One Mailbox, 178 Brand Costumes: Anatomy of a Consumer-Data Lead Broker
One Mailbox, 178 Brand Costumes: Anatomy of a Consumer-Data Lead Broker
Between January and June 2026, a single email operator sent US consumers offers under 178 different sender names, 118 of them belonging to real companies. Globe Life, Aflac, Liberty Mutual, Colonial Penn, Quicken Loans, PREMIER Bankcard, CarShield, ADT, Jacuzzi, AARP. None of those companies sent the mail. The envelope never changed: four generically-named domains the operator had registered itself, sending thousands of messages across seven unrelated verticals. What changed was the costume. And behind every "Get your free quote" button sat a redirect that appended the recipient's full name, street address, city, state, ZIP, email address and IP to the outbound URL before handing them to whichever affiliate was buying that day.
Key Takeaways
- Display-name impersonation needs no spoofing. The operator owned its sending domains, so SPF, DKIM and DMARC passed genuinely on every message. Authentication tells you a sender configured DNS correctly, not that the sender is who the inbox says it is.
- The product being sold is a pre-filled consumer lead. Recipient identity travels in the click URL as query parameters, so the buyer receives a fully populated record rather than a form the consumer filled in.
- Four sending domains were bound into one estate by two independently co-varying signals: a 21-character account-scoped click-tracker token prefix, and a uniform
help@sender localpart. Registration data did not bind them at all. - The tracker is a commercial white-label product consumed via per-tenant CNAME, not operator-built infrastructure. The subdomain prefix alone is meaningless as an indicator, because legitimate newsletters and credit unions use identically-named hosts.
- A structurally identical second operator runs the same tradecraft on different token prefixes and a
support@convention. Shared brand personas and a shared tracking vendor do not establish common ownership, and treating them as attribution merges unrelated actors. - The postal address in the CAN-SPAM footer is not a legitimacy signal. One of the three addresses in rotation is a mailbox rental inside a pack-and-ship storefront. Another is the genuine corporate headquarters of a lender whose name the operator also wore in the From line.
Background
Consumer lead generation is a large legitimate industry. A consumer fills in a quote form for auto insurance, a Medicare plan, or a personal loan, and that contact record is sold or auctioned to carriers, agents, lenders, or call centers who then reach out directly. Because leads are paid per contact or per sale, the incentive runs toward maximizing form-fills, and regulators have repeatedly found that incentive producing misleading marketing and broad resale of sensitive data.
The scale is not small. In August 2025 the Federal Trade Commission settled with Assurance IQ and MediaAlpha/QuoteLab for a combined $145 million over deceptive health-insurance lead-generation sites that funneled consumer data into telemarketing pipelines; the complaint described roughly 119 million consumer leads sold in a single year. A 2026 measurement study by Vekaria, Demir, Kollnig and Shafiq, presented at IEEE Symposium on Security and Privacy and hosted by the FTC, instrumented more than 100 health-insurance lead-generation sites and found consumer data shared with over 70 distinct third parties per site on average.
The operation described here sits at the front of that pipeline, and inverts its usual shape. Rather than building a quote site and waiting for consumers to arrive, it starts from a purchased list that already contains name, postal address and email, then uses brand impersonation to manufacture the click that converts a list entry into a billable lead. The consumer never fills in a form. They have already been filled in.
Several pieces of infrastructure recur below and are worth defining first.
Amazon SES is AWS's bulk-sending service; return-path addresses on SES-relayed mail resolve to amazonses.com. It is cheap, scales high, and lets a customer verify their own sending domain, which makes it a common outbound relay for large commercial mail streams of every kind.
Per-tenant click-tracking CNAMEs are standard marketing-automation practice. During onboarding, an email service provider has each customer point a subdomain such as links.<customer-domain> or trck.<customer-domain> at the provider's tracking infrastructure, so click and open tracking appear to originate from the customer's own domain. It improves deliverability and branding. It also means any operator can route every click through a hostname it controls before forwarding the visitor onward.
ImprovMX is a free email-forwarding service that lets a domain owner receive mail without running a mail server. It shows up in SPF records for domains that need a working reply or abuse address cheaply.
A DMARC rua address is the mailbox that receives daily aggregate authentication reports for a domain. Operators often reuse one reporting mailbox across everything they run, which makes the rua value a quiet ownership fingerprint capable of linking domains that otherwise look unrelated.
