One Burner Domain a Day: A Two-Rail Cash-Offer Lead-Gen Operation
One Burner Domain a Day: A Two-Rail Cash-Offer Lead-Gen Operation
Through spring 2026, an email operator burned roughly one throwaway domain a day, sending cash-offer lures to homeowners to harvest and resell their leads. The messages used borrowed real-estate brand names ("Sellhousefast.com Affiliate", "Liz Buys Houses Team") that had no connection to the domains sending them. Behind the display names were two distinct pieces of infrastructure operating in parallel: a high-churn fleet of single-use .top domains sent through a legitimate marketing platform, and one aged, persistent mailer that rotated dozens of unrelated brand names across many verticals. The house-selling pitch accounted for only part of the second rail's traffic. Both rails passed every email authentication check, which is exactly the point.
Key Takeaways
- The operator uses two independent sending rails under one set of borrowed cash-offer brand names: a disposable
.topdomain fleet and a single persistent multi-vertical hub. - Rail one registers and discards roughly one
.topdomain per day. Each sends through a legitimate marketing-cloud sub-account, so the messages inherit warm IPs and pass SPF, DKIM, and DMARC. - The
.topnames are machine-generated from a small dictionary recombined across three slots (qualifier, theme, structure). As the clean vocabulary runs out, the generator visibly degrades into near-nonsense middles. - Registration data divides the fleet into two registrar cohorts with a one to five day gap between creation and first send, identifying the domains as purpose-built and never intended for renewal.
- For a defender, the lasting value lies not in the domains, which are gone by the time they surface, but in the borrowed display-name brand strings and the marketing-cloud click-tracking host that ties the disposable fleet together.
Background
Unsolicited "we buy your house for cash" solicitation is an old pretext that has moved into email. The Better Business Bureau and AARP both publish consumer warnings about "we'll buy your home" mailers and ads. Consumer-finance press has documented two recurring harms: lowball contract-assignment schemes, and the lead-harvesting harm seen here, where a homeowner's contact details and property information are collected under a cash-offer pretext and resold into buyer pipelines the homeowner never opted into. The pretext works because cash home buying is a real, legal business. That also makes a real cash-buyer brand name an effective shortcut to trust.
This operation is an affiliate lead-gen spammer, not the business it names. Under this model, the sender is paid per lead. The message entices a consumer to submit information, and the resulting lead is sold downstream. Permission and brand equity do not transfer, so using a recognizable brand in the display-name slot is impersonation, not partnership. "Sellhousefast.com" and "Liz Buys Houses" are both real cash-home-buyer businesses; here, their names are borrowed as email display names by an operator that controls neither.
Two pieces of abused infrastructure make the tradecraft inexpensive. The first is Salesforce Marketing Cloud, formerly ExactTarget, a legitimate enterprise email platform that wraps outbound links through Salesforce-owned tracking hosts such as cl.s6.exct[.]net. A throwaway sub-account on that platform inherits the provider's reputable sending IPs and passes authentication automatically. The click-tracking wrapper also hides the true landing destination behind a trusted Salesforce domain until the recipient clicks. The abuse is confined to a specific sub-account; exct[.]net itself is shared Salesforce infrastructure and is never an adversary indicator. The second is the .top top-level domain, one of the cheapest generic TLDs, often sold for a dollar or two in the first year. Spamhaus and Krebs on Security have both documented .top as a favored burner TLD for this reason: a domain can be registered, used once, and abandoned long before the higher renewal price comes due.
Discovery and Infrastructure
The cluster emerged from unclassified-sender sweeps that grouped messages by cash-offer subject lines and borrowed real-estate display names. Following those two threads separated the traffic into two rails that share branding and lure copy but little else. Across the spring 2026 window, the two rails together sent thousands of cash-offer messages.
