Also by us:LastSpamReporter

We Mapped Where Spoofed Email Actually Comes From

We just published something we have wanted to build for a while: a live map of where forged email is coming from, updated every hour. You can see it at dmarcguy.com/threat-map.

It is built from real rejections happening right now on production mail infrastructure — not a simulation, not a vendor demo. And the first thing it told us was not what we expected.

The attacks are not coming from where you think

Ask most people to picture the origin of email attacks and they will describe somewhere far away and vaguely lawless.

The data says otherwise. The heaviest origins are the United States and Canada, followed by the Netherlands, Germany and Singapore. Not because attackers live there — because that is where the cloud datacenters are. Modern attackers do not own infrastructure. They rent it by the hour, from the same providers everyone else uses, and they discard it when it gets blocked.

That is also why the map deliberately never names a network or a provider. The provider is not the attacker, and pretending otherwise would be both wrong and lazy.

Two very different attacks, and only one of them is your problem

The map has two views, and the distinction between them matters more than anything else on the page.

Domains that do not exist. The sender invents a domain with no DNS records at all — a throwaway identity built to slip past filters. Nobody owns it. Nobody is being impersonated. There is no policy anyone could publish to stop it, because there is nobody to publish it.

Real domains with weak or no DMARC. Here the sender used a real, existing company's exact domain. Not a look-alike — the actual domain. And that company's DMARC record is either missing entirely or set to p=none, which means "detect this, but do nothing about it."

That second view is the one worth staring at. Every country lit up there represents mail sent in some real company's name, to their customers and their partners — and that company almost certainly has no idea it happened.

Spoofing is not the same as a look-alike domain

This trips up a lot of people, so it is worth being precise.

ExampleWho owns itCan DMARC stop it?
Look-alikeyourcornpany.comThe attacker registered itNo — it is their domain and their policy
Spoofingyourcompany.comYouYes — this is exactly what DMARC is for

A look-alike domain is a trademark problem. You fight it with registrars and lawyers, and it is genuinely difficult.

Spoofing is a configuration problem. Someone is using your exact domain, and the only reason it works is that you have not told the world's mail servers to reject it. That is a fix you control, and it takes one DNS record.

Why we publish no numbers and no names

Two deliberate omissions.

No counts. How many messages anyone blocks is a vanity metric. It tells you nothing about whether your domain can be used against your customers — and that is the only question that matters to you.

No domain names, ever. Every spoofed domain on that map belongs to a victim. Someone is using their name without permission, and they cannot even report it to a registrar, because it is their own domain. Publishing a list would punish the wrong party. So we show the country and stop there.

p=none is not protection

If you take one thing from the map, take this.

A DMARC record set to p=none monitors. It does not protect. It is the right first step — you publish it, you collect reports, you learn who legitimately sends mail on your behalf. But it is a starting line, not a finish line, and a great many domains have been parked at p=none for years.

Until you move to p=quarantine or p=reject, every receiving mail server in the world has been told: if mail claiming to be from this company fails authentication, deliver it anyway.

That is what the second view of the map is showing you. Somebody, somewhere, is taking that offer.

Check yours

It takes about ten seconds and costs nothing. DMARC Guy will tell you whether your domain publishes a DMARC record, what policy it is set to, and whether SPF and DKIM are properly aligned.

If you find p=none — or nothing at all — that is not a crisis. It is an afternoon of work, and we do this all the time. Get in touch and we will walk you through moving to enforcement without breaking your legitimate mail, which is the part people are rightly nervous about.

Want to read this later? Email it to yourself.

Stay ahead of email threats

Get our latest DMARC, SPF, and email-security guides in your inbox. No spam — unsubscribe anytime.

We only use your email to send blog updates. One click unsubscribes you.