One Registrant, Three Sending Rails: A Multi-Vertical Email-Scam Fleet
One Registrant, Three Sending Rails: A Multi-Vertical Email-Scam Fleet
Over nine months, one operator ran an eight-vertical email fleet across three sending rails, two of them paid email platforms, under one WHOIS registrant. The operator we track as Swanhurst does not impersonate a bank or a shipping brand. It rents legitimate email infrastructure, spins up single-tenant subaccounts on paid email service providers, and rotates the same prize, benefits, loan, and job lures through whichever funnel is converting that week. Six of the eight verticals carry lures; the other two are weather and news filler that warms the sending identities. What makes the fleet legible is not the messages, which are generic by design, but the naming of the infrastructure behind them: the operator registers tracking domains named after its own ESP subaccounts, and it registers them in same-day batches under one holding-company shell.
Key Takeaways
- One operator runs three parallel sending rails: roughly 20 single-tenant Sailthru ESP subaccounts, 27 Robly ESP subaccounts, and 7 self-hosted SMTP relay senders whose bounce path routes back through Sailthru MX.
- A single WHOIS registrant string ties more than 80 domains together across three registrars, spanning all three rails.
- The operator co-registers tracking domains literally named after its subaccount labels (a
sharesubaccount getssharesailpmta[.]com,sharemxsail[.]com), so the domain estate is a readable index of the subaccount roster. - Same-day registration cohorts pair self-attributed domains with privacy-scrubbed backend twins on the identical date, a linkage signal stronger than any single WHOIS field.
- Subaccount labels are camouflage, not vertical predictors: one
crime.robly[.]comsubaccount sends sweepstakes, job-interview, utility-benefits, and credit lures interchangeably. - A small shared pool of click-through landing domains is reused across about ten subaccounts each, which is the cleanest cross-cluster pivot for attribution.
Background
Most email-scam infrastructure hides by looking cheap and disposable: freemail senders, throwaway domains registered the morning they are used, burned within days. This operator does the opposite. It pays for real email service providers and behaves, at the delivery layer, like a legitimate high-volume marketer. That choice is the whole strategy.
An email service provider (ESP) is a platform businesses use to send bulk mail: newsletters, receipts, promotions. Sailthru, owned by Marigold, and Robly are both established ESPs marketed to publishers, retailers, nonprofits, and small businesses. When a customer signs up, the ESP provisions a sending identity, often a single-tenant subaccount on a shared sending domain. On Sailthru that looks like benefits.pmta.sailthru[.]com, where pmta refers to PowerMTA, the mail-transfer software behind the rail, and mx.sailthru[.]com handles bounce processing. The subaccount inherits the ESP's warmed sending reputation, its TLS certificates, and its trusted parent domain. A scammer who onboards as a paying customer gets all of that for the price of a subscription.
The operator abuses this in three ways at once. It buys a fleet of Sailthru subaccounts, one sender identity each. It runs a parallel fleet of Robly subaccounts with the same lures. And for a job-alert vertical it sends from its own domains but points the return path at Sailthru's bounce MX, borrowing the ESP's deliverability handling without sending through it. Rented reputation across three rails gives the operator redundancy: when one delivery surface degrades, the others keep running. Across the active window the fleet pushed well over a million messages from these rails combined.
None of the lures impersonate a specific company as their sender. The operator works the affiliate lead-generation model, where the payout comes from harvesting a consumer's contact and financial details and passing the lead downstream, not from a one-shot credential theft. The bait is deliberately generic scam vernacular: prize money, pending payments, approved loans, interview requests. Real brand names (Amazon, Zelle, Cash App, and various subprime store cards) appear inside the body copy as bait references, never as the claimed sender.
Discovery and Infrastructure
The fleet surfaced through its Sailthru subaccounts. Each subaccount is single-tenant, with exactly one sender address, and the subaccount labels read like a product catalog: benefits, financial, cardarena, myfinances, jobfinder, daily, share. That alone is not attribution. Any number of unrelated marketers could hold adjacent subaccounts. What collapsed roughly 20 Sailthru subaccounts, 27 Robly subaccounts, and 7 self-hosted senders into one operator was the overlap in what they linked to.
