Self-Routed DMARC: Fingerprinting an Aged-Domain Email-Scam Ecosystem
Self-Routed DMARC: Fingerprinting an Aged-Domain Email-Scam Ecosystem
A single stacked DNS-authentication fingerprint ties roughly 12,800 aged dropped domains to one email-scam ecosystem impersonating warranty and benefits brands. The operator behind it does not register fresh domains. It buys expired ones that carry a decade or more of clean history, publishes an authentication stack that only looks compliant, and burns each domain after a handful of sends. What links the whole population together is not a shared brand or a single IP address. It is two DNS records that co-occur almost nowhere in legitimate mail: a DMARC record that mails its own compliance reports back to itself, and an SPF record that authorizes exactly one IP and rejects everything else.
Key Takeaways
- The operator sends from aged dropped domains, most registered before 2020, which sidesteps the newly-registered-domain reputation penalty that most mail filters lean on.
- Every domain publishes a self-routing DMARC record (
rua=mailto:report@<own_apex>) whose aggregate reports land in a mailbox nobody reads, paired with a single-IP hard-fail SPF record. The co-occurrence is the operator's attribution signature. - Stacking the two anti-patterns across a large URL-reputation corpus surfaced 12,798 domains that share the fingerprint, spanning six lead-gen verticals off one shared sending chassis.
- Domain supply funnels through a handful of registrars. GoDaddy, Dynadot, and Namecheap account for roughly 90% of the pool, sourced through the aged-domain secondary market.
- Click-throughs run via a self-hosted
/r####.php?32=<token>redirect on the sending domain itself, then fan out to burner Azure Blob Storage buckets. - The ecosystem pushes hundreds of thousands of messages across a rolling quarter, burning roughly 37 fresh domains into the pool every day.
Background
Most modern mail filters treat domain age as a first-class risk signal. Microsoft Defender, Proofpoint, Mimecast, and Cisco Talos all penalize freshly registered domains, because a legitimate business almost never launches a commercial mail program from a domain registered last week. Public research puts hard numbers behind the heuristic and its limits at the same time: the large majority of phishing domains are now older than 90 days, and a substantial share are more than five years old. Age-based filtering, on its own, sees only a fraction of the real attack surface.
This operator is built around that gap. Rather than register burner domains, it acquires expired ones through the aged-domain secondary market. When a registered domain lapses, it eventually drops back to the registry, and drop-catch services race to re-register it the instant it becomes available, then resell it. DropCatch, SnapNames, NameJet, Sedo, and GoDaddy Auctions run this market, where a domain with a long, clean history commonly lists for roughly $50 to $500. The buyer inherits the aged WHOIS creation date and any residual reputation without inheriting a shred of the legitimacy that built it. A domain like tracyscustomboatcovers[.]com or hollandheaterusa[.]com, registered in 1999 or 2009 by a real small business, becomes a burner for auto-warranty spam a decade and a half later.
The pretext is a familiar one to U.S. regulators. Auto-warranty fraud, the "your car's extended warranty is about to expire" genre, is heavily documented: the FCC ordered voice providers to block an auto-warranty robocall operation in 2022, the FTC has banned operators of extended-vehicle-warranty schemes, and in 2024 CarShield's parent company settled an FTC action over its own deceptive marketing for vehicle service contracts. This operator has no connection to CarShield. It impersonates the brand. Regulators consistently note that a real warranty company does not cold-email or cold-text consumers, and that is exactly the trust the operator borrows: it fronts CarShield and Endurance look-alikes, then rotates the same infrastructure through auto-insurance, life-insurance (Fidelity Life look-alikes), debt-relief, Medicare, and sweepstakes lures.
The operator abuses two platforms in ways worth spelling out: Azure Blob Storage and DMARC aggregate reporting.
