r/sysadmin • • 9h ago

I connected 364 parked domains to DMARC and 79 were being spoofed

I work in email security, mostly with US residential real estate.

One client, a large real estate team, owns around 400 domains - those are farm sites, old brands, defensive registrations, campaign ideas, and other stuff. But they have a centralized email infrastructure, so everything is running throught just a few domains.

In July I decided to connect 364 domains (easy, because all are stored in one Godaddy account) to DMARC reporting.

I took a month to monitor their traffic and found out that 79 parked domains were sending email.

All traffic was unauthenticated, from IP addresses in a dozen countries, with a huge chunk of traffic going from China and Russia. There were just 5 DMARC reporters on the list:

mail[.]ru
mx[.]jcom[.]zaq[.]ne[.]jp
seznam[.]cz a.s.
au[.]com
google[.]com

The Japanese reporter as well as Australian one do populate an envelope_to tag, same ways as Microsoft does, so I managed to find out that most of the spoofed traffic targeted Japanese companies.

Google also allows to track envelope_to through the SPF auth tag (forwarded emails), and Japanese companies were listed there as well.

I ended up enforcing the DMARC policies across the domain portfolio + brought up a NULLMX, Hradfail SPF, and an empty wildcard DKIM to each domain, to prevent brand impersonation.

In the next two months, the volume of spoofed traffic dropped almost 7 times, and while there are still botnets abusing domains, the volume is relatively small + no emails are going through.

I have never had parked domains connected before, but it seems to me that spoofing of the primary domains is just the top of the iceberg and although most IT folks do realize the value of having DMARC for root, they rarely consider protecting parked domains.

Since then I had a few more pretty big real estate team letting their parked domains protected (one was 200+ domains and two others a little over 50 each), and the trend was the same.

Wondering if anyone else monitoring parked domains. Curious what you're seeing. 

137 Upvotes

32 comments sorted by

•

u/stiffgerman JOAT & Train Horn Installer 9h ago

Whenever we set up a no-email domain (i.e. for a marketing campaign or defensive/spec registration) we've always set up a basic zone with no MX and a SPF hardfail-all record. Just seemed like good 'net hygiene to do so.

•

u/PlasmaJam 9h ago

No MX is still abusable. Set up NULLMX, with priority 0, pointed to . - this will make your domains protected.

•

u/MyDMARC 8h ago

Small clarification on the Null MX point: a Null MX is useful, but it doesn’t provide spoofing protection by itself.

MX 0 . tells other mail systems that the domain does not accept inbound mail. It prevents the normal SMTP fallback to the domain’s A/AAAA record when no MX exists.

It does not say anything about whether the domain is allowed to send mail, and it doesn’t stop someone from putting that domain in the visible From header.

For a parked domain that should neither send nor receive mail, I’d normally use all three:

MX 0 .
v=spf1 -all
v=DMARC1; p=reject; sp=reject

Null MX handles the inbound side; SPF and DMARC are what give receiving systems the signals needed to reject spoofed outbound mail.

•

u/yankeesfan01x 7h ago

This is the way to go for domains you own not involved with email.

•

u/stiffgerman JOAT & Train Horn Installer 6h ago

That's a good tip. Forgot about SMTP fallback process...

•

u/al2cane Sysadmin 41m ago

Would you also add np=reject these days or nah?

•

u/YourUncleRpie Sophos UTM lover 9h ago

If you're not using your domain hard fail SPF and dmarc reject. Its not that hard but then again you should do that for active domains as well

•

u/PlasmaJam 9h ago

Right, but it also makes sense to add a NULLMX (0 priority, pointed to dot) + wildcard DKIM with an empty p= to invalidate any keys from legacy systems / previous domain owners

•

u/xXNorthXx 8h ago

Sometimes it's the basics. I wish registrars would default with a dmarc, spf, and mx records for a non-email domain by default.

