Also by us:LastSpamReporter
Live threat origins

Real companies are being spoofed right now

These attacks used a real company's exact domain — not a look-alike — which is what spoofing means. Their domain publishes no DMARC policy, or one set to “do nothing”, so anyone in the world can send email as them. This is what a missing DMARC record costs you.

Less activityMore activity
Awaiting first update

Live data from LastSpam, our sister email-security service, updated hourly.

Why no numbers?

How many messages were blocked is a vanity metric. What matters is whether your domain can be used against your customers — and that is a yes or no question.

Why no company names?

Every domain on this map is a victim, not an attacker — someone is sending mail from their exact domain, not a look-alike they could report. Naming them would punish the wrong party.

Could this be your domain?

If your DMARC record is missing, or set to p=none, your domain can appear in traffic like this and you would never know. DMARC reporting is how you find out.

Is your domain one of them?

Check your DMARC, SPF and DKIM in about ten seconds. Free, no account, no obligation.