One Subdomain Per Message: A Warranty and Insurance Lead-Gen Network
One Subdomain Per Message: A Warranty and Insurance Lead-Gen Network
Since January 2026, a single email operator has run warranty and insurance lead-gen lures from a fresh random subdomain on every message. The brand names ride entirely in the From display line, CarShield one hour and Liberty Mutual the next, while the actual sending domain is an eight-character label that has never been seen before and will never be seen again. Behind that rotation sits a stable pool of more than twenty operator-controlled apexes, most of them bought aged on the secondary market to inherit a clean reputation. We tracked thousands of lure messages across roughly five months, all of them steering recipients toward a lead-capture funnel whose only product is the recipient's own contact and interest data.
Key Takeaways
- The operator mints a new
<localpart>@<8-char-label>.<apex>sender for every single message, so no sending identity accrues reputation before it is retired. - Brand impersonation lives only in the From display name. The envelope domain carries no brand token, which lets one apex pool impersonate at least sixteen consumer brands across warranty, insurance, membership, and benefits verticals.
- Every message passes SPF and DKIM on the operator's own domains, with DMARC published as
p=none. Authentication proves the mail came from the sender's domain; it says nothing about whether that domain is honest. - The apex pool splits into two cohorts: seven purpose-built domains registered in a December 2025 batch, and fourteen aged 2002 to 2015 domains re-provisioned in a single 2025 window, the classic secondary-market acquisition fingerprint.
- The click layer moved from path-style DigitalOcean Spaces buckets to an affiliate-redirect kit planted on compromised third-party websites, keeping the destination off any host the operator owns.
Background
Deceptive lead generation in the auto-warranty, home-warranty, and insurance verticals does not sell anything to the recipient. It harvests contact and interest data and resells those leads into a downstream chain of marketers, contract sellers, and call centers, the same economics that drive the auto-warranty robocall wave the FTC and FCC have warned consumers about for years. Impersonating a familiar seller such as CarShield or Endurance, or an insurer such as Liberty Mutual, raises open and response rates and lends the lure legitimacy. CarShield itself was an FTC enforcement subject, settling deceptive-advertising claims for roughly 10 million dollars in 2024; here it is an impersonated brand, not the operator. The regulatory pressure on this model is real: the FCC's TCPA one-to-one consent rule, adopted in December 2023, was written to close the lead-generator loophole by barring blanket "share with our marketing partners" consent daisy-chains, though an Eleventh Circuit ruling later complicated its status.
Two pieces of infrastructure in this campaign deserve a plain-English gloss. DigitalOcean Spaces is an S3-compatible object-storage service reachable over a trusted, well-known hostname with valid TLS by default. Attackers park landing content there because it is cheap, fast to rotate, and rides a reputable parent domain. The path-style bucket form, nyc3.digitaloceanspaces[.]com/<bucket>/, matters because every tenant's bucket shares the same regional hostname, so any reputation verdict keyed on the host either over-blocks all legitimate Spaces content or stays permissive. The malicious signal lives only in the per-bucket path, which coarse host-reputation systems do not evaluate. The aged-domain secondary market is the second piece: expired domains are drop-caught and resold through auction houses and fixed-price marketplaces, and lead-gen operators pay a premium for age because pre-existing history is treated as a trust head start by filtering systems.
Discovery and Infrastructure
The campaign surfaced as a subdomain-shape anomaly rather than a bad sender. Because each address is used exactly once, a sender blocklist has nothing durable to hold. What holds instead is the grammar: an eight-character alphanumeric label, one per message, sitting atop a small, stable set of apexes. Pivoting on that shape rather than on any single address collapsed a scatter of one-shot senders into one operator.
The apexes fall into two clean cohorts, confirmed by public WHOIS. The first is purpose-built: .com and .org domains registered on Namecheap in a December 2025 batch, with privacy-proxy or null registrant data and a last-updated date equal to their creation date. Those were born for this campaign. The second cohort is aged: creation dates spread across 2002 to 2015, but with re-registration dates that cluster tightly into a single 2025 window. Old age paired with a sudden recent ownership change is the drop-catch fingerprint of a bulk secondary-market purchase, not organic ownership. Three of the aged apexes, donjuanspice[.]com, binkdogphoto[.]com, and drannstrong[.]com, were all re-provisioned on the same day, 19 June 2025. Two aged apexes in the pool remain staged, with no observed sending yet.