A small set of click-through landing domains is shared across the fleet. The three busiest, homeunemploymentbenefitsfinder[.]com, realwealthinfo[.]com, and reademergencymessages[.]com, each appear behind roughly ten different subaccounts. Independent marketers do not share private landing pages. A shared landing pool used by ten sender identities on two different ESPs is a single operation wearing many sender costumes.
The second pivot is the WHOIS registrant. More than 80 of the operator's domains carry one organization string, "Swanhurst Holdings LLC," across NameCheap, GoDaddy, and one legacy Joker.com registration. Independent research shows that name only as a domain-registration entity sitting behind spam and scam properties, not as a real operating business. It is the operator's own paperwork, and it is the thread that ties the Sailthru rail, the Robly rail, and the self-hosted relays to one hand.
The Robly estate coexists with legitimate Robly customers on the same platform. The operator's subaccounts separate cleanly from real tenants on three signals: they share the operator's landing pool, they carry the same rotating persona names, and they went dark together on a single day when the primary Sailthru cohort burned down. Genuine Robly customers kept sending. That separation matters, because the takeaway is not that the ESP is malicious. The ESP is the victim of a paying abuser, and only the operator's own third-level subaccounts belong to the fleet.
How It Works
A recipient receives a message from a warmed ESP subaccount with a display name like SuperSweeps, Successful Documentation, or David @ CareerHunter. The subject promises money in a specific dollar amount, frames it as time-sensitive with tags like *Last Notice* or (3rd Attempt), and personalizes with the recipient's first name pulled from an ESP merge field. The body is short, restates the offer, and pushes one link.
That link is wrapped in the ESP's own click tracker (cb.sailthru[.]com/oc/<token> on the Sailthru rail), so the first hop looks like ordinary marketing telemetry from a trusted domain. Following the redirect surfaces the operator's landing domain, a tokenized path of the shape /<UUID>-<64-hex> on one of the shared lead-capture pages. The landing page collects the consumer's details for the lead-gen payout. The click-tracker wrapping is deliberate: naive link extraction stops at the ESP tracker and never sees the operator domain unless it follows the redirect.
The same sender rotates through unrelated pretexts. One Robly subaccount, in a single window, sent a million-dollar sweepstakes notice, a utility-bill-assistance "third attempt," a job-interview request, and a credit-card balance alert. The subaccount label predicts nothing about the lure. The operator runs whatever vertical is performing, from whichever identity is warm.
Sample Lures
The samples below are real messages from the fleet, with all recipient identifiers removed and links defanged. They show four of the eight verticals, all sent from operator subaccounts on the shared rails. Note that the currency figures, emoji, and urgency tags in the subject lines are part of the lure and are reproduced as observed.
Reward / sweepstakes lure (Robly subaccount):
From: "Online Research" <noreply@crime.robly[.]com>
Subject: STAY CALM | YOU'VE WON $1,000,000.00, [first name]?
Body: Do your best to stay calm, [first name]! The $1,000,000.00 prize
is being assigned today. Confirm your details at the attached site
to begin your claim. -> hxxps://<landing-domain>/<UUID>-<64-hex>
Benefits / pending-payment lure (Sailthru subaccount):
From: "Go" <noreply@benefits.pmta.sailthru[.]com>
Subject: PICK UP YOUR PAYMENT *Last Notice*
Body: This is your last notice that you can still request the payment
opportunity available to you. Confirm eligibility now before it
is released. -> hxxps://unemploymentbenefitsfindercare[.]com/<UUID>-<64-hex>
Credit / loan lure (Sailthru subaccount):
From: "Successful Documentation" <noreply@benefits.pmta.sailthru[.]com>
Subject: APPROVED LOAN (Request Form Enclosed)
Body: [subprime-card brand] [first name], we have great news! You can
receive your approved offer. Complete the request form enclosed.
