Every TLS certificate a company issues is published in public certificate-transparency logs, so its hostnames are a public map of how it is built. We pulled those names for 33 competitors and probed up to 150 per domain on 5 October 2026 (scoreboard). They show two things. The architecture behind the marketing claims. And a search asset most competitors underuse: the help centre, which answers the "how do I…" queries that buyers and AI assistants ask.
This page describes patterns and counts. We do not list customer-identifying or internal hostnames one by one. Names in certificate logs are public by design, but a staging host is not an invitation.
What the cert logs reveal
| Domain | Cert names | Live (of probed) | Pattern |
|---|---|---|---|
| EmailBison | 698 | 53 of 150 | Single-label names, most of them customer or agency names; 49 of 55 responding hosts serve an "EmailEngine" page; 23 names contain "overflow", "custom" or "proxy" |
| snov.io | 191 | 23 of 150 | 87 names contain "stage"; 11 tracking hosts; internal-tooling hosts |
| Smartlead | 176 | 28 of 150 | 63 two-level names: API, GraphQL, webhook and realtime hosts under ten AWS region labels (us-east-1, eu-central-1, ap-south-1 …); 47 "dev", 17 "internal" |
| Outreach | 149 | 47 of 144 | Numbered app shards (app1a–app2d), 14 Kibana hosts; the marketing site has moved to outreach.ai |
| Zapmail | 136 | 117 of 136 | 96 ee* hosts, almost all returning 403; one serves an EmailEngine page; "whitelabel", "uat" and "stage" names |
| salesloft.com | 111 | 41 of 111 | Tech-ops, Copilot and help-desk hosts |
| Saleshandy | 107 | 42 of 102 | 26 numbered staging names (staging2 … staging24); 22 "tools" names |
| Hunter | 83 | 38 of 76 | 14 noindex hosts; the app sits behind Cloudflare Access |
| ReachInbox | 77 | 68 of 75 | 48 ee* hosts in the same pattern as Zapmail; one EmailEngine page; Elastic |
| Maildoso | 59 | 45 of 58 | 21 IMAP hosts named after Greek gods: a mail-server fleet |
| Instantly | 47 | 26 of 42 | api, mail, unibox attachments, MCP, n8n, pusher, partner API |
EmailBison sells one instance per customer. EmailEngine is Postal Systems' source-available IMAP/SMTP-to-REST gateway, licensed at $1,450 a year (Open source in cold email, Build costs and team). 49 of 55 responding EmailBison hosts serve its default page. That fits EmailBison's own claim that "each customer receives a dedicated network cluster" (EmailBison). If our 150-host sample is representative, the certificate count approximates the number of customer instances. 698 is an upper bound, since one customer can hold "overflow" and "custom" hosts. The EmailBison teardown found three hosts that redirect to an agency's own branded login, which suggests white-label resale.
ReachInbox and Zapmail share an architecture. Both run numbered ee, ee2 … shards (48 and 96), each with one public EmailEngine page. That fits a connector layer built on EmailEngine and sharded at a few thousand mailboxes per instance, the scaling unit Postal Systems itself describes (Sending architecture). Same naming, same vendor and same shard pattern suggest a shared engineering lineage. We have not confirmed common ownership.
Smartlead runs regional API endpoints. GraphQL, webhook and realtime hosts sit under ten AWS region labels, from us-east-1 to eu-central-1 and ap-south-1. That fits its scale (Smartlead) and is the part of its stack an entrant would take longest to match.
Numbered staging hosts (Saleshandy, Snov) and dev/internal names (Smartlead) are visible in public logs. At least one staging copy is in search results: a test.reply.io copy of Reply.io's template library showed up for "cold email template to invite podcast guests". An indexed staging host duplicates content and exposes unreleased pages. Put staging behind authentication, not just noindex.
Help centres: the SEO asset most competitors underuse
Help articles answer concrete, high-intent questions ("how to connect Outlook to X", "why are my emails bouncing"), and AI assistants quote them. We fetched each help centre's home page and sitemap.