| Apex | Registrar | Created | WHOIS Last-Updated | Cohort |
|---|---|---|---|---|
melbourne-radiology[.]org |
Namecheap | 2025-12-02 | 2025-12-07 | Purpose-built |
community-of-joy[.]org |
Namecheap | 2025-12-02 | 2025-12-07 | Purpose-built |
holgerkeller[.]com |
Namecheap | 2025-12-12 | 2025-12-12 | Purpose-built |
gothicbeachstudio[.]com |
Namecheap | 2025-12-12 | 2025-12-12 | Purpose-built |
fingerschiene[.]com |
Namecheap | 2025-12-18 | 2025-12-18 | Purpose-built |
jcpenny[.]org (typosquat) |
Namecheap | 2004-10-18 | 2025-10-30 | Aged (typosquat) |
caddishackcorp[.]com |
Namecheap | 2002-04-03 | 2025-04-05 | Aged acquisition |
angelasacristan[.]com |
Namecheap | 2003-05-09 | 2025-06-08 | Aged acquisition |
elcochecito[.]com (SPF hub) |
Namecheap | 2011-08-09 | 2025-10-27 | Aged acquisition |
donjuanspice[.]com |
Namecheap | 2014-10-30 | 2025-06-19 | Aged acquisition |
binkdogphoto[.]com |
Namecheap | 2014-12-26 | 2025-06-19 | Aged acquisition |
drannstrong[.]com |
Namecheap | 2015-01-05 | 2025-06-19 | Aged acquisition |
The aged names read as plausible defunct small businesses or personal sites: a photo studio, a spice brand, a radiology clinic, an event group. None of them has a live legitimate owner, and where an aged name resembles a real entity, the real entity lives on a different domain. axaseattle[.]com resembles an AXA advisory office, but the real Seattle office operates on a separate domain and the AXA US brand retired to Equitable in 2020. melbourne-radiology[.]org resembles a clinic that actually uses a .com.au address. The one apex with a genuine brand token is jcpenny[.]org, an aged JCPenney typosquat that JCPenney does not own.
How It Works
A recipient receives a message whose From line reads as a known brand and whose subject matches the vertical: a repair-coverage notice, a policy-comparison prompt, a membership or senior-benefit pitch. The sending address is a fresh eight-character subdomain that authenticates cleanly. Bodies frequently carry decoy transactional text spliced in for spam-trap evasion, recurring verbatim strings such as Premier League | Password Reset during the early window and university-admissions boilerplate later. The call to action pushes the recipient toward a lead-capture page.
The click layer evolved in two phases. Through mid-February 2026, payloads sat on path-style DigitalOcean Spaces buckets, riding a trusted cloud host where the malicious signal is confined to the bucket path. After that, the operator moved the click-through onto an affiliate-redirect kit installed on compromised third-party websites, reached through a distinctive /cl/<numeric-id>_md/ path. That shift traded clean-host abuse for compromised-site redirector chains, which are harder to take down and blend click-tracking into legitimate hosts the operator does not own.
Sample Lures
All sender domains below are operator-controlled and defanged. Recipient data has been removed; only attacker-side content remains. Compromised third-party redirector hosts are genericized because those sites are themselves victims.
Insurance policy-comparison lure (phase one, cloud-storage payload):
From: "Liberty Mutual" <hello@12icajep.elcochecito[.]com>
Subject: How does your current policy compare?
CTA: hxxps://nyc3.digitaloceanspaces[.]com/<bucket>/
Auto-warranty lure with spliced decoy body text (phase one):
From: "Endurance" <noreply@fmtmm32j.jcpenny[.]org>
Subject: Streamline Your Repair Process
Body: ...decoy line spliced mid-message: "Premier League | Password Reset"...
CTA: hxxps://nyc3.digitaloceanspaces[.]com/<bucket>/
Senior-membership lure (phase two, compromised-site redirector):
From: "AARP Invitation for You" <info@vclr6fq0.jcpenny[.]org>
Subject: AARP - Memorial Day Sale Membership
CTA: hxxp://<random-label>.<compromised-third-party-host>/cl/<numeric-id>_md/
Technical Analysis
The durable fingerprint here is not any address or apex. It is the sending grammar plus a set of shared DNS artifacts that tie every apex, across both cohorts, back to one hand.
Sender Grammar and Display-Name Rotation
Every sender takes the form <localpart>@<8-char-alnum-label>.<apex>, with a fresh label minted per message. This is a snowshoe technique carried to its logical end. Snowshoe spamming spreads volume thinly so no single sender trips a rate or reputation threshold; a new subdomain per message denies IP, domain, and historical-sender reputation systems any accumulated signal at send time. The brand identity is decoupled from the domain entirely and lives in the display name, which is why one apex pool can present as CarShield, Endurance, Liberty Mutual, Fidelity Life, Provide Insurance, Sam's Club, AARP, and roughly a dozen more, with heavy punctuation variants (Provide.Insurance, Provide-Insurance) to dodge exact-string matching.
Self-Issued Authentication
Every message passes SPF and DKIM, and the apexes publish DMARC at p=none. Because the operator owns the sending domains and their DNS, it can publish fully valid records and reach alignment. Authentication verifies that mail came from the sender's domain; it does not verify that the domain is honest. A p=none policy is a deliberate choice here: report-only enforcement means nothing bounces while the mail still authenticates.
Cross-Apex Linkage
Four independent signals prove a single operator spans both cohorts.
| Linkage signal | What it shows |
|---|---|
| Reused 8-char labels | The same subdomain label (for example acnf91ln) appears on more than one apex, pointing to one minting engine. |
| Shared DMARC rua mailboxes | Two reporting mailboxes on mxtoolbox.dmarc-report[.]com, 7d6a0925@ and ab666928@, each collect reports for a set of apexes that spans both the aged and purpose-built cohorts. |
| Shared SPF includes | Recurring include tokens (gaiachain[.]co, ukrainadnes[.]com) group otherwise-unrelated apexes; one pool apex, elcochecito[.]com, is itself used as a shared SPF hub included by four others. |
| Batch WHOIS timestamps | The 19 June 2025 re-provision of three aged apexes on the same day, inside a wider June 2025 window, ties the acquisitions to one provisioning event. |
The elcochecito[.]com SPF hub is the strongest single tie: a domain that both sends lures and anchors other apexes' SPF is self-referential cross-linking that a coincidental convention would not produce.
Two-Phase Click Architecture
The phase-one path-style bucket and the phase-two /cl/<id>_md/ redirector share a design goal: keep the destination off any host the operator can be blocklisted on. The bucket rides a shared cloud hostname; the redirector rides hijacked legitimate sites. Both frustrate host-level reputation, which is why the durable correlators are the subdomain grammar, the redirector path token, and the shared DNS artifacts rather than any single host.
Detection Observations
The signal in this campaign is structural, not per-message. Any one message looks like a mildly pushy brand email that authenticates cleanly, so per-sender and per-domain reputation have nothing to bite on by design. What separates this traffic from legitimate brand mail is the combination of attributes rather than any single one.
- A brand name in the display line paired with an envelope domain that carries no brand token and has never sent before is a strong mismatch signal.
- An eight-character alphanumeric subdomain used exactly once, atop an apex that hosts a stream of such one-shot subdomains, is a shape legitimate senders do not produce.
- Passing SPF and DKIM with DMARC at
p=noneon a domain with no sending history is authentication without reputation, which is the opposite of a trust signal in this context. - Shared DMARC reporting mailboxes and shared SPF includes across otherwise-unrelated apexes are a durable cross-apex pivot that survives address and subdomain rotation.
- The
/cl/<numeric-id>_md/redirector path is a stable string that persists even as the compromised host underneath it changes.
Indicators of Compromise
All indicators are defanged. Recipient data has been removed. The sender list is a representative subset; each apex mints a fresh one-shot subdomain per message, so the full sender inventory is unbounded.