-> hxxps://<landing-domain>/<UUID>-<64-hex>
Job / employment lure (Robly subaccount):
From: "David @ CareerHunter" <noreply@crime.robly[.]com>
Subject: [employer name] Wants to Interview [first name]
Body: I've been trying to contact you. [employer name] wants to move
forward. Respond to confirm your interview slot.
-> hxxps://<landing-domain>/<UUID>-<64-hex>
Technical Analysis
The Tracking-Domain Grammar
The operator's most distinctive signature is how it names infrastructure. For each Sailthru subaccount label, it registers tracking and redirect domains built by concatenating the label with tokens lifted from the sending rail itself: pmta (PowerMTA), and sail / thru / mx (from mx.sailthru[.]com). The result is a domain estate that reads as a literal index of the subaccount roster.
| Subaccount label | Name-mirror tracking domains (defanged) |
|---|---|
share |
sharesailpmta[.]com, sharethrupmta[.]com, sharepmta[.]com, sharemxsail[.]com, sharesailmx[.]com |
daily |
dailypmta[.]com, dailypmtathru[.]com, dailypmtasail[.]com, dailymxsail[.]com |
hero |
heromxthru[.]com, mxheros[.]com |
financial |
financialpmta[.]com, financialpmtasail[.]com |
myfinances |
myfinancespmta[.]com, junipermyfinances[.]com |
employment |
employmentpmta[.]com, employmentpmtas[.]com |
platinum |
platinumpmta[.]com, netfirstplatinumpmta[.]com |
benefits |
benefitspmta[.]com |
This grammar is close to unique. A pmta or mxsail suffix on an otherwise ordinary English label is not a shape legitimate registrants produce. Pattern-matching on <token>pmta(sail|thru)?[.]com and <token>mx(sail|thru)?[.]com catches new operator domains the moment they are registered, before they ever appear in traffic, though the pattern needs anchoring on the operator suffix to avoid colliding with legitimate names such as butterflymx[.]com.
Registration Cohorts and the Dual-String Tell
The operator registers in same-day batches, and the batches carry a second signature the operator probably did not intend to expose. NameCheap registrations split across two registrar-string variants. Domains registered under one variant self-attribute the "Swanhurst Holdings LLC" organization; the backend tracking twins are registered privacy-scrubbed under a second variant on the same date. Registering the self-attributed CTA and filler names alongside the privacy-shielded backend twins on the identical day binds the anonymous infrastructure to the named infrastructure more tightly than any single WHOIS field could.
| Cohort date | Registrar | Example domains (defanged) | Count |
|---|---|---|---|
| 2010-07-21 | Joker.com | espchat[.]com (aged acquisition) |
1 |
| 2022 (Apr to Oct) | GoDaddy .info |
supremetelecasttodetecttoday[.]info, choicestdatalettertoregardtoday[.]info |
~20 |
| 2025-10-15 | NameCheap | chucklerinbox[.]com, dianaespchatter[.]com + privacy twins dianaespchat[.]com, espchatty[.]com |
17 |
| 2025-10-17 | NameCheap | sharesailpmta[.]com, heromxthru[.]com + privacy twins dailypmta[.]com, dailypmtasail[.]com |
17 |
| 2025-12-09 | NameCheap | acceptancepmtasail[.]com, financialpmtasail[.]com + privacy twins financialpmta[.]com, myfinancespmta[.]com |
9 |
| 2026-01-22 | NameCheap | celebinsiderscoops[.]com, weather-dailybox[.]com, quickjobalerter[.]com |
17 |
| 2026-02-02 | NameCheap | benefitspmta[.]com, employmentpmtas[.]com, happy2news[.]com |
6 |
Some inventory predates the active sending window by years: espchat[.]com, acquired via Joker.com around 2010, a GoDaddy name from 2011, and the 2022 .info batch, all registered well before the 2025 and 2026 provisioning cohorts and reused as the operation stood up. Aged-domain reuse for a backend deliverability family alongside freshly minted, purpose-built tracking cohorts is a common operator pattern: the aged names lend the sending backbone a longer, calmer history while the burnable tracking layer rotates on top.
Domain-Generation Templates
Four naming templates run in parallel, each mapped to a role.