| Vendor | Host | Platform | Indexable? | Articles in sitemap |
|---|---|---|---|---|
| lemlist | help.lemlist.com | Intercom | Yes | 373 |
| Woodpecker | woodpecker.co/help-center (moved from help.) | Intercom, subfolder | Yes | 267 |
| Instantly | help.instantly.ai | Intercom | Yes | 263 |
| ReachInbox | help.reachinbox.ai | Intercom | Yes | 246 |
| Salesforge | help.salesforge.ai | Gleap | Yes | 241 |
| Klenty | support.klenty.com | Gleap | Yes | 218 |
| Hunter | help.hunter.io | Intercom | Yes | 206 |
| PlusVibe | help.plusvibe.ai | Intercom | Yes | 171 |
| HeyReach | help.heyreach.io | Intercom | Yes | 105 |
| Amplemarket | knowledge.amplemarket.com | Custom | Yes | 98 |
| Zapmail | help.zapmail.ai | Intercom | Yes | 75 |
| Mailshake | docs.mailshake.com | Help Scout | Yes | 257 URLs |
| QuickMail | help.quickmail.com | Gatsby (custom) | Yes | 165 URLs |
| Smartlead | help.smartlead.ai | Notion | Weak | 23 URLs |
| Reply.io | support.reply.io | Intercom | No (noindex, nofollow) | — |
| Clay | support.clay.com | GitBook | No (noindex) | — (university.clay.com is indexable) |
| Saleshandy | help. / support.saleshandy.com | — | Returned Cloudflare 525 at crawl time | — |
Three takeaways:
- Smartlead's help centre barely exists for search engines. The Notion-hosted site lists 23 URLs, and its server-rendered HTML carries Notion's generic product description ("A collaborative AI workspace…") instead of Smartlead's. The 40-page
/smartlead-101/course on the main domain partly makes up for it. - Reply.io hides its help centre on purpose, and Clay hides its GitBook support site. Both give up the "how do I" long tail.
- Intercom is the default (9 of the 16 we identified), because it ships indexable, localisable articles with sitemaps. Developer docs have converged on Mintlify (Instantly, Salesforge, Clay, lemlist, EmailBison and Reply.io API docs), which also generates
llms.txt(llms.txt, pricing.md and AI crawlers).
Other subdomain types
| Type | Who has it | Note |
|---|---|---|
| Status page | 15 vendors (Hunter, HeyReach, Reply, Outreach, Woodpecker, lemlist via lempire…) | Thin pages; a trust signal, not SEO |
| Trust centre | Instantly (Vanta), Saleshandy (Sprinto), Salesforge, Clay, Amplemarket, lemlist | Procurement asset; EU buyers ask for it (GDPR and ePrivacy) |
| Academy / university | lemlist (academy on WordPress, university on Webflow), Clay, Outreach, Reply (behind sign-in), Salesloft (noindex) | Amplemarket moved its university into /university/ on the main domain |
| Community | Clay (Slack mirror, indexable), Reply (Slack mirror), Salesloft (noindex) | Clay's community threads rank for "Instantly vs Smartlead" (Comparison and alternatives pages) |
| Feedback / roadmap | Instantly (Featurebase), Smartlead, Salesforge, HeyReach (ProductLift), AgentMail (Canny), LGM | Rarely indexable; useful product evidence |
| Affiliate / partner portal | Saleshandy, QuickMail, Artisan, Hunter, ReachInbox, Zapmail; Instantly's partner portal is noindex | Sign-up gates, not content |
Subdomain or subfolder
Google has published no rule that subdomains rank worse. The vendors' own moves show which way they think it goes. Content keeps moving into the main domain: blog.hunter.io, blog.lemlist.com, blog.smartreach.io, blog.warmy.io and blog.lavender.ai all redirect into /blog/. Woodpecker moved its Intercom help centre to /help-center/. Amplemarket moved its university into a subfolder. Instantly runs a Ghost blog but serves it at instantly.ai/blog/, and its robots.txt disallows /blog/ghost/ (the CMS admin path). The working rule across the market: apps, APIs, docs and status on subdomains; anything meant to rank in a subfolder.
We could not verify how much search traffic any help centre earns, or whether Google treats Intercom-hosted subdomains as part of the main site. Our probe saw only hostnames that ever had a certificate. Wildcard certificates hide individual hosts, so the counts are lower bounds for some vendors.
What this means for an entrant
- Launch the help centre in a subfolder, from day one, indexable. Intercom or Help Scout at
/help/costs nothing extra and beats Smartlead's Notion page and Reply.io's hidden centre. Write the 100 articles a multi-client agency needs (client workspaces, reply routing, per-country rules) before the 1,000 everyone else writes. - Put developer docs on Mintlify (or similar) with
llms.txtand an OpenAPI spec. It is the market's standard, and it is what coding agents read (API, webhooks and MCP). - Keep staging out of certificate logs. Use a wildcard certificate for non-production hosts, require auth on every staging host, and never let a
test.copy be crawled. - If you sell per-customer instances, don't name hosts after customers. EmailBison's cert log is effectively a customer list. Use opaque IDs plus customers' own CNAMEs (White-label and agency portals).
- Publish an EU trust centre (sub-processors, data location, DPA, AVV in German) on a
trust.host or/trust. It is a procurement document for German buyers and a reason to choose an EU vendor (EU-native compliant outbound). - Read your rivals' cert logs every quarter. New hostnames (an
mcp.host, a new region, a white-label pattern) show up months before a launch post.