Discovery and Infrastructure
The estate presents as four sending domains, each with a single help@ mailbox. Every message passed SPF, DKIM and DMARC.
| Domain | Role | Sending mailbox | Distinct display names |
|---|---|---|---|
familyinsuranceguys[.]com |
Primary sender | help@familyinsuranceguys[.]com |
178 |
generalshomeservice[.]com |
Sender | help@generalshomeservice[.]com |
46 |
creditgiver[.]com |
Sender | help@creditgiver[.]com |
1 |
insurancequants[.]com |
Sender | help@insurancequants[.]com |
1 |
Each apex carries the same subdomain grammar, with roles cleanly separated.
| Host pattern | Role |
|---|---|
trck.<apex> |
Click redirector; the hop where the recipient PII payload is assembled |
links.<apex> |
ESP click wrapper (/s/c/ click, /s/u/ unsubscribe, /s/eo/ open) |
trp.<apex> |
Open-tracking pixel (/v1/image.png) |
assets.<apex> |
Creative and image hosting |
track.<apex> |
Legacy parallel tracker, plain HTTP |
The interesting part is what does not bind the estate. The four domains were registered across three different registrars, with creation dates spanning 2015 to 2023. There is no registration batch, no shared registrant organization, no common nameserver story. Two of the four publish a WHOIS organization that simply echoes the domain's own words, "general home" and "credit giver", which is a tell about care taken rather than a link between them. SPF include sets diverge domain by domain, and the one include common to all four, _spf.sparkpostmail.com, is also present on unrelated senders, including the separate operator discussed below. Registration and authentication data, in other words, would have kept these four apart.
Two signals bound them, and they co-vary exactly. The first is a 21-character token that prefixes every click-tracker path, xukR5lAVjXT8y4TANKZW7. The second is the help@ localpart, uniform across all four. Where one appears, so does the other.
| Sender | Token prefix | Account | Traffic-source key |
|---|---|---|---|
help@familyinsuranceguys[.]com |
xukR5lAVjXT8y4TANKZW7 |
601553 | DAWLAAI, DBSKRTRIVTT |
help@generalshomeservice[.]com |
xukR5lAVjXT8y4TANKZW7 |
601553 | DAISAD |
help@creditgiver[.]com |
xukR5lAVjXT8y4TANKZW7 |
not recovered | not recovered |
help@insurancequants[.]com |
xukR5lAVjXT8y4TANKZW7 |
601558 | not recovered |
Two of the four share an ESP account identifier outright. The confidence tiers follow the evidence rather than the convenience: generalshomeservice[.]com is a firm attribution on four agreeing signals, creditgiver[.]com and insurancequants[.]com rest on the token-and-localpart pair alone, and insurancequants[.]com carries a different account number, which argues against it as much as the token argues for it.
How It Works
A message arrives from a name the recipient recognizes. The From display reads Globe Life - Notice or Avant Card Info or Jacuzzi Bath Remodel Info. The envelope address underneath is help@ one of four generic domains, and the reply-to matches it. Nothing is spoofed, so nothing fails authentication.
The subject frequently opens with the recipient's own first name, and the body goes further: home city, home equity framing, Medicare eligibility, and in the auto vertical the specific make and model of the vehicle the recipient owns. Some creatives print an explicit provenance block, a labelled Intended for: line echoing the recipient's own name and email address back at them, which is list-broker plumbing surfacing through the template.
The call to action points at links.<apex>/s/c/<token>, the ESP click wrapper. That is where the visible link ends. One hop downstream, the trck. redirector assembles the payload that makes the whole operation pay:
hxxps://trck.<apex>/xukR5lAVjXT8y4TANKZW7<token>/sent-<YYYY-MM-DD>_acct-<NNNNNN>
_cmpid-<id>_seg-_srcid-<key>_secsrcid-<key>/<md5-shaped-hash>/LT<NNN>
?ipaddress=[redacted]&streetaddress=[redacted]&city=[redacted]&state=[redacted]
&zipcode=[redacted]&firstname=[redacted]&lastname=[redacted]
&emailaddress=[redacted]&srcid=<key>&hcmp=<offer>
The consumer clicks a button that says "Compare Coverage and Pricing". What travels to the buyer is a complete identity record: full name, street address, city, state, ZIP, email address, and the IP the click came from. The hcmp parameter selects which offer, and therefore which buyer, receives it.
Because the PII is assembled at the redirect rather than written into the message, it is not visible in the delivered email. A defender inspecting the message body sees an ordinary ESP tracking link.
Sample Lures
All recipient identifiers below are redacted. Bracketed placeholders mark where personal data appeared in the original messages.
Subprime credit card, impersonating a real lender in the display name:
From: "Avant Card Info" <help@familyinsuranceguys[.]com>
Subject: Difference between due date and close date - Check out this card
Avant Explains three core credit habits
Credit card due date vs. statement closing date
If these two dates blur together, here's what each one means, and a simple
routine that can help your balance look more manageable.