- Template A, the ESP name-mirror tracking domains described above:
<label>plus a PowerMTA or Sailthru-MX token. - Template B, a GoDaddy
.infonews-clickbait batch built by a slot grammar:<adjective>-<noun>to-<verb>-today[.]info. The adjective slot draws from a fixed vocabulary (supreme,prominent,choicest,attractive,preferred,certified, and others), the noun slot from news words (telecast,bulletin,article,dataletter,report), and the verb slot from reading words (detect,regard,identify,study). The output,supremetelecasttodetecttoday[.]info, is machine-generated at a glance. - Template C, vertical-keyword landing domains: a benefit or money word plus a suffix such as
finder,guide,matchers,alert, orsavings. Examples:homeunemploymentbenefitsfinder[.]com,virtualcreditcardfinder[.]com,localjobmatchers[.]com,sweepstakesguide[.]com. - Template D, an ESP-backend deliverability family keyed on the tokens
espchat,inbox, andchuckle:dianaespchat[.]com,espchatty[.]com,chucklerinbox[.]com,chucklesinboxer[.]com.
CTA Family to Vertical Mapping
The landing-domain vocabulary sorts cleanly onto the eight lure verticals, which is useful because the sender identity does not. Grouping domains by their keyword stems recovers the vertical structure that the sender labels hide.
| Vertical | Representative landing / tracking domains (defanged) |
|---|---|
| Unemployment / benefits | homeunemploymentbenefitsfinder[.]com, benefitspmta[.]com, planetunemploymentbenefitsguide[.]com |
| Credit / financial | financialpmtasail[.]com, virtualcreditcardfinder[.]com, topcreditcardsoft[.]com, realwealthinfo[.]com |
| Jobs / employment | employmentpmta[.]com, localjobmatchers[.]com, quickjobalert[.]com (self-hosted rail), myelitejobs[.]com |
| Class-action / emergency-alert | reademergencymessages[.]com, crimereport[.]net, the Template-B .info news grammar |
| Sweepstakes / reward | sweepstakesguide[.]com, sweepstakesguide[.]me, foundamoney[.]com |
| Housing / home | myhousingsolutionconnect[.]com, fixupnester[.]com |
| Weather filler | weather-dailybox[.]com, theweatherdailies[.]com, webweatherdailies[.]com |
| News / celeb filler | celebinsiderscoops[.]com, cuisineoftoday[.]com, dailyhistoric[.]com, happy2news[.]com |
What Ties the Clusters Together
Five signals bind the Sailthru rail, the Robly rail, and the self-hosted relays into one operation. The single WHOIS registrant string spans more than 80 domains across all three rails. The shared landing pool is reused across about ten subaccounts each. The self-hosted job-alert senders route their return path through mx.sailthru[.]com, binding them to the Sailthru rail. The espchat backend family serves deliverability across subaccounts. And the name-mirror tracking domains index the subaccount roster one-to-one. The operator also keeps dozens of registered-but-unused domains in reserve, a provisioning pipeline for the next wave that WHOIS-registrant pivoting exposes before any of them send.
One caveat for anyone mapping this estate: the ESP sending rails themselves (sailthru[.]com, pmta.sailthru[.]com, mx.sailthru[.]com, and the robly[.]com parent) are shared multi-tenant platforms carrying legitimate customers. Only the operator's own third-level subaccounts and its co-registered domains belong to the fleet. The shared rails must never be treated as operator infrastructure.
Detection Observations
The fleet is easy to recognize at the ecosystem level and deliberately hard to recognize per message. Any single email resembles an aggressive but ordinary marketing blast: a warmed ESP sender, a personalized subject, one wrapped link. The scam is visible in the relationships, not the content.
- The strongest cross-cluster pivot is the shared landing pool. A handful of lead-capture domains sitting behind ten different sender identities on two ESPs is a structure legitimate marketers do not produce.
- The tracking-domain grammar (
<label>plus apmta/mxsail/mxthrutoken) is close to operator-unique and observable at registration time, ahead of traffic. - The same-day dual-string registration cohorts link privacy-scrubbed backend domains to self-attributed ones, so a WHOIS-registrant pivot recovers unused reserve domains before they are ever sent from.