Azure Blob Storage (*.blob.core.windows[.]net) serves static files from publicly readable containers under Microsoft's own domain, with valid Microsoft-issued TLS. Scammers host landing pages there because the trusted parent domain and legitimate certificate make the page look benign and cause some tooling to skip inspection. Containers are cheap, near-anonymous, and easy to spin up and burn. Microsoft's own security team documented active phishing abuse of this surface in October 2025. The apex is shared Microsoft infrastructure and is never itself an indicator: only the specific operator-created container is adversarial.
DMARC aggregate reporting is the second. A DMARC record's rua= tag names an address where receiving providers send daily XML reports listing every IP that sent mail claiming to be from the domain, and whether authentication passed. The entire point is that a human or a monitoring service reads those reports. Legitimate senders route them to a service such as dmarcian, Postmark, Valimail, or EasyDMARC, or to a staffed deliverability inbox. Routing them back to a mailbox on the same throwaway domain, where they are auto-discarded, is not brand protection. It is an operational tell that the domain is disposable.
Discovery and Infrastructure
The investigation began with a known brand-impersonation pool: a set of throwaway domains fronting CarShield and Endurance auto-warranty lures. Joining that 3,752-domain pool against WHOIS and DNS data exposed a signature that turned out to be far more general than the original brand keyword.
Two anti-patterns dominated the pool. First, nearly every domain that published DMARC at all self-routed its aggregate reports to a report@ mailbox on its own apex. Second, a large share published an SPF record consisting of exactly one hardcoded IPv4 address and a hard-fail -all, with no ESP include: and no mx mechanism. Each anti-pattern alone carries some false-positive risk. A small business that hand-configured DMARC to an internal inbox would match the first; a single-server install with manual SPF would match the second. Their co-occurrence on the same apex is what matters. A business with the maturity to publish a strict DMARC policy almost always routes reports somewhere useful and almost always has multi-mechanism SPF. The intersection is empirically near-absent from legitimate corpora, which makes it an attribution signature rather than a heuristic.
Running the stacked fingerprint against the full URL-reputation corpus, and excluding shared-hosting infrastructure, returned 12,798 domains. Only about 1,100 of those matches came from the original 3,752-domain CarShield and Endurance pool; the rest of that seed pool never published the fingerprint. The other roughly 11,700 matches were previously unattributed, and they were not confined to auto warranty. Life-insurance, auto-insurance, debt-relief, Medicare, and sweepstakes display names all appeared on domains carrying the identical authentication stack. The fingerprint does not identify one campaign. It identifies a sending chassis that one operator ecosystem reuses across every vertical it runs.
How It Works
A single aged domain is a self-contained sending and redirect unit. The envelope-from, the header-from, the DMARC rua target, and the click-through host all point at the same apex. There is no ESP in the path and no separate landing domain in the authentication records.
The domain sends a burst of near-identical messages, each with a rotating random envelope-from localpart, then goes quiet. The visible message is usually image-based, impersonating a warranty or insurance brand, with a call-to-action button. That button does not link to the impersonated brand. It links back to a randomized PHP endpoint on the sending domain, of the form /r####.php?32=<token>, where the ?32= value is a per-recipient tracking token. That endpoint redirects the click to the real landing page, which sits in a burner Azure Blob Storage container. When one landing container is reported, the operator spins up another. When a sending domain accumulates reputation damage, it is abandoned for the next aged drop in the queue. New domains debut at a rate of roughly 37 per day.
Sample Lures
All samples below are real messages with recipient identifiers and per-recipient tracking tokens redacted, and every domain and URL defanged. They show attacker-side content only.
The primary auto-warranty lure impersonates CarShield, quotes the real company's mailing address and disclaimers in the footer to look authentic, and routes its call-to-action through the self-hosted redirect on the sending domain:
From: "CarShield*" <vvv...zvn03ou0w_@voztec[.]com>
Subject: [recipient token] ""2026AUTO PROTECTION.QUOTES"" [random tracking token]
Return-Path: <return@voztec[.]com>
List-Unsubscribe: <http[:]//voztec[.]com/mail/un-subscribe/m/eo?id=221B928D-...&sid=...>
ENDURANCE
CarShield.
