5 min read By Excello Mail Team

One Phishing Platform Now Sends Tens of Millions of Messages a Month Without a Human Writing One of Them. DMARC Still Only Asks Who Sent It.

Microsoft is tracking phishing-as-a-service platforms like Tycoon2FA generating tens of millions of AI-assisted messages a month, while a Dark Reading poll finds 48% of security professionals now rank agentic AI as the top attack vector of 2026. The reconnaissance, targeting, and pretext generation behind these campaