Back redsift.com Beyond Dmarc Guide Layered Defense Against Domain Impersonation
Ask any security professional where most cyberattacks start, and you’ll get the same answer: email. It remains the primary entry point for phishing and business email compromise (BEC), threats that rely on impersonation to manipulate human trust.
Most phishing attacks succeed because they look legitimate. Attackers impersonate trusted senders to deceive employees, customers, and partners into clicking malicious links, entering credentials, or wiring funds. When organizations implement DMARC (Domain-based Message Authentication, Reporting & Conformance) to stop exact-domain spoofing, attackers don’t abandon their efforts; they evolve.
Instead of forging a company’s domain, attackers register deceptive lookalike domains, exploit overlooked DNS misconfigurations, and use tactics designed to bypass traditional email security. These evolving attack methods make it clear that stopping exact-domain spoofing alone isn’t enough. Organizations need a multi-layered domain defense strategy to detect and mitigate all forms of domain-based threats before they escalate.
Most phishing attacks rely on one key element: a domain that looks real. Whether attackers are sending fraudulent emails or setting up fake websites, their goal is to mimic a trusted brand so that victims don’t question the legitimacy of their messages.
Attackers do this using two primary tactics:
Sometimes, these tactics aren’t used in isolation. Sophisticated attackers combine both methods, spoofing emails from a trusted domain while simultaneously using lookalike domains to bypass email security, redirect victims, and execute large-scale fraud. See a real-life example of this below.
In an exact-domain spoofing attack, a fraudster fakes an email header to make their message appear as if it’s coming from your real domain (e.g., @yourcompany.com ). To the recipient, the email looks legitimate even though it never actually originated from your infrastructure.
Most email clients only show the display name and sender address, not the underlying authentication details. This makes it easy for attackers to impersonate trusted senders – whether it’s an internal executive, a supplier, or a customer support address – when DMARC isn’t enforced.
In 2020, a sophisticated phishing campaign spoofed legitimate Microsoft domains to target Office 365 users. Attackers leveraged real Microsoft email addresses (e.g., @onmicrosoft.com) to send phishing emails that bypassed security checks.
Because Microsoft hadn’t fully enforced DMARC, these fraudulent emails were delivered to inboxes as if they were legitimate. The emails contained links to a convincing fake Office 365 login page, where victims unknowingly entered their credentials, granting attackers full access to their accounts.
This attack highlights the direct consequences of not enforcing DMARC at p=reject – attackers can send emails from a real domain, tricking recipients into handing over sensitive data.
The only way to block exact-domain spoofing is by enforcing DMARC (p=reject), ensuring that only authorized senders can use your domain.
But here’s the problem: while trusted domains are first to be spoofed, attackers don’t stop when DMARC is in place. Instead, they adapt their methods, which is where lookalike domains come into play.
Once DMARC prevents exact-domain spoofing, attackers pivot - registering fake versions of your domain that closely resemble the real thing. These lookalike domains don’t just enable phishing emails; they also power fraudulent websites, fake login pages, and scam operations that trick your customers and employees.
Attackers register domain names that are visually similar to yours, making it easy to deceive recipients at a glance. Here’s how they do it:
Typosquatting (misspelled domains)
yourcornpany.com instead of yourcompany.com
Homoglyph attacks (similar-looking characters)
yourcоmpany.com (using a Cyrillic “о” instead of “o”)
Subdomain impersonation
login.yourcompany.com instead of yourcompany.com
Brand abuse in new TLDs
yourcompany.support or yourcompany.help
In early 2024, a fraudulent lookalike domain attack targeted users of the DAT Freight & Analytics load board, a widely used platform in the trucking industry. Attackers created a domain that closely resembled the legitimate one, using it to impersonate logistics providers and steal shipments. The attack led to financial losses and significant operational disruptions for affected businesses.
While official financial losses were not disclosed, the DAT lookalike domain attack likely resulted in a six-figure loss for the affected shipment, consistent with other recent freight fraud cases . Estimates range from $50,000 to $200,000+ for a single load theft in these schemes
Impersonation attacks don’t always follow the same playbook. Some attackers register deceptive lookalike domains. Others spoof real ones. The tactics vary, but the goal is the same: to exploit trust in your brand.
Security teams need visibility across both their owned domain landscape and the broader ecosystem of malicious lookalikes. Without it, threats can slip through unnoticed — and lead to phishing, fraud, and reputational damage.
Cybercriminals are constantly evolving their tactics to bypass traditional defenses. When exact-domain spoofing is blocked by DMARC and lookalike domains are identified and neutralized, attackers still don’t stop their efforts to impersonate - instead, they shift to exploiting weaknesses in domain infrastructure.
DNS misconfigurations are one of the most overlooked attack surfaces in cybersecurity. Many organizations set up DNS records once and forget them, leaving behind abandoned, misconfigured, or poorly secured entries that attackers can exploit.
