Also by us:LastSpamReporter

The authenticated swarm

They passed SPF. They passed DKIM. They passed DMARC. Then 342 domains wore 18,749 different faces, and almost nobody noticed.

Here is the uncomfortable part. Roughly one message in eleven from this operation was sloppy — a broken signature, a missing record — and that portion went nowhere, the way badly-configured mail always does.

The other 90% authenticated perfectly. Not forged: signed. A domain the operator controlled, vouching for a message the operator sent, exactly as the standard intends.

Read that twice. Nothing about this campaign was broken. It was correctly configured mail, and correctly configured mail is what every system on the internet is built to give the benefit of the doubt.

For fifteen years the industry has told senders the same thing: publish SPF, sign with DKIM, enforce with DMARC. It is good advice. It works. And somebody took it very, very seriously.

Publishing DMARC doesn't just prove who you are. It buys you the benefit of the doubt — and that benefit is now something you can mass-produce.

Three hundred domains, eighteen thousand faces

Reputation systems work by remembering. Send from a domain often enough and it accumulates a history — good or bad — and that history is what gets judged.

So this operator simply never sent twice from the same address. Across ninety days: 20,424 messages from 18,749 distinct sending hostnames. By the time any system could form an opinion about one, it had been abandoned.

The instinct is to picture a warehouse of purchased domains. That is not what happened, and the truth is considerably worse.

xjsxrs . portal   . nuanqi06.com        <- bought
claxvd . form     . dxdwz.com           <- bought
nwhwtu . inquiry  . zh-zhuafanzb.com    <- bought
eqpynb . notice01 . ikuxin.com          <- bought
 \________________/
   free, unlimited, instant

Everything to the left of the registered domain is free, unlimited, and instantaneous.

Those 18,749 identities came from 342 registered domains — an average of 55 disposable subdomains each. One domain generated 309 of them by itself.

CampaignMessages (90 days)Sending identitiesDomains boughtIdentities per domain
Brokerage brand20,42418,74934254.8
Investment platform17,2808382054.1
Consumer tech brand3,171195523.8

Three separate operations over the same ninety-day window — not a total, and not a day's traffic. One economy between them: about 600 registrations behind nearly 19,700 identities.

The barrier to running this is a few hundred domain registrations. Not a warehouse — a shopping trip.

This is why "that domain is brand new, be careful" fails as an instinct. The registration can be years old and perfectly quiet; only the subdomain is new, and a subdomain has no registrar in the loop, no fee, and no waiting period. xqwvd.example.com becomes ydccx.example.com in the time it takes to edit a zone file.

Those 18,749 identities were sent from 1,125 machines across 39 networks — six consecutive ranges at one cloud provider carried 88% of it. Roughly 33 fresh sender identities out of every single machine.

That ratio is the whole story in one line. The names were disposable and effectively free. The place they were sent from was neither — it had to be rented, it stayed put, and there was far less of it than the eighteen thousand identities suggested.

Worth adding, because the obvious conclusion is the wrong one: these are shared cloud ranges. Your payroll provider and your CRM may be renting the machine next door. Nothing here is an argument for blocking a cloud provider — it is an argument that identity was cheap and location was not.

The characters you cannot see

A display name is the part of the From line a human actually reads. So it is the part worth attacking — and it is text, which means it can be quietly sabotaged.

Between every single letter of the brand name, these messages carry a zero-width space: a real Unicode character that occupies no pixels and renders as nothing at all.

Your eye reads one word. A string comparison reads twenty-one characters that match nothing on earth.

Over ninety days, 12,719 messages across 10,837 domains used this. It is not a clever one-off; it is standard equipment.

Written by something that doesn't get bored

A second campaign impersonated a global consumer-tech brand. Not with one display name — with fourteen, each mapped to a real product line, each spread across dozens of sender domains.

Display nameSender domains (90 days)Share that were disposable
Brand Music8699%
Brand Developer9398%
Brand Support9298%
Brand Account9098%
Brand Pay8398%
Brand News9896%
Brand Arcade7296%

Seven of fourteen variants. Nobody sits and types this.

And the registrations behind it were not new. One had been sitting quietly since 2023 — aged like a cask, then woken up to mint disposable children on demand.

The habit they can't automate away

Here is a thing that sounds trivial and isn't. Real organisations reuse their mailboxes. Mail comes from info@, sales@, from Marie, from the same handful of people, week after week.

These campaigns never reuse one. Every message, a freshly minted random mailbox — lmfyglg@, khigtrr@, sihxxzr@ — used once and thrown away.

The counter-intuitive bit is what that looks like beside legitimate bulk senders. Big email platforms send on behalf of thousands of companies from a handful of domains — you would expect them to look more machine-like, not less:

SenderMessagesDistinct mailboxesSubdomains
A major marketing platform1635252
A major newsletter platform44911944
A global software vendor2,6472814
Campaign domain92926
Campaign domain76765

The legitimate platforms run more subdomains than the criminals — and still reuse their mailboxes. Fan-out isn't the tell. Repetition is.

The phishing nobody reports

You might assume a campaign this size generates complaints. We went looking through a hundred and eighty days of user reports to find out.

Of every "report spam" click over that window, 95% were automated scanners — link-checkers following the button on the reader's behalf. Five percent were an actual human being.

And the share of those humans naming this campaign's networks: zero.

Not a low number — none. Every genuine "you missed one" report we reviewed over six months, and not one of them pointed at the networks that had been delivering authenticated phishing the entire time.

People report the newsletter they're tired of. They do not report credential phishing — they either act on it, or they delete it and move on with their day. Median time to report anything at all: four hours. By then a credential is either used or it isn't.

The mail that generates complaints and the mail that costs you money are not the same mail.

This is worth sitting with, because "train your staff and give them a Report Phishing button" is the standard answer to exactly this threat. The button is worth having. It is not a control you can put weight on — it fires on the mail people find annoying, hours later, and stays silent on the mail that empties an account.

Which leaves one place to catch it: before it is ever in front of a human.

What this actually means for you

If you send email: authentication is still worth doing. It is table stakes, it protects your name, and skipping it now marks you out. Just retire the idea that a green checkmark is a verdict on intent. It never was. It says a domain vouched for a message — not that the domain deserves vouching for.

If you receive email: the single most useful question about an unfamiliar sender is no longer "did it authenticate?" It is "have I ever heard from these people before?" — and everything above is one operator's answer to that question being expensive.

All figures are drawn from live mail flow over a ninety-day window. Organisations, recipients and the impersonated brands have been withheld; the attacker infrastructure has not.


Start with your own name. Everything above is someone else's domain being worn as a costume. The first question worth answering is whether yours is available to borrow — whether you publish DMARC, whether it is actually enforcing, and who is sending as you right now.

These observations come from live mail flow on LastSpam, our filtering platform — ninety days of ordinary traffic to organisations who had no idea any of it was happening. That is the normal state of affairs, which is rather the point.

Want to read this later? Email it to yourself.

Stay ahead of email threats

Get our latest DMARC, SPF, and email-security guides in your inbox. No spam — unsubscribe anytime.

We only use your email to send blog updates. One click unsubscribes you.