Sender Addresses (representative subset)
| Value | Impersonated Brand | Notes |
|---|---|---|
carshield@3gewgzfs.jcpenny[.]org |
CarShield | One-shot sender, typosquat apex |
carshield.partner@racbn69e.holgerkeller[.]com |
CarShield | Purpose-built apex |
liberty_mutual@05icajhz.elcochecito[.]com |
Liberty Mutual | Aged-acquisition apex |
liberty_mutual@lvv7duit.jcpenny[.]org |
Liberty Mutual | Typosquat apex |
hello@12icajep.elcochecito[.]com |
Liberty Mutual | Phase-one cloud-storage lure |
fidelitylifecoverage@zyvu8u78.fingerschiene[.]com |
Fidelity Life | Purpose-built apex |
provide.insurance@lzcp5txi.community-of-joy[.]org |
Provide Insurance | Purpose-built apex |
biolife.plasma@kiziqjpn.donjuanspice[.]com |
BioLife Plasma | Opportunistic vertical |
info@bksa1rn3.angelasacristan[.]com |
Sam's Club | Membership lure |
noreply@fmtmm32j.jcpenny[.]org |
Endurance | Decoy-body lure |
info@xfxg2sif.gopibc[.]com |
CarShield | Phase-two redirector lure |
info@vclr6fq0.jcpenny[.]org |
AARP | Senior-membership lure |
coverage.alert@nv76rmo6.holgerkeller[.]com |
Insurance (generic) | Purpose-built apex |
service@vuvphn2g.elcochecito[.]com |
Warranty (generic) | Aged-acquisition apex |
no-reply@t3mhf62o.axaseattle[.]com |
Insurance (generic) | Aged-acquisition apex |
| ... (representative subset; 250+ verified-malicious sender addresses) |
Sending Domains (purpose-built, Dec 2025)
| Value | Role | Notes |
|---|---|---|
holgerkeller[.]com |
Sender apex | Purpose-built, Dec 2025 |
community-of-joy[.]org |
Sender apex | Purpose-built, Dec 2025 |
fingerschiene[.]com |
Sender apex | Purpose-built, Dec 2025 |
melbourne-radiology[.]org |
Sender apex | Purpose-built; real clinic uses a .com.au domain |
vivideventgroup[.]com |
Sender apex | Purpose-built, Dec 2025 |
gothicbeachstudio[.]com |
Sender apex | Purpose-built, Dec 2025 |
peaceofmindparenting[.]com |
Sender apex | Purpose-built, Dec 2025 |
Sending Domains (aged, operator-acquired)
| Value | Role | Notes |
|---|---|---|
jcpenny[.]org |
Sender apex | Aged 2004 JCPenney typosquat; JCPenney does not own it |
elcochecito[.]com |
Sender apex / SPF hub | Aged 2011; included by four other apexes |
caddishackcorp[.]com |
Sender apex | Aged 2002, re-provisioned 2025 |
angelasacristan[.]com |
Sender apex | Aged 2003, re-provisioned 2025 |
dsmartland[.]com |
Sender apex | Aged 2003, re-provisioned 2025 |
ezboosters[.]com |
Sender apex | Aged 2008, re-provisioned 2025 |
kridik[.]com |
Sender apex | Aged 2008, re-provisioned 2025 |
axaseattle[.]com |
Sender apex | Aged 2012; real AXA office on a separate domain |
gopibc[.]com |
Sender apex | Aged 2012, lone GoDaddy registrar |
donjuanspice[.]com |
Sender apex | Aged 2014, re-provisioned 19 Jun 2025 |
binkdogphoto[.]com |
Sender apex | Aged 2014, re-provisioned 19 Jun 2025 |
drannstrong[.]com |
Sender apex | Aged 2015, re-provisioned 19 Jun 2025 |
MITRE Fight Fraud Framework Mapping
The mappings below align to the MITRE Fight Fraud Framework (F3), https://ctid.mitre.org/fraud. F3 centers on financial-account fraud, so a consumer data-harvesting operation maps only partially; the honest matches are given with their F3 or ATT&CK-inherited technique IDs, and the absence of a discrete "lead resale" technique is noted rather than invented.
| Tactic | Observed behavior | ID |
|---|---|---|
| Reconnaissance | Phishing for Information | T1598 |
| Initial Access | Impersonate Official | F1032 |
| Resource Development | Acquire Infrastructure: Domains (aged secondary-market) | T1583.001 |
| Resource Development | Compromise Infrastructure: web services (redirector hosts) | T1584 |
| Reconnaissance | Gather Customer Information (email addresses) | F1029 |
| Monetization | Lead resale (no discrete F3 technique) |
Conclusion
This operator built for rotation from the ground up: a new sending identity per message, brand impersonation kept in the display name so the domain stays generic, and a click layer that always lives on infrastructure someone else owns. Address blocklists and sender reputation were never going to hold against it. What does hold is the plumbing the operator cannot rotate cheaply: the one-shot subdomain grammar, the shared DMARC reporting mailboxes and SPF hub that bind both domain cohorts, and the redirector path token that outlives the hosts beneath it. Defenders watching this space should key on that structure and treat authenticated mail from a no-history domain as unresolved, not trusted.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.