- Statement close: Billing cycle ends; statement balance is set
- Due date: The minimum payment is due
Auto insurance, personalized with the recipient's own vehicle:
From: "Blue Sky Auto Offer" <help@familyinsuranceguys[.]com>
Subject: Looking for affordable auto insurance options for your [vehicle model]?
Compare and save
Affordable Car Insurance Providers in [city] for your [vehicle model]
Compare Coverage and Pricing >> hxxps://links.familyinsuranceguys[.]com/s/c/[token]
Senior health screening, borrowing a real medical charity's statistics as credibility filler:
From: "Life Line Screening | Partner" <help@familyinsuranceguys[.]com>
Subject: 80% of Strokes Can Be Prevented (American Heart Association)
LIFE LINE SCREENING
Find a location near you. Call Now: [phone]
Plaque build-up in your arteries can go unnoticed for years...
Home remodel, showing the in-body provenance block:
From: "Jacuzzi Bath Remodel Info" <help@generalshomeservice[.]com>
Subject: [recipient name], Upgrade your bathroom and possibly increase your home's value
Jacuzzi Bath Remodel - Get a free quote
Reimagine Your Bathroom with a Custom Bath Remodel
Intended for:
Name: [recipient name]
Email: [recipient email]
Your free estimate: Click here to view
List validation, the one variant that asks the recipient to confirm rather than convert:
From: "ISQ Auto" <help@creditgiver[.]com>
Subject: Please confirm: your auto quotes are ready
Insurance Savings Quiz
This message was sent to you per your inquiry for auto insurance quotes.
You requested auto insurance quotes with us. Please confirm this message
reached you so we can connect your request to your prepared results.
That last one is worth pausing on. No offer, no brand. Its only function is to get a click that proves the address is live and attended, which raises the value of that record before anything is sold against it.
Technical Analysis
The Costume Rack
The display-name roster is not a handful of brands recycled. Across the estate it runs to 178 distinct strings, of which 118 name an identifiable real company and 60 are generic descriptors such as "Credit Card Offer" or "Walk In Baths Offer". They spread across seven verticals with no relationship between the sending identity and what is being sold on any given day.
| Vertical | Example display-name strings |
|---|---|
| Life and supplemental insurance | Globe Life - Notice, Colonial Penn Life Insurance Plans, Aflac Insurance, Liberty Mutual Team |
| Auto insurance and vehicle warranty | Blue Sky Auto Offer, CarShield Message., Ultra Auto Warranty Center, Auto Insurance Savings Quiz |
| Home services and warranty | Jacuzzi Bath Remodel Info, ServicePlus Online., RenewalbyAndersen, ADT Security Services, Vivint SmartHome Security |
| Debt and credit products | National Debt Relief, Freedom Debt Relief Team, Fortiva Mastercard, PREMIER Bankcard Offer |
| Mortgage and home equity | Amerisave Mortgage Rates, Quicken Loans., New American Funding, Reverse Mortgage Eligibility |
| Medicare and senior | Medicare Comparison Shop Guide, AARP Offer, Life Line Screening Info |
| Lifestyle affiliate | WarbyParker Offer, Sam's Club Affiliate Offer, USCCA - Concealed Carry, Consumer Cellular Offers |
The strings recur across sending domains verbatim, punctuation artifacts and all. ServicePlus Online. carries its trailing period on both familyinsuranceguys[.]com and generalshomeservice[.]com. RenewalbyAndersen is unspaced on both. Liberty_Mutual keeps its underscore on both. Duplication down to a stray period is not two teams independently writing similar copy; it is one template store feeding two sending identities.
Tracker Path Anatomy
The redirector path is highly structured, and every segment carries meaning.
| Segment | Example | Meaning |
|---|---|---|
| 21-char token | xukR5lAVjXT8y4TANKZW7 |
Account-scoped tracker token; the durable cross-domain correlator |
sent-<date> |
sent-2026-06-12 |
Send date |
acct-<id> / af-<id> |
acct-601553, af-601558 |
ESP tenant account identifier |
cmpid-<id> |
cmpid-18541143 |
Campaign identifier |
seg- |
(empty in observed traffic) | Segment slot, unpopulated |
srcid- / secsrcid- |
srcid-DAWLAAI |
Traffic-source key, also repeated as a query parameter |
| md5-shaped hash | opaque hex | Per-message value |
LT<NNN> |
LT773, LT1536, LT1554, LT1630 |
Offer or creative template identifier |
| query string | ?firstname=...&zipcode=... |
Recipient PII payload |
Observed hcmp offer-routing values mix small integers with longer codes, including 40, 09, p06, 6537, 7680 and 9057, which points to per-creative offer buckets rather than one code per vertical.
