mail exchanger that a scoped domain actually publishes, the observation has a routing context. If it does not, the hit may be a coincidental listing and should be labeled unlinked.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
WatchGuard Firebox T145 with 3 Year Basic Security Suite - Tabletop Firewall, 2.5Gb, 1Gb & SFP Ports, Enterprise Security for Branch Locations (WGT145000+WGT1450073)
  • Watchguard T145 Firebox with 3 Year Basic Security Suite License (WGT145033) - The Firebox T145 delivers enterprise-grade protection for branch offices and retail sites. With a blend of 2.5Gb, 1Gb, and SFP/SFP+ ports, it supports high throughput, AI-driven malware protection, and DNS filtering for robust network defense.
  • The Basic Security Suite activates core protections on your Firebox, including intrusion prevention, gateway antivirus, URL filtering, and spam blocking in WatchGuard Cloud. Upgrade to Total Security Suite to add AI-powered malware detection, cloud sandboxing, DNS filtering, and advanced correlation.
  • The Basic Security Suite equips your WatchGuard Firebox with a robust set of foundational security tools. This bundle delivers intrusion prevention, gateway antivirus, URL filtering, and spam blocking, all managed through WatchGuard Cloud. It’s a cost-effective choice for organizations that need reliable, essential protection without unnecessary extras.
  • Interfaces and deployment: 2.5Gb and 1Gb Ethernet with SFP or SFP+ fiber for clean aggregation and segmented backhaul at the edge.
  • Performance and scale: UTM up to 710 Mbps with inspection on; flexible VPN topologies for hub and spoke or mesh designs.

TLS certificates on SMTP

Where the service negotiates STARTTLS, the certificate it presents can show the names it claims to serve. A certificate that covers your scoped domain, or a provider’s naming pattern, supports a link to that provider. A certificate that cannot be tied to your scope or to any known provider does not identify the vendor, even if it is valid.

SMTP banners

The greeting banner is the signal most often copied from search data, and it is the one most often mistaken for proof. Banners can be customized, inherited from software packages, or left at defaults. Record the banner exactly as received, but do not treat a single banner as a definitive product identification.

Protocol responses

Responses to SMTP commands, such as how the server handles EHLO, its capability list, and its reply to unusual input, add behavior to the picture. They help separate a filtering service from a plain mail server with a similar greeting. Like the other signals, they are evidence for classification, not a verdict.

Signal What it adds Main limitation
ZoomEye search fields (banner, port, product, service, time) A recorded, time-stamped observation that can be filtered and repeated Does not establish function, ownership, or current state; results depend on the collector
MX and A records Shows whether a host sits in a scoped domain’s mail path Shared infrastructure can map many domains to one host
TLS certificate on SMTP Names the domains or provider the service claims to serve Certificates can be reused or cover unrelated names
SMTP banner Quick, human-readable identity hint Customizable and easy to copy; not definitive alone
Protocol responses Behavioral evidence that can separate similar services Needs direct, authorized interaction and careful interpretation

Comparing measurement approaches

The difference between a weak and a defensible finding usually lies in how the candidate was identified, what it was checked against, and whether the work can be repeated. The table below compares the two approaches on the axes that matter most.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Axis Single search match Corroborated, scoped measurement
Identification confidence Low; one banner or field Higher; several independent signals agree
Scope and authorization Often general internet observations with no owner consent Limited to assets the researcher is authorized to assess
Reproducibility Depends on an unrecorded snapshot Query, data type, filters, and observation date recorded
Suitable for counts Not suitable without validation Suitable only when validation criteria are stated and applied

No head-to-head benchmark of ZoomEye against other asset-search products is available in these sources, so the table compares approaches, not tools.

Rank #4
WatchGuard Firebox T125 with 1 Year Basic Security Suite - Tabletop Firewall, 1x 2.5Gb + 4X 1Gb Ports, High-Speed Security for Branch Offices (WGT125000+WGT1250071)
  • Watchguard T125 Firebox with 1 Year Basic Security Suite License (WGT125031) - The Firebox T125 provides enterprise-grade protection for branch offices and remote sites. Featuring 2.5Gb and 1Gb ports, it delivers fast throughput, advanced malware detection with IntelligentAV, and SD-WAN compatibility in a compact form factor.
  • The Basic Security Suite activates core protections on your Firebox, including intrusion prevention, gateway antivirus, URL filtering, and spam blocking in WatchGuard Cloud. Upgrade to Total Security Suite to add AI-powered malware detection, cloud sandboxing, DNS filtering, and advanced correlation.
  • The Basic Security Suite equips your WatchGuard Firebox with a robust set of foundational security tools. This bundle delivers intrusion prevention, gateway antivirus, URL filtering, and spam blocking, all managed through WatchGuard Cloud. It’s a cost-effective choice for organizations that need reliable, essential protection without unnecessary extras.
  • Interfaces and deployment: 1x 2.5Gb and 4x 1Gb Ethernet to simplify uplinks, carve out segmented zones, and keep branch wiring minimal.
  • Performance and scale: UTM up to 510 Mbps with inspection on; sized for small and branch offices with room to grow VPN connectivity.

