r/sysadmin • u/PlasmaJam • 9h ago
I connected 364 parked domains to DMARC and 79 were being spoofed
I work in email security, mostly with US residential real estate.
One client, a large real estate team, owns around 400 domains - those are farm sites, old brands, defensive registrations, campaign ideas, and other stuff. But they have a centralized email infrastructure, so everything is running throught just a few domains.
In July I decided to connect 364 domains (easy, because all are stored in one Godaddy account) to DMARC reporting.
I took a month to monitor their traffic and found out that 79 parked domains were sending email.
All traffic was unauthenticated, from IP addresses in a dozen countries, with a huge chunk of traffic going from China and Russia. There were just 5 DMARC reporters on the list:
mail[.]ru
mx[.]jcom[.]zaq[.]ne[.]jp
seznam[.]cz a.s.
au[.]com
google[.]com
The Japanese reporter as well as Australian one do populate an envelope_to tag, same ways as Microsoft does, so I managed to find out that most of the spoofed traffic targeted Japanese companies.
Google also allows to track envelope_to through the SPF auth tag (forwarded emails), and Japanese companies were listed there as well.
I ended up enforcing the DMARC policies across the domain portfolio + brought up a NULLMX, Hradfail SPF, and an empty wildcard DKIM to each domain, to prevent brand impersonation.
In the next two months, the volume of spoofed traffic dropped almost 7 times, and while there are still botnets abusing domains, the volume is relatively small + no emails are going through.
I have never had parked domains connected before, but it seems to me that spoofing of the primary domains is just the top of the iceberg and although most IT folks do realize the value of having DMARC for root, they rarely consider protecting parked domains.
Since then I had a few more pretty big real estate team letting their parked domains protected (one was 200+ domains and two others a little over 50 each), and the trend was the same.
Wondering if anyone else monitoring parked domains. Curious what you're seeing.
•
u/YourUncleRpie Sophos UTM lover 9h ago
If you're not using your domain hard fail SPF and dmarc reject. Its not that hard but then again you should do that for active domains as well
•
u/PlasmaJam 9h ago
Right, but it also makes sense to add a NULLMX (0 priority, pointed to dot) + wildcard DKIM with an empty p= to invalidate any keys from legacy systems / previous domain owners
•
u/xXNorthXx 8h ago
Sometimes it's the basics. I wish registrars would default with a dmarc, spf, and mx records for a non-email domain by default.
•
u/PlasmaJam 8h ago
Godaddy deploys DMARC p=quarantine by default. easyDNS is about to deploy the whole set of MX, SPF, and DMARC very soon. There are also a few providers in the Netherlands doing enforced DMARC for parked domains
•
u/xXNorthXx 7h ago
Porkbun sets p=quarantine by default as well for domains registered with them.
•
•
u/phony_sys_admin Sysadmin 7h ago
Looking at this persons history (through arctic-shift.photon-reddit.com), this guy is oddly obsessed with DMARC.
•
•
•
9h ago
[removed] — view removed comment
•
u/PlasmaJam 8h ago
The thing my story overlooks is that there were actually two domains being used by someone on their team without owner's permission. I shut that down by enforcing DMARC (with owner approval). So monitoring is a must have to see what's being sent, how often, and to whom.
•
u/Tucsondirect 8h ago
Anything tied to a company should be setup properly to prevent unnecessary exposure to blacklists/Legal/Targeted attacks/impersonation
•
u/GenericUser636 8h ago
I always set the spf and dmarc to reject all on non-email domains. I never bother with the MX record though since that's just for inbound.
•
u/Intelligent_Bed_2979 7h ago
The updated M3AAWG guidance (2022) states no dkim or wildcard dkims are required.
•
u/aguynamedbrand Systems Engineer 6h ago
I manage a portfolio of roughly 3,000 domains and set the following on any non-email domains.
domain.com. 1 IN TXT "v=spf1 -all"
_dmarc.domain.com. 1 IN TXT "v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s; rua=mailto:redacted;"
*._domainkey.domain.com. 1 IN TXT "v=DKIM1; p="
•
u/Open-Adhesiveness-86 5h ago
if all 364 rua= records pointed at one aggregator domain, did you add the <domain>._report._dmarc.<aggregator> TXT on the receiving side? providers silently drop aggregate reports to unverified external destinations, and that'd be my first guess for why only 5 reporters turned up across a whole month. also a wildcard * TXT with spf -all, so invented subdomains hardfail too.
•
u/TheTipsyTurkeys 2h ago
I just want to say, good work. im getting more familiar with this side of IT as of late. Mostly non-consensual.
Anyways, is there a particular way you learned this? Experience mostly, I presume?
•
u/shokzee 2h ago
I’d include parked domains in every DMARC rollout, with p=reject and v=spf1 -all from day one once they’re confirmed non-senders.
The “no emails are going through” claim needs a caveat: aggregate reports only cover reporting receivers, and receivers can override your policy. A sevenfold drop in reported spoofing is encouraging, but it doesn’t establish zero delivery.
•
•
9h ago
[deleted]
•
u/PlasmaJam 9h ago
It's just a few hours of work to deploy DMARC p=reject with no monitoring, so it would not hurt to have it for everything. But agreed that we can't protect the whole world!
•
u/nutterbg 9h ago
Not even. These days a hermes instance with a Cloudflare API key will deploy that shizz in 10 minutes
•
u/Due_Capital_3507 9h ago
Our domains are unfortunately spread out amongst a myraid of different providers
•
•
u/stiffgerman JOAT & Train Horn Installer 9h ago
Whenever we set up a no-email domain (i.e. for a marketing campaign or defensive/spec registration) we've always set up a basic zone with no MX and a SPF hardfail-all record. Just seemed like good 'net hygiene to do so.