Avoid Costly Car Repairs
When one repair can cost more than a year of protection
[ GET YOUR FREE QUOTE ] -> http[:]//voztec[.]com/r91ba.php?32=[tracking token]
333 Mid Rivers Mall Drive, St. Peters, MO 63376
Preview contracts at carshield[.]com. Exclusions and deductibles apply.
A second vertical swaps the same chassis to an Endurance auto-insurance pretext. The visible body is scraped newsletter text used as filler, with the real offer carried in the subject line and an image:
From: "Drive For Less" <[random localpart]@anokana[.]com>
Subject: 2026: As low as $38/Month for Auto Insurance [tracking token]
[decoy filler body] ... ENDURANCE Save Big on Auto Insurance ...
The same domain also runs a Fidelity Life impersonation the same week, which is one of the clearest tells that the vertical is a content layer rather than a separate actor:
From: "Fidelity Life Offer" <[random localpart]@anokana[.]com>
Subject: Confirm Your Life Insurance Quote in Minutes.. [tracking token]
The auto-rate variant shows the display-name obfuscation and the decoy-body technique together. The visible text is lifted from an unrelated newsletter (here a political-news digest and foreign-language filler), which pushes the message away from the spammy-content profile a classifier expects:
From: "2026 RateSSRISE!!." <[random localpart]@abridalbargain[.]com>
Subject: Rates Confirmed - Crush Them Before They Rise! [tracking token]
[scraped newsletter decoy] ... President Donald J. Trump's 2026 State of the Union ...
Technical Analysis
The infrastructure, more than the lure, is the durable operator identity. Six signals, layered, describe it.
The Aged-Domain Supply Chain
WHOIS creation dates on the operator set cluster overwhelmingly before 2020, most 10 to 25 years old at the time of abuse. Across the resolvable operator domains, roughly 97% predate 2020, and registrant identity is uniformly scrubbed behind registrar privacy shields (Domains By Proxy on the GoDaddy set, Super Privacy Service on the Dynadot set). A representative slice:
| Domain | Registrar | Created | WHOIS org |
|---|---|---|---|
dennywiggers[.]com |
GoDaddy | 1997 | (none) |
hollandheaterusa[.]com |
GoDaddy | 1999 | (none) |
stainlesscomputing[.]com |
GoDaddy | 2004 | (none) |
wprsource[.]com |
GoDaddy | 2006 | domains by proxy, llc |
tradewithwisdom[.]com |
GoDaddy | 2007 | (none) |
psychicworldwide[.]com |
GoDaddy | 2008 | (none) |
dilfallnight[.]com |
GoDaddy | 2009 | (none) |
nineface[.]com |
Name.com | 2009 | domain protection services, inc. |
voztec[.]com |
GoDaddy | 2010 | (none) |
anokana[.]com |
Dynadot | 2011 | super privacy service ltd c/o dynadot |
ataconline[.]org |
Name.com | 2013 | (none) |
abridalbargain[.]com |
Dynadot | 2018 | super privacy service ltd c/o dynadot |
Registrar concentration across the full pool is tight: GoDaddy carries roughly 69%, Dynadot roughly 13%, and Namecheap roughly 8%, with the top three registrars covering close to 90% of domains. That concentration reflects where bulk aged-drop tooling is cheapest, and it makes the supply chain itself a pivot.