Keep measurement inside authorized scope

ZoomEye’s attack-surface-management product page describes a SaaS workflow in which an organization supplies asset leads, such as IP addresses, domains, or keywords, and the service reports discovery and ongoing monitoring of exposed assets, including websites, IPs, apps, personnel, and email. That is the vendor’s description of its service. It is not a legal determination, and it does not decide whether a given probe is permitted where you operate.

For measurement work, limit the candidate list to assets you own or have written permission to assess, and record that scope with the results. Direct SMTP interaction should be restricted to those assets. Observations of hosts outside your scope should be reported, if at all, as unvalidated search records.

Best Value
WatchGuard Firebox T125 with 5 Year Basic Security Suite - Tabletop Firewall, 1x 2.5Gb + 4X 1Gb Ports, High-Speed Security for Branch Offices (WGT125000+WGT1250075)
  • Watchguard T125 Firebox with 5 Year Basic Security Suite License (WGT125035) - The Firebox T125 provides enterprise-grade protection for branch offices and remote sites. Featuring 2.5Gb and 1Gb ports, it delivers fast throughput, advanced malware detection with IntelligentAV, and SD-WAN compatibility in a compact form factor.
  • The Basic Security Suite activates core protections on your Firebox, including intrusion prevention, gateway antivirus, URL filtering, and spam blocking in WatchGuard Cloud. Upgrade to Total Security Suite to add AI-powered malware detection, cloud sandboxing, DNS filtering, and advanced correlation.
  • The Basic Security Suite equips your WatchGuard Firebox with a robust set of foundational security tools. This bundle delivers intrusion prevention, gateway antivirus, URL filtering, and spam blocking, all managed through WatchGuard Cloud. It’s a cost-effective choice for organizations that need reliable, essential protection without unnecessary extras.
  • Interfaces and deployment: 1x 2.5Gb and 4x 1Gb Ethernet to simplify uplinks, carve out segmented zones, and keep branch wiring minimal.
  • Performance and scale: UTM up to 510 Mbps with inspection on; sized for small and branch offices with room to grow VPN connectivity.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

A reproducible workflow

  1. Write down the question and the scope: the domains, IP ranges, or organizations you are authorized to assess.
  2. Run the ZoomEye search with the data type, query text, filters, and time window spelled out. Save the exact query string and the date and time you ran it.
  3. Export the matching records and keep the raw fields. Do not edit them after the fact.
  4. For each candidate in scope, resolve the MX and A records and note whether the IP appears in the mail path of a scoped domain.
  5. Where authorized, record the SMTP banner and the TLS certificate, and note the protocol responses to standard commands.
  6. Classify each candidate as unlinked, partially corroborated, or corroborated. Attribute a provider only when at least two independent signals support the same identification, and state which signals those were.
  7. Re-run the same query on a later date and record what changed. A count without a date is not a current count.

What the provider list does and does not show

The 2024 Unfiltered paper reports signatures for 15 leading email filtering services: Proofpoint, Mimecast, Cisco (aka Ironport), Barracuda, TrendMicro, Broadcom (formerly Symantec), Trellix (formerly FireEye), Sophos, Cloudflare, Fortinet, N-able (formerly SolarWinds MSP), Forcepoint, AppRiver, Spamhero, and HornetSecurity. That is the study’s reported set, useful as an example of vendor diversity. It is not an exhaustive market list, it is not a 2026 inventory, and it is not a count of exposed gateways. Several names have changed through acquisitions and rebranding, so check current vendor identity before drawing conclusions from older signatures.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What is not established

The sources reviewed for this topic do not provide a validated ZoomEye query for email security gateways, a current result count, a trend, or a vendor-attribution rate. They also do not specify a geography, a date range, or an audience role for any particular study. If you publish numbers from this kind of work, state the query, the data type, the observation date, the authorized scope, and the validation criteria alongside them. Without those, a figure describes a search result, not the exposure of any gateway.

The practical takeaway is that ZoomEye is a useful starting point for finding candidates, while the classification depends on corroboration from DNS, TLS, SMTP, and protocol evidence gathered within scope.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.