Rail one is a disposable .top fleet. More than 40 operator-registered .top apexes appear across the window. Each was used for a single send, with the display name fixed to a Sellhousefast or Liz-Buys brand string on an unrelated compound-word sending domain. Every message routes its call-to-action through Salesforce Marketing Cloud click-tracking (cl.s6, cl.s7, or cl.s13.exct[.]net). Using one domain and then discarding it prevents reputation from accumulating. Because each burner is freshly and correctly configured, every send passes SPF, DKIM, and DMARC.
Rail two is a single persistent mailer, info@mail.yourhelpfulresources[.]com, that cycles through more than 47 display names across many verticals. House-buying accounts for a minority of its output. On other days, the same address carries lending, debt-relief, insurance, telehealth, and home-services brand names borrowed in the same way. This rail runs its own mail on Zoho with a strict DMARC policy of its own. Its messages contain no extractable click-through link, forcing recognition to rely on sender and content signals rather than URL reputation.
| Indicator | Role | Notes |
|---|---|---|
mail.yourhelpfulresources[.]com |
Persistent hub sender | Aged non-brand mailer, self-hosted on Zoho, more than 47 rotating display names |
superhqline[.]top |
Burner sender | One-shot .top, cash-offer display name, click-through pointed at a blocklisted destination |
epicglobaldash[.]top |
Burner sender | One-shot .top, blocklisted click destination |
topcoreflow[.]top |
Burner sender | One-shot .top, blocklisted click destination |
cl.s6/s7/s13.exct[.]net |
Click-tracking (abused platform) | Salesforce Marketing Cloud, legitimate shared infrastructure, never flag the host |
How It Works
A recipient gets a message whose display name is a recognizable cash-buyer brand and whose subject promises a fast, no-hassle sale. On rail one, the body links through a Salesforce click-tracking URL that resolves to a lead-capture flow. On rail two, the message has no link and instead invites a reply or presents the lure as plain text. In both cases, the goal is to persuade the homeowner to provide contact details and property information, which become a sellable lead.
The seller-urgency copy remains consistent across both rails and dozens of sending domains. Subjects draw on fear of a stalled sale ("Still haven't sold?") and the promise of speed ("What if you could close next week?", "Skip the repairs. Skip the agent. Get cash."). The brand names, copy, and pretext remain stable while the sending domains churn, making the message content a much more durable fingerprint than any single domain.
Sample Lures
All samples below are attacker-side content. Sending domains are defanged, and every recipient-specific field has been replaced with a neutral placeholder.
Rail one, disposable .top burner through Salesforce Marketing Cloud:
From: "Sellhousefast.com Affiliate" <info@primedirecthub[.]top>
Subject: Skip the repairs. Skip the agent. Get cash.
[body call-to-action] http[:]//cl.s6.exct[.]net/?qs=[tracking token]
Rail two, persistent multi-vertical hub, no extractable link:
From: "Liz Buys Houses Team" <info@mail.yourhelpfulresources[.]com>
Subject: We have buyers interested in your home
A cash buyer is reviewing homes near you. A direct buyer will make a
cash offer on your property.
Rail one, higher-severity variant whose click-through pointed at a destination already on public URL blocklists:
From: "Sellhousefast.com Affiliate" <info@superhqline[.]top>
Subject: Still haven't sold?
[body call-to-action] http[:]//cl.s13.exct[.]net/[tracking path]
A later personalized variant placed the recipient's own account name in the subject and used an unrelated small-business domain instead of a fresh .top. That domain resolves to a real, established business with no connection to real estate, so it was almost certainly compromised or spoofed rather than operator-registered. Its name is withheld here for that reason:
From: "Liz Buys Houses" <[name]@[unrelated compromised business domain]>
Subject: [recipient username], You Received A Cash Offer For Your Home
Technical Analysis
The infrastructure makes this operation easier to read than its one-domain-a-day churn suggests. It uses two rails, two registrar cohorts, a machine-generated naming scheme, and an observable move toward personalization.