- Sender label and lure vertical are decoupled, so vertical-keyword rules keyed to one theme miss the operator's full footprint. Persona-name reuse and landing-pool membership generalize where subject keywords do not.
- A return path of
mx.sailthru[.]comon a sender that is not itself a Sailthru subaccount is a strong same-operator tell for the self-hosted rail.
Indicators of Compromise
All indicators are defanged. Recipient data has been removed. The lists below are a representative subset of the operator's verified-malicious infrastructure, weighted toward durable hubs over throwaway names.
Senders
| Value | Role | Notes |
|---|---|---|
noreply@crime.robly[.]com |
Sender | Highest-breadth Robly subaccount; all personas observed here |
noreply@cuisineoftheday.robly[.]com |
Sender | Robly subaccount; cuisineoftoday[.]com name-mirror |
noreply@dayofhist.robly[.]com |
Sender | Robly subaccount |
noreply@emergencymessagenews.robly[.]com |
Sender | Emergency-alert persona host |
curator@dailyhistoricfacts.robly[.]com |
Sender | Robly subaccount; dailyhistoric[.]com name-mirror |
noreply@unemploymentguide.robly[.]com |
Sender | Benefits vertical |
noreply@guide2employ.robly[.]com |
Sender | Jobs vertical |
noreply@theamericansurvey.robly[.]com |
Sender | Survey vertical |
active@signal.quickjobalert[.]com |
Sender | Self-hosted relay; return-path mx.sailthru[.]com |
work@quickjobalert[.]com |
Sender | Self-hosted relay |
employment@start.quickjobalert[.]com |
Sender | Self-hosted relay |
lineup@mission.myelitejobs[.]com |
Sender | Self-hosted relay |
| … (representative subset; 50+ verified-malicious sender addresses) |
Domains
| Value | Role | Notes |
|---|---|---|
sharesailpmta[.]com |
Tracking / redirect | Name-mirror of share subaccount |
heromxthru[.]com |
Tracking / redirect | Name-mirror of hero subaccount |
financialpmtasail[.]com |
Tracking / redirect | Financial vertical |
benefitspmta[.]com |
Tracking / redirect | Benefits vertical |
homeunemploymentbenefitsfinder[.]com |
Landing | Shared pool; used across ~10 subaccounts |
realwealthinfo[.]com |
Landing | Shared pool; aged 2011 GoDaddy name |
reademergencymessages[.]com |
Landing | Shared pool; emergency-alert pretext |
sweepstakesguide[.]com |
Landing | Sweepstakes vertical |
dianaespchat[.]com |
Backend | ESP-backend deliverability family |
espchat[.]com |
Backend | Aged 2010 Joker.com acquisition |
supremetelecasttodetecttoday[.]info |
Landing | Template-B .info news-clickbait grammar |
cuisineoftoday[.]com |
Landing | Robly-side CTA name-mirror |
crimereport[.]net |
Landing | WHOIS org string emergencymessagesystem |
myhousingsolutionconnect[.]com |
Landing | Housing vertical |
planetunemploymentbenefitsguide[.]com |
Landing | Benefits vertical |
| … (representative subset; 200+ verified-malicious domains) |
WHOIS Registrant
| Value | Role | Notes |
|---|---|---|
| Swanhurst Holdings LLC | Registrant string | Ties 80+ domains across NameCheap, GoDaddy, Joker.com |
Conclusion
The operator's weakness is the same as its strength: consistency. Renting real ESP subaccounts buys deliverability, but naming the tracking domains after the subaccounts, and registering them in same-day batches under one holding-company shell, turns the whole estate into a fingerprint. The lures will keep rotating and the subaccount labels will keep churning, because those are cheap to change. The naming grammar and the single-registrant provisioning pipeline are not, and they expose the next wave of domains before the first message ships. Defenders watching for that grammar, and pivoting on the registrant rather than the sender, stay a cohort ahead.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.