The Authentication Fingerprint
The DMARC record is byte-identical across the set except for the apex substitution. Every domain publishes v=DMARC1; p=reject; pct=100; rua=mailto:report@<own_apex>; ruf=mailto:report@<own_apex>. The strict report@ localpart is a provisioning-template default, not a decision any of these domains' notional owners made:
| Domain | DMARC rua target | Policy | SPF |
|---|---|---|---|
wprsource[.]com |
report@wprsource[.]com |
reject | ip4:104.36.23[.]220 -all |
voztec[.]com |
report@voztec[.]com |
reject | ip4:67.23.234[.]5 -all |
dilfallnight[.]com |
report@dilfallnight[.]com |
reject | ip4:148.72.167[.]139 -all |
exampasses[.]com |
report@exampasses[.]com |
reject | ip4:216.189.145[.]172 -all |
anokana[.]com |
report@anokana[.]com |
reject | ip4:69.65.11[.]13 -all |
mangatraitheoriginal[.]com |
report@mangatraitheoriginal[.]com |
reject | ip4:192.227.96[.]47 -all |
dogdundee[.]com |
report@dogdundee[.]com |
reject | ip4:83.136.51[.]50 -all |
be-15[.]org |
report@be-15[.]org |
reject | ip4:95.214.55[.]138 -all |
Two corroborating details ride along. Most domains also carry an INT:: Google Search Console verification TXT record left over from the prior legitimate owner, DNS residue the operator never cleaned out after acquisition, which independently confirms the aged-drop origin. And none of the domains publish DKIM in their TXT records. The operator runs DMARC and SPF only, no message signing, which is itself unusual for a sender publishing a strict p=reject policy.
The combined signal, a self-routed rua plus a single-IP -all SPF on the same apex, does not appear to have a prior published name. It is presented here as an original attribution signature, not a third-party classification.
Outbound-IP Clustering
Because each domain pins exactly one IP in SPF, the pool's outbound infrastructure is trivially enumerable, and it clusters hard. Rolling the single SPF IPs up to /24 and /16 blocks shows a small set of budget-hosting ranges doing all the work:
| Block | Operator domains | Notes |
|---|---|---|
104.36.23[.]0/24 |
8 | shared /24 |
192.227.96[.]0/24 |
8 | shared /24 |
162.251.160[.]0/24 |
6 | shared /24 |
77.247.124[.]0/24 |
5 | shared /24 |
95.214.55[.]0/24 |
5 | shared /24 |
67.23[.]0.0/16 |
12 | spread across 8 distinct /24s |
192.227[.]0.0/16 |
11 | 3 distinct /24s |
104.36[.]0.0/16 |
10 | 2 distinct /24s |
The 67.23[.]0.0/16 backbone is the most prominent, with a dozen operator domains sprayed across eight of its /24s. The operator rotates burner IPs inside a handful of contiguous hosting ranges while keeping each sending domain pinned to one address, so the shared /16s tie otherwise-unrelated aged domains back to a single supply chain.
Sender and Display-Name Grammar
The envelope-from localpart rotates on every send, in two dominant shapes: a short random token followed by a role suffix (<9-char-random>-no_reply@nineface[.]com), and a seed word followed by a long run of underscores and a random block (notification______________________<random>@hollandheaterusa[.]com). The underscore padding pushes any readable content out of the visible localpart window.
Display names obfuscate a real brand token so the string renders as the brand to a human but defeats exact-string matching. The taxonomy is broad and systematic:
- separator-splitting:
Car*Shield*,CarShield/Support,AUTO|INSURANCE - Unicode-separator injection:
CarShield•Coverage(bullet),AUTO·INSURANCE(middot),AUTO▪INSURANCE(black square) - zero-width-space injection:
Jason | CarShieldandCar/Shield.with a trailing or embedded ZWSP - leet substitution:
FastAUT0Notice(zero for O),2026 Rates RlSE!(lowercase L for I),AUTO-INNSURANCE(doubled letter) - bracket and asterisk wrapping:
FidEliTylife{},*Auto/Insurance*
The same brand tokens recur at scale. CarShield variants span more than 40 domains and Fidelity Life variants span around 20, all on the identical fingerprint.
The Redirect Kit and Burner Landings
The call-to-action targets a randomized PHP endpoint on the sending domain, /r####.php?32=<token>, where the four-character filename regenerates per wave (r91ba, rc0c2, r30f5, rd189) and the ?32= value is a per-recipient tracking token. The redirect fans out to a landing container on *.blob.core.windows[.]net. Container names are random lowercase-alphanumeric strings ranging from four to twenty-four characters:
| Short (4-6) | Mid (8-14) | Long (18-24) |
|---|---|---|
tfqv, hdmc, qeb4d, 1oflm |
6dez1fv4bdw, la903ekvq2, ekk2mzb1ayw |
dwbwalblfmo2hezuodzw5z5e, tww1ypshh8yvknub7nzdb7su |
Some waves add one more hop: a short five-character random-prefix subdomain on a pool apex (for example 7cp3h.velteatrix[.]world) that resolves to the bucket, so the visible link carries neither the sending domain nor the Microsoft host. Across the auto-warranty pool alone, 82 distinct Azure Blob containers were observed hosting kit landings. The apex is shared Microsoft infrastructure; only the specific container is operator-controlled. The messages also self-align on every axis at once: the envelope return-path, the header-from, the DMARC rua, and the redirect host all point at the one aged apex, and a common List-Unsubscribe GUID template recurs across domains as a soft supply-chain marker.
One Chassis, Six Verticals
The same three-part fingerprint (an aged pre-2020 dropped domain with scrubbed WHOIS, the self-routing DMARC plus single-IP SPF stack in the shared hosting /16s, and the /r####.php?32= redirect to Azure Blob) appears verbatim across every vertical the ecosystem runs:
| Vertical | Display-name evidence | Example domains |
|---|---|---|
| Auto-warranty (CarShield/Endurance impersonation) | CarShield, Car*Shield*, Welcome to Endurance |
wprsource[.]com, nineface[.]com, seadoodealers[.]com |
| Auto-insurance | DriveForLess, AutoRatesFast, As Low As $38 Auto Quote |
mangatraitheoriginal[.]com and siblings |
| Life-insurance (Fidelity Life impersonation) | FidelityLife, Fidelity.Life, FidelityLiFeE! |
anokana[.]com and ~20 domains |
| Debt-relief | DebtReliefAdvocates, USNationalDebtReliefService |
shared infra set |
| Medicare / health | TheMedicareHelpline, Clinical Trial Alert |
shared infra set |
| Sweepstakes / prize | BonusMonster, Approbatíon.du.Gagnant.! |
shared infra set |
A single domain such as mangatraitheoriginal[.]com rotates between auto-insurance, life-insurance, and auto-warranty display names while keeping one pinned SPF IP and one self-route DMARC. The vertical is a content layer swapped on top of a shared sending chassis, and the authentication fingerprint plus the Azure-Blob-and-redirect supply chain are the durable operator identity.
Detection Observations
The behavioral signals that separate this traffic from legitimate mail are structural, which is what makes them useful to a defender who cannot rely on the lure content.
- The stacked co-occurrence of a self-routed DMARC
ruaand a single-IP-allSPF on the same apex is the strongest single marker. Either alone has legitimate edge cases; together they are near-absent from real sender corpora and can be computed from published DNS at scan time without touching message content. - Full self-alignment is a corroborating signal: envelope return-path, header-from, DMARC
ruamailbox, and the click-through host all resolve to the same apex, which is not how a domain using any real ESP behaves. - Inherited DNS residue is a tell. A domain sending unrelated commercial mail while carrying a prior owner's Google Search Console verification TXT record is very likely a repurposed drop.
- Display-name obfuscation around a known brand token, especially Unicode-separator injection and zero-width-space padding, indicates an attempt to render a brand to a human while defeating exact-string matching. Normalizing the display name (strip zero-width characters, collapse non-alphanumeric separators, lowercase, then match against a brand-token list) re-exposes the brand string that literal matching would skip.
- One IP pinned in SPF, drawn from a small set of budget-hosting /16s shared across many otherwise-unrelated domains, is a reputation pivot: flagging the range surfaces siblings.
