4 min read By Excello Mail Team

LastPass and Bitwarden Users Are Being Phished by Domains DMARC Was Never Built to Stop

LastPass's threat intelligence team identified an active phishing campaign on July 13, 2026 using two lookalike domains and a fake DocuSign page to steal master passwords. Bitwarden users are being hit by similar lures. Because the attacker owns the sending domain outright, the mail authenticates perfectly and DMARC on lastpass.com never sees it.

On July 13, 2026, LastPass’s Threat Intelligence, Mitigation, and Escalation team flagged an active phishing campaign built around two freshly registered domains, lastpassnewsletter.com and lastpasscompliance.com. Neither belongs to LastPass in any way. The emails, sent from [email protected] with the subject line “Action Required: Review Updated LastPass Security Policies,” are formatted to look exactly like an official LastPass security notice. LastPass has confirmed its own systems were not touched. Bitwarden customers are seeing near-identical fake alert emails from a separate but similar campaign running in parallel, and reporting suggests the same playbook is being reused across more than one password manager brand.

The Attack Chain: A Fake Policy Notice Leads to a Fake DocuSign Page

The email tells recipients they need to review updated security policies and provides a link. Clicking through does not land on a crude, obviously-fake login form. It lands on lastpasscompliance.com, a page built to impersonate DocuSign, the electronic signature service millions of people use for legitimate document workflows every week. The page prompts the visitor to sign or download a document, and the real goal sitting behind that prompt is the visitor’s LastPass master password, the single credential that unlocks every other password in their vault. Microsoft Defender for Office 365 has since flagged the destination and blocks it through SafeLinks, and Cloudflare is now serving a “Suspected Phishing” warning on the domain, but that protection only kicks in once a link has been reported and classified. Before that point, the message and the page behind it look, to most recipients, like exactly what they claim to be.

Why DMARC on lastpass.com Never Sees Any of This

This is the detail that matters most for anyone running email authentication. DMARC only evaluates mail that claims to come from a specific domain, checking whether the SPF and DKIM results align with what the From header asserts. The email in this campaign never claims to be from lastpass.com. It comes from lastpassnewsletter.com, a domain the attacker registered, controls end to end, and can authenticate however they like. If the attacker bothers to set up SPF and DKIM on lastpassnewsletter.com, and there is no reason they would not since it costs nothing and only makes the mail look more legitimate, that mail passes DMARC cleanly. Not because DMARC failed, but because DMARC was checking the wrong question. It was built to answer “did this domain’s real owner send this,” and lastpassnewsletter.com’s real owner is the attacker. LastPass’s own DMARC policy, however strictly enforced, has no jurisdiction over a domain it does not own.

Why This Matters for Password Managers, Deliverability, and Trust

Password managers are an especially high-value target for exactly this pattern because the entire product depends on users trusting a single credential to unlock everything else. A cousin domain that merely sounds official, paired with a familiar-looking notice and a second-stage impersonation of a trusted service like DocuSign, does not need to beat any authentication check because it was never subject to one in the first place. For every brand whose users manage sensitive credentials, this is a reminder that domain-level authentication and lookalike-domain monitoring are two separate defenses solving two separate problems, and skipping either one leaves a gap the other cannot close.

What Security Teams and Users Should Do Now

Register the newsletter, compliance, and policy variants of your own domain before someone else does. lastpassnewsletter.com and lastpasscompliance.com are exactly the kind of low-cost, high-plausibility patterns that attackers reach for first; a small defensive registration budget closes off the cheapest version of this attack.

Monitor for lookalike domains continuously, not just after a campaign is already reported. By the time Microsoft SafeLinks and Cloudflare flagged these domains, the campaign had already been running long enough to reach a large number of inboxes.

Never enter a master password, or any single credential that unlocks other accounts, on a page reached by clicking a link in an unsolicited email. Navigate to the password manager’s site directly instead, every time, regardless of how urgent or official the email claims to be.

Treat DMARC enforcement on your own domain as necessary but not sufficient. It stops someone from sending mail that impersonates your exact domain. It does nothing to stop someone from registering a domain that merely sounds like yours and authenticating that instead.

The Takeaway

Two new domains, one fake compliance notice, and a borrowed DocuSign identity were enough to build a campaign that no DMARC policy, no matter how strict, was ever positioned to catch. The lesson is not that DMARC failed here. It is that DMARC answers one specific question about domains you own, and lookalike-domain monitoring has to answer the question DMARC was never designed to ask.


Excello Mail keeps every domain you actually own fully authenticated and enforced against direct spoofing, so your security team can spend its time watching for the lookalike domains and cousin registrations that live outside DMARC’s reach. Sign up for free to Excello Mail to see exactly who is authenticated to send as you today.