The Tracker Is Rented, Not Built
It would be easy to read trck.<operator-domain> as bespoke infrastructure. It is not. The path grammar above belongs to a commercial white-label click-tracking and lead-routing product, consumed through the same per-tenant CNAME that any marketing team uses, and the account identifiers observed here cluster tightly in a sequential range shared with unrelated tenants.
This matters for anyone tempted to key on the hostname. Hosts named trck. are used by mainstream technology newsletters, at least two US credit unions, a Portuguese news outlet and an Indonesian asset manager, none of which have anything to do with this operation. Their paths look nothing alike, and they carry no account grammar at all. The discriminating artifact is the 21-character account-scoped token, not the subdomain label.
The practical consequence is that "self-hosted tracker" is the wrong mental model. The operator configured a product; it did not write one. Whether appending consumer PII to the outbound URL is a product default or a per-tenant setting is an open question, and the answer determines whether this is one operator's data-handling choice or a much broader industry pattern.
Registration Tells You Nothing Here
| Domain | Registrar | Created | WHOIS organization |
|---|---|---|---|
familyinsuranceguys[.]com |
GoDaddy | 2017-10-02 | redacted |
generalshomeservice[.]com |
Namecheap | 2023-01-06 | "general home" |
creditgiver[.]com |
Name.com | 2022-11-30 | "credit giver" |
insurancequants[.]com |
Wild West Domains | 2015-06-16 | redacted |
Three registrars, eight years of spread, no shared organization. Analysts accustomed to registration-batch clustering as the primary estate-building pivot would have found nothing here. The domains are individually aged rather than bulk-provisioned, and two were plausibly acquired rather than registered fresh. An estate can be real and leave no registration fingerprint at all.
Authentication Posture
All four domains authenticate cleanly, which is the point. Three publish a tight p=reject; pct=100 DMARC policy with a self-referencing rua, which is stricter than a great many legitimate senders manage. Only the primary apex runs a loose p=none; pct=0 policy pointing its aggregate reports at an off-domain mailbox, and that off-domain rua is the thread that ties the sending infrastructure to a corporate identity operating a credit-services brand.
A defender reading DMARC posture as a trust signal would rank three of these four domains above much of their legitimate inbox. Strict alignment costs nothing when you own the domain and nobody is trying to spoof you.
A Second Operator, Deliberately Not Merged
Three further domains run what looks like the same operation: same host taxonomy, same PII-in-redirect pattern, same underlying tracking product, and a persona pool that overlaps heavily. They are a different operator, and the evidence for that is as concrete as the evidence binding the estate. Their token prefixes are entirely disjoint, their sender localpart convention is support@ rather than help@, their registration cohort shares nothing, and no account identifier or traffic-source key from the estate appears anywhere in their traffic.
Brand personas converge across this whole ecosystem by base rate, because everyone is impersonating the same well-known consumer brands. Merging on shared creative would have produced one imaginary mega-operator out of two real ones. Attribution here has to rest on artifacts the operator configures, not artifacts the market supplies.
The Footer Addresses
Three physical postal addresses rotate through the CAN-SPAM footers. One resolves to a retail pack-and-ship storefront, where the "Ste 350 - 545" double designator is the store's own suite followed by a rented mailbox number. Another is the genuine corporate headquarters of a consumer lender, a company whose name the operator simultaneously wore in the From line of other messages in the same estate.
The second case is the more instructive. A footer address that resolves to a real, occupied office is not evidence the sender is that business. It can be evidence of the opposite.
CAN-SPAM requires that commercial email not carry false or misleading header information (15 U.S.C. 7704(a)(1)) and that it include a valid physical postal address for the sender (15 U.S.C. 7704(a)(5)). Those are the requirements the statute sets out; whether any particular message meets them is a question for a regulator, not a research post.
Detection Observations
The behavioral signals that separate this traffic from legitimate commercial mail are structural rather than reputational, which is what makes them durable.
- A labelled provenance block echoing the recipient's own address back at them is a strong signal on its own. Legitimate transactional mail addresses the recipient; it does not print them a receipt proving it holds their record. Pairing the labelled block with a check that the echoed address matches the actual envelope recipient makes the signal self-verifying and brand-independent.
- A call to action on a subdomain of the sending domain carries no independent reputational information. The operator is vouching for the operator. On an apex with no established history that is an absence of evidence rather than reassurance, and it is worth treating differently from a CTA that points somewhere the sender does not control.