Two Rails, One Brand Layer
The display-name brand strings and identical lure copy connect the two rails, not shared sending infrastructure. Rail one's stable correlator is the Salesforce Marketing Cloud click-tracking host used as the call-to-action domain across otherwise unrelated .top burners. It is the one durable string connecting the disposable fleet. Rail two's correlator is the single persistent hub address, which carries the same cash-offer brands as a minority portion of a much broader multi-vertical rotation. A defender focused only on domains sees noise. A defender focused on the borrowed brand strings and tracking host sees one operation.
Domain-Generation Grammar
The .top names are not random. They come from a small dictionary recombined across three slots: a qualifier or intensifier, a theme or vertical token, and a structural suffix.
| Slot | Role | Tokens observed |
|---|---|---|
| Prefix | qualifier / intensifier | prime, super, ultra, pure, mega, epic, top, smart, fast, all, just, try, go, get, zen, real, the, my, you, pro, buy |
| Middle | theme / vertical | direct, brand, core, official, hero, high, plus, boost, funne, regis, auto, cover, secure, growth, expansion, global, checkout, segue, ister, imary, automatic, hq |
| Suffix | structure | hub, lab, grid, flow, zone, box, star, view, world, line, set, spot, dash, dock, base, online, ai, app, ify, planet, cube, tech |
Shared middle tokens reveal the generator recombining the same dictionary. The "direct" family alone produced prodirectspot[.]top, primedirecthub[.]top, primedirectlab[.]top, thedirectlab[.]top, and smartdirectstar[.]top; the "official" family produced ultraofficialgrid[.]top, goofficialcore[.]top, fastofficialset[.]top, and zenofficialview[.]top. In a later wave, the vocabulary starts to run dry: middles degrade into near-nonsense tokens (getseguebase[.]top, allsegueline[.]top, prosegueify[.]top, getistergrid[.]top, zenregisgrid[.]top, ultraimary[.]top). The local-part slot changed according to the same logic. It began as an info@ monoculture in the May wave, then diversified into role words (outreach@, ledger@, support@, reach@, specialist@, strategy@, update@) as the operator spread its fingerprint more thinly.
Registration Cohorts
Registration data separates the fleet cleanly, and the timing provides the signal. Every apex examined had a resolvable creation record, and the fresh .top domains were registered in tight batches days before sending.
| Cohort | Registrar | Creation window | Registrant org | Mail / SPF signal | Role |
|---|---|---|---|---|---|
.top burn fleet |
Dynadot | 2026-05-19 to 2026-06-05 | null / redacted | none persistent (sent via marketing cloud) | Rail-one disposable senders |
.top siblings |
Namecheap | 2026-03-25 to 2026-04-02 | null / redacted | spf.efwd.registrar-servers[.]com (registrar email forwarding) |
Earlier auto and insurance themed batch |
| Affiliate hub | GoDaddy | 2023-09-28 (aged) | null | Zoho mail, DMARC policy reject | Rail-two persistent asset |
The largest cohort is on one registrar, with creation dates clustered within a three-week window. Each domain uses the minimum one-year term, has a redacted or empty registrant, and shows a register-to-first-send gap of one to five days. This is purpose-built, register-send-discard infrastructure: minted in batches, used once, and never intended for renewal. A smaller, earlier batch on a second registrar has an auto and insurance theme and a different email-forwarding signal, identifying it as an earlier or parallel experiment. The hub has the opposite profile: an aged domain on a mainstream registrar with hosted mail and its own reject-policy DMARC record. It is the kind of durable asset an operator protects instead of burning.
Drift Toward Personalization
The operation's most recent change moves away from generic homeowner blasting. A username-personalized variant placed the recipient's own account name in the subject and was markedly more aggressive and targeted than the generic homeowner blasts that account for the rest of the traffic. At the same time, the display name shifted from borrowed real-estate brands to first-name personas ("Anika | Easy Cash Offers", "Olivia | Easy Cash Offers"). Sending also moved from fresh .top domains to aged, real-looking domains that resolve to unrelated real businesses, consistent with compromised or spoofed accounts rather than operator registrations. The operation is moving toward per-recipient targeting on infrastructure that appears less disposable.