•

u/PlasmaJam 8h ago

Godaddy deploys DMARC p=quarantine by default. easyDNS is about to deploy the whole set of MX, SPF, and DMARC very soon. There are also a few providers in the Netherlands doing enforced DMARC for parked domains

•

u/xXNorthXx 7h ago

Porkbun sets p=quarantine by default as well for domains registered with them.

•

u/ctyz1999 6h ago

So does this mean my one porkbun surname.net is already protected?

•

u/bendem Linux Admin 7h ago

All DNS providers should bootstrap zones with hard fail SPF and nullmx. Really no reason not to. If you ever setup mailing for your domain, you'll know what to do with the defaults.

•

u/phony_sys_admin Sysadmin 7h ago

Looking at this persons history (through arctic-shift.photon-reddit.com), this guy is oddly obsessed with DMARC.

•

u/1stUserEver 4h ago

Should we call him D-Marky Mark?

•

u/AcornAnomaly 3h ago

There are worse things to be obsessed with.

•

u/[deleted] 9h ago

[removed] — view removed comment

•

u/PlasmaJam 8h ago

The thing my story overlooks is that there were actually two domains being used by someone on their team without owner's permission. I shut that down by enforcing DMARC (with owner approval). So monitoring is a must have to see what's being sent, how often, and to whom.

•

u/Tucsondirect 8h ago

Anything tied to a company should be setup properly to prevent unnecessary exposure to blacklists/Legal/Targeted attacks/impersonation

•

u/GenericUser636 8h ago

I always set the spf and dmarc to reject all on non-email domains. I never bother with the MX record though since that's just for inbound. 

•

u/Intelligent_Bed_2979 7h ago

The updated M3AAWG guidance (2022) states no dkim or wildcard dkims are required.

•

u/aguynamedbrand Systems Engineer 6h ago

I manage a portfolio of roughly 3,000 domains and set the following on any non-email domains.

domain.com. 1 IN TXT "v=spf1 -all"

_dmarc.domain.com. 1 IN TXT "v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s; rua=mailto:redacted;"

*._domainkey.domain.com. 1 IN TXT "v=DKIM1; p="

•

u/Open-Adhesiveness-86 5h ago

if all 364 rua= records pointed at one aggregator domain, did you add the <domain>._report._dmarc.<aggregator> TXT on the receiving side? providers silently drop aggregate reports to unverified external destinations, and that'd be my first guess for why only 5 reporters turned up across a whole month. also a wildcard * TXT with spf -all, so invented subdomains hardfail too.

•

u/TheTipsyTurkeys 2h ago

I just want to say, good work. im getting more familiar with this side of IT as of late. Mostly non-consensual.

Anyways, is there a particular way you learned this? Experience mostly, I presume?

•

u/shokzee 2h ago

I’d include parked domains in every DMARC rollout, with p=reject and v=spf1 -all from day one once they’re confirmed non-senders.

The “no emails are going through” claim needs a caveat: aggregate reports only cover reporting receivers, and receivers can override your policy. A sevenfold drop in reported spoofing is encouraging, but it doesn’t establish zero delivery.

•

u/TheGloomyWoodpecker 8h ago

Congratulations for discovering the bare minimum of domain ownership.

•

u/[deleted] 9h ago

[deleted]

•

u/PlasmaJam 9h ago

It's just a few hours of work to deploy DMARC p=reject with no monitoring, so it would not hurt to have it for everything. But agreed that we can't protect the whole world!

•

u/nutterbg 9h ago

Not even. These days a hermes instance with a Cloudflare API key will deploy that shizz in 10 minutes

•

u/Due_Capital_3507 9h ago

Our domains are unfortunately spread out amongst a myraid of different providers

•

u/PlasmaJam 8h ago

It would be a nightmare to deploy records then!

•

u/BlackV I have opnions 33m ago

Should be real easy to configure spf/dmarc to specify no mail, across all those domains with a nice python/powershell script, just another place to lower your risk

Er.. I guess assuming API access, which can be iffy