- A
/r####.php?32=<token>redirect hosted on the sending domain itself, rather than a link straight to the brand or to a normal tracking service, is a self-hosted-redirect indicator worth keying on.
Indicators of Compromise
All indicators are defanged. The domain list is a representative subset of the verified-malicious set, weighted toward the highest-volume sending hubs.
Sending Domains
| Domain | Role | Notes |
|---|---|---|
voztec[.]com |
Sender / redirect | CarShield lure, /r91ba.php redirect |
anokana[.]com |
Sender / redirect | Drive For Less / Fidelity Life |
abridalbargain[.]com |
Sender / redirect | auto-rate, decoy-body |
ataconline[.]org |
Sender / redirect | auto-rate |
tradewithwisdom[.]com |
Sender / redirect | multi-vertical |
be-15[.]org |
Sender / redirect | auto-insurance |
psychicworldwide[.]com |
Sender / redirect | CarShield / Endurance |
hollandheaterusa[.]com |
Sender / redirect | CarShield |
po-po-ya[.]com |
Sender / redirect | CarShield-protection |
phomkhmer[.]com |
Sender / redirect | CarShield support |
stainlesscomputing[.]com |
Sender / redirect | CarShield USA |
wprsource[.]com |
Sender / redirect | prolific frontend |
dilfallnight[.]com |
Sender / redirect | Fidelity Life |
nineface[.]com |
Sender / redirect | CarShield coverage |
mangatraitheoriginal[.]com |
Sender / redirect | vertical-rotating |
| … | (representative subset; 250+ verified-malicious sending domains) |
CTA Host
| Host | Role | Notes |
|---|---|---|
7cp3h.velteatrix[.]world |
CTA subdomain | 5-character random-prefix front end |
Outbound IPs (single-IP SPF)
| IP | Role |
|---|---|
104.36.23[.]220 |
operator outbound |
148.72.167[.]139 |
operator outbound |
192.227.96[.]47 |
operator outbound |
216.189.145[.]172 |
operator outbound |
67.23.234[.]5 |
operator outbound |
69.65.11[.]13 |
operator outbound |
83.136.51[.]50 |
operator outbound |
95.214.55[.]138 |
operator outbound |
MITRE Fight Fraud Framework Mapping
Mapping aligns to the MITRE CTID Fight Fraud Framework (F3) matrix. Technique labels use F3 vocabulary; enterprise ATT&CK analogs are noted where the pre-compromise activity maps more precisely there.
| Tactic | Observed behavior | Observed behavior |
|---|---|---|
| Resource Development | Acquire Infrastructure | Bulk purchase of aged dropped domains; single-IP relays; burner Azure Blob containers (ATT&CK analog T1583) |
| Resource Development | Spoof Authentication | Publishing self-routing DMARC and single-IP SPF to appear authentication-compliant |
| Initial Access | Phishing / Unsolicited Message | Cold lead-gen email to consumer inboxes |
| Initial Access | Brand Impersonation | CarShield, Endurance, and Fidelity Life look-alike display names and footers |
| Execution | Lure to Attacker-Controlled Destination | /r####.php?32= self-hosted redirect to Blob-hosted landing (ATT&CK analog T1204) |
| Stealth | Trusted-Infrastructure and Reputation Abuse | Aged-domain trust inheritance, Microsoft Blob parent-domain trust, self-discarded DMARC reports |
Conclusion
The operator's edge is patience, not novelty. By sourcing aged domains instead of registering fresh ones, it neutralizes the one heuristic most filters weight the heaviest, and by publishing an authentication stack that only performs compliance, it clears the checks that reward domains for having DMARC and SPF at all. The weakness is that the performance leaves fingerprints. A self-routed report mailbox and a lone authorized IP are cheap for the operator to deploy and cheap for a defender to detect from public DNS alone. Enumerating the population by its authentication grammar, rather than by the brand of the week, is what turns a rotating pool of throwaways into a single, trackable adversary.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.