These attacks don’t rely on traditional spoofing. They abuse real, authorized domains, making them harder to detect and more convincing to victims.
A company forgets to remove a DNS record that points to an expired third-party service (e.g., AWS, Azure, Heroku).
Attackers claim control of the abandoned subdomain and send emails that bypass DMARC.
Mail Exchange (MX) records are misconfigured or left pointing to decommissioned mail servers.
Attackers reroute legitimate email traffic or use the forgotten server to send phishing emails.
Oversized SPF records
SPF (Sender Policy Framework) allows only 10 DNS lookups. Exceeding this limit causes SPF to fail, meaning email authentication no longer works.
Attackers exploit broken SPF policies to spoof emails that appear legitimate.
Dangling CNAME records
A CNAME (alias) record points to a domain that no longer exists or is no longer controlled by the company.
Attackers register the missing domain and take over the alias, potentially sending phishing emails.
In early 2024, researchers at Guardio Labs uncovered a massive phishing campaign, dubbed "SubdoMailing," that exploited over 8,000 hijacked subdomains from reputable brands such as MSN, VMware, McAfee, and eBay. Attackers leveraged these compromised subdomains to send millions of spam and malicious emails daily, effectively bypassing traditional email security measures.
This campaign exploited DNS misconfigurations, such as dangling CNAME records and mismanaged SPF entries, allowing attackers to:
This incident underscores a critical flaw in domain security - organizations often secure their primary domains but overlook DNS misconfigurations that leave them vulnerable to impersonation.
For an in-depth read on SubdoMailing attacks, check out our dedicated guide .
Attackers don’t rely on just one method to impersonate your brand - they pivot, adapt, and exploit whatever gaps they can find. DMARC enforcement stops exact-domain spoofing, DNS security hardens infrastructure, and brand monitoring detects external threats but these defenses can’t operate in isolation.
To illustrate why a layered approach is essential, let’s use a simple analogy. Think of your domain like a house: different security gaps represent different entry points that attackers can exploit. Locking the front door won’t help if the windows are open or the foundation is weak.
To fully protect against domain impersonation, organizations need a solution that enables multi-layered defense by providing:
No single control is enough to stop attackers who constantly shift tactics. That’s why Red Sift OnDMARC, DNS Guardian, and Brand Trust work together, providing the layered protection needed to secure your domain from every angle.
Securing a domain starts with DMARC enforcement, ensuring that only authorized senders can use the domain for email. Without it, attackers can send phishing emails that appear to come from a trusted source, tricking recipients into taking action.
Think of this as locking the front door of your house. If attackers can forge emails using a legitimate and trusted domain name, they don’t need to trick people with lookalikes - they can walk right in through an open door.
Red Sift OnDMARC is an automated DMARC application that helps organizations take back control of their email reputation and stop unauthorized use of their email-sending domains. By providing step-by-step implementation guidance, hosted email protocol management, as well as clear DMARC reports that provide insight into sending services and domain health, it helps global brands reach DMARC enforcement (p=reject) quickly and effectively.
With Red Sift OnDMARC, you can:
But locking the front door isn’t enough if attackers can crawl through an open window, which is exactly what happens when DNS misconfigurations are left unchecked.
Even with DMARC fully enforced, misconfigured or abandoned DNS records can leave an organization exposed. Attackers look for these weaknesses, using subdomain hijacking, SPF misconfigurations, and MX record abuse to bypass authentication checks.
This is like reinforcing the windows and fixing cracks in the foundation. Even if the front door is secure, an attacker will find another way in if there’s a weak spot elsewhere.
That’s why Red Sift OnDMARC has the industry’s only built-in DNS configuration monitoring that can identify and stop malicious mail that bypasses DMARC, including spam from domain takeovers and SubdoMailing.
DNS Guardian helps to:
Securing your domain and DNS infrastructure shuts down direct impersonation, but attackers don’t need access to your systems to exploit your brand. Instead, they create deceptive lookalike domains designed to mislead customers, partners, and employees.
If OnDMARC is the lock and DNS Guardian secures the foundation, Brand Trust is the neighborhood watch, identifying threats beyond your perimeter. Even when your domain is protected, attackers can still set up deceptive lookalike domains designed to mislead customers, partners, and employees.
Red Sift Brand Trust is an AI-driven solution designed to protect brands by identifying and monitoring lookalike domains that imitate legitimate assets. It leverages advanced algorithms and computer vision to detect unauthorized use of brand elements (such as logos, faces, keywords), enabling swift enforcement actions against such abuse.
Red Sift Brand Trust enables:
When used in tandem, Red Sift OnDMARC and Red Sift Brand Trust create a “full-spectrum” defense: emails purportedly from your genuine domains will not be delivered unless properly authenticated, and emails or links from lookalike domains are identified and can be blocked or removed. This dramatically reduces the attack surface for phishing. An attacker’s choices get whittled down to nothing very effective – they can’t spoof the real domain (DMARC blocks it), and if they try to use a fake domain, there’s a high chance Brand Trust has already flagged and initiated action against it.