- One mailbox rotating brand display names across unrelated verticals is visible at the account level and invisible per message. Any single message reads as ordinary marketing. The count of distinct display names alone is not usable as a signal, because legitimate notification senders routinely exceed 400 distinct display strings; the discriminator is that the names belong to unrelated real companies that do not own the sending domain.
- Consumer PII in a click URL is worth surfacing as a hunting pivot, but not as a rule. Prefilling name and postal fields into a link is a mainstream marketing convenience used by political campaigns, survey platforms and retailers. In this operation the parameters are assembled a hop downstream of the delivered link, so they are absent from the message body entirely.
- The account-scoped tracker token is the highest-precision pivot available against this operator class. It survives domain rotation, it survives persona rotation, and it partitions tenants of a shared product cleanly.
Indicators of Compromise
All indicators are defanged. Recipient data has been removed.
Senders
| Value | Role | Notes |
|---|---|---|
help@familyinsuranceguys[.]com |
Sender | Primary; 178 display-name strings |
help@generalshomeservice[.]com |
Sender | 46 display-name strings; shares account 601553. Firm attribution, four agreeing signals |
help@creditgiver[.]com |
Sender | List-validation variant. Token and localpart only; account not recovered at this volume |
help@insurancequants[.]com |
Sender | Account 601558, which differs from the estate. Token and localpart only |
Domains
| Value | Role | Notes |
|---|---|---|
familyinsuranceguys[.]com |
Sending domain | GoDaddy, 2017-10-02 |
generalshomeservice[.]com |
Sending domain | Namecheap, 2023-01-06 |
creditgiver[.]com |
Sending domain | Name.com, 2022-11-30. Token and localpart correlation only |
insurancequants[.]com |
Sending domain | Wild West Domains, 2015-06-16. Token and localpart correlation only; account differs |
Hosts
| Value | Role | Notes |
|---|---|---|
trck.familyinsuranceguys[.]com |
Click redirector | PII assembly hop |
trck.generalshomeservice[.]com |
Click redirector | PII assembly hop |
trck.creditgiver[.]com |
Click redirector | PII assembly hop |
trck.insurancequants[.]com |
Click redirector | PII assembly hop |
links.familyinsuranceguys[.]com |
ESP click wrapper | /s/c/, /s/u/, /s/eo/ |
trp.familyinsuranceguys[.]com |
Open-tracking pixel | /v1/image.png |
assets.familyinsuranceguys[.]com |
Creative hosting | Now behind a bot challenge |
assets.generalshomeservice[.]com |
Creative hosting | Mirrors the primary asset host |
track.familyinsuranceguys[.]com |
Legacy tracker | Plain HTTP |
Message Patterns
| Pattern | Notes |
|---|---|
xukR5lAVjXT8y4TANKZW7 |
21-char account-scoped tracker token prefix; the durable correlator |
acct-601553, af-601558 |
ESP tenant account identifiers |
srcid-DAWLAAI, srcid-DAISAD, srcid-DBSKRTRIVTT |
Traffic-source keys |
Intended for: Name: / Email: |
In-body recipient provenance block |
ServicePlus Online., RenewalbyAndersen, Liberty_Mutual |
Display-name strings reused verbatim across domains |
MITRE Fight Fraud Framework Mapping
Mapping aligns to the MITRE Fight Fraud Framework (F3) v1.1, https://ctid.mitre.org/fraud. F3 is scoped to post-access fraud behavior, so this pre-access lead-brokering operation maps only partially; unmapped stages are noted rather than forced.
| F3 Tactic | Technique | ID |
|---|---|---|
| Reconnaissance | Gather Customer Information | F1029 |
| Reconnaissance | Phishing for Information (the list-validation lure only, which solicits an engagement signal rather than routing an offer) | T1598 |
| Resource Development | Acquire Infrastructure: Domains | T1583.001 |
| Resource Development | Establish Accounts | T1585 |
| Resource Development | Create Fake Materials: Fake Website | F1020.002 |
| Initial Access | Impersonate Official | F1032 |
| Stealth | Impersonate Official | F1032 |
| Monetization | Sale of brokered consumer lead records to affiliate buyers; no discrete F3 technique covers lead brokering |
Conclusion
The durable lesson here is about what binds infrastructure together. Registration cohorts, WHOIS organizations and authentication posture, the pivots analysts reach for first, would each have kept these four domains apart, and the one thing common to all of them was a shared commercial ESP that proves nothing. What bound them was a token the operator configured once and forgot, and a mailbox naming habit. Operators rotate what they think is being watched. Watch what they configure and stop thinking about.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.