Detection Observations
The two rails create opposite recognition problems. The burner fleet has a strong structural signal, but it arrives too late to be useful when relying on the domain alone: by the time a one-day-old .top domain is reported and listed, the operator has already retired it. The combination that remains constant across domains survives the churn: a borrowed cash-buyer brand in the display name on an unrelated compound-word .top sending domain, with the call-to-action routed through a marketing-cloud click-tracking host. That three-part combination is much more stable than any single indicator.
The persistent hub is harder to recognize from content features alone because each message resembles a mildly spammy marketing newsletter, while the scam becomes apparent at the ecosystem level rather than in any single send. Its lasting signal is one sender address carrying an implausibly broad rotation of unrelated consumer brands across verticals. Newly registered domain age is a strong prior for the burner rail because a one-domain-a-day cadence ensures that the sending domain is at most days old. Message content is the strongest cross-rail pivot: the seller-urgency subject lines and borrowed brand strings remain while everything around them rotates.
Indicators of Compromise
The indicators below are a representative, defanged subset from the confirmed operator infrastructure. The disposable .top domains are excluded because they are single-use and retired. The lasting indicators are the persistent hub sender and the burners whose click-through reached a blocklisted destination.
Senders
| Value | Role | Notes |
|---|---|---|
info@mail.yourhelpfulresources[.]com |
Persistent hub sender | Aged Zoho-hosted mailer, more than 47 rotating multi-vertical display names |
info@superhqline[.]top |
Burner sender | One-shot .top, click destination on public blocklists |
info@epicglobaldash[.]top |
Burner sender | One-shot .top, click destination on public blocklists |
info@topcoreflow[.]top |
Burner sender | One-shot .top, click destination on public blocklists |
MITRE Fight Fraud Framework Mapping
The mapping below aligns to the MITRE Fight Fraud Framework (F3) v1.1, https://ctid.mitre.org/fraud. F3 organizes fraud tradecraft into eight tactics: Reconnaissance, Resource Development, Initial Access, Stealth, Defense Impairment, Positioning, Execution, and Monetization. F3 centers on financial-account fraud, so a lead-gen operation of this shape maps only partially, and rows below are stated as observed behavior rather than forced onto named techniques. Where a behavior is better served by an enterprise ATT&CK technique, the row cites it as an ATT&CK cross-reference.
| Tactic | Observed behavior | Reference |
|---|---|---|
| Resource Development | Acquire infrastructure: register throwaway .top domains and onboard marketing-cloud sending accounts |
ATT&CK T1583.001 (Domains), T1585 / T1586 (Accounts) |
| Initial Access | Deliver unsolicited cash-offer spam to homeowner inboxes | F3 Initial Access (TA0001) |
| Stealth | Borrow real brand display names; route clicks through a trusted marketing-cloud host; pass SPF, DKIM, and DMARC on fresh burners | F3 Stealth (TA0005) |
| Positioning | Seller-urgency pretext to pull the homeowner into a lead form or reply | F3 Positioning (FA0001) |
| Positioning | Capture homeowner contact and property details | Gather Customer Information (F1029) |
| Monetization | Resell harvested homeowner leads into cash-buyer pipelines | F3 Monetization (FA0002); no discrete F3 technique for lead resale |
Conclusion
The operator treats its domains as disposable, minting and discarding one a day. The reusable machinery persists: a borrowed-brand display-name layer, a legitimate marketing platform onboarded through a throwaway sub-account, and a machine that recombines a small dictionary into an endless supply of sending names. The recent move toward per-recipient subjects and aged, real-looking sending domains is worth watching because it exchanges the burner rail's inexpensive disposability for messages that are harder to dismiss on sight. Defenders should focus on the constants, the brand strings and click-tracking host, rather than the domains carrying them.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.