Organizations relying on just one approach (for example, only a DMARC solution, or only a domain monitoring service) leave themselves exposed to the vector not covered. For instance, a company that only monitors for lookalike domains but hasn’t implemented DMARC could still be spoofed by a hacker simply sending emails from the company’s real domain. Conversely, a company with DMARC set up but no lookalike domain monitoring might fail to catch attackers deceiving users with near-identical domain names. That’s why the Red Sift philosophy – and increasingly the industry consensus – is that protocol-based security together with continuous detection and monitoring provides far stronger protection than either one alone.
Protecting your domain against impersonation attacks requires more than just one solution. OnDMARC, DNS Guardian, and Brand Trust provide a comprehensive, layered defense that eliminates attack surfaces before they can be exploited.
Request a demo today to see how Red Sift can help your organization stay ahead of evolving threats.
Exact-domain spoofing is when an attacker forges an email header to make a message appear as if it came from your real domain (e.g., @yourcompany.com). It exploits weak or missing DMARC policies and is blocked entirely by enforcing DMARC at p=reject. Lookalike domain attacks are different. Attackers register new domains that visually resemble yours, using tactics like typosquatting (yourcornpany.com), homoglyph characters (swapping a Latin "o" for a Cyrillic "о"), subdomain impersonation (login.yourcompany.com), or brand abuse through new TLDs (yourcompany.support). \
Because these are entirely separate domains, DMARC on your domain won't block them, and attackers can even authenticate their own lookalike domains with SPF, DKIM, and DMARC.
DMARC stops exact-domain spoofing, but attackers have two ways around it. First, they register lookalike domains that mimic your brand without using your actual domain, so your DMARC policy doesn't apply. Second, they exploit DNS misconfigurations in your own infrastructure, like abandoned subdomains, dangling CNAME records, or broken SPF records, to send phishing emails that actually pass SPF, DKIM, and DMARC checks on legitimate subdomains you control. The 2024
SubdoMailing campaign showed exactly how this works at scale: attackers hijacked over 8,000 subdomains from reputable brands and sent millions of malicious emails daily that bypassed traditional email security.
Four common DNS misconfigurations create attack surfaces. Subdomain hijacking happens when a DNS record still points to an expired third-party service (like AWS, Azure, or Heroku), and attackers claim control of that abandoned subdomain. MX record exposure occurs when mail exchange records point to decommissioned mail servers, letting attackers reroute legitimate email traffic or use the forgotten server to send phishing emails.
Oversized SPF records exceed the 10-DNS-lookup limit, causing SPF to fail entirely and leaving the domain open to spoofing. Dangling CNAME records point to domains that no longer exist, allowing attackers to register the missing domain and take over the alias. All four give attackers the ability to send emails or host content on what appears to be a legitimate subdomain.
SubdoMailing was a large-scale phishing campaign uncovered by Guardio Labs in early 2024. Attackers exploited DNS misconfigurations, specifically dangling CNAME records and mismanaged SPF entries, to hijack over 8,000 subdomains belonging to brands like MSN, VMware, McAfee, and eBay. They used these hijacked subdomains to send millions of spam and phishing emails daily that passed SPF, DKIM, and DMARC checks because they were sent from legitimate infrastructure. This campaign demonstrated that securing your primary domain with DMARC isn't enough if your broader DNS configuration has gaps that attackers can exploit.
Red Sift uses a three-layer approach. Red Sift OnDMARC handles email authentication, enforcing DMARC at p=reject so only authorized senders can use your domain.
DNS Guardian, built into OnDMARC, continuously monitors your DNS configuration for vulnerabilities like subdomain hijacking, dangling CNAMEs, poisoned SPF records, and domain takeovers, including SubdoMailing-style attacks.
Red Sift Brand Trust covers external threats by using AI-powered detection to identify newly registered lookalike domains, score their risk level based on factors like logo usage, executive face detection, keyword analysis, and page classification, and initiate rapid takedowns. Together, these three layers close off exact-domain spoofing, DNS infrastructure exploits, and lookalike domain abuse.
In 2020, attackers spoofed legitimate Microsoft domains to phish Office 365 users because DMARC wasn't fully enforced, resulting in credential theft at scale. In early 2024, a lookalike domain attack on DAT Freight & Analytics led to stolen shipments and significant financial losses. While official figures were not disclosed, comparable freight fraud cases have resulted in losses ranging from $50,000 to $200,000+ per stolen shipment.
And the SubdoMailing campaign in 2024 affected thousands of well-known brands whose hijacked subdomains were used to send millions of phishing emails. Each attack exploited a different gap: missing DMARC enforcement , no lookalike domain monitoring, and unmanaged DNS records. An organization relying on only one defense would have been vulnerable to at least two of these attack types.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
