Check your DNS! Abandoned domains used to bypass spam checks
ID: e6bbb408-41eb-55d6-ba93-e4dc2d1a827e
STIX ID: report--e6bbb408-41eb-55d6-ba93-e4dc2d1a827e
Feed Name: Malwarebytes Blog
Threat Score
Guardio Labs discovered a large-scale abuse technique called “subdomailing” where attackers purchase forgotten domains that legitimate sites still reference via CNAME or SPF include records. By controlling those domains, attackers can send email from brand subdomains (e.g., marthastewart.msn.com) that pass SPF and other checks, enabling widespread spam and impersonation across thousands of hijacked subdomains; Guardio published a checker to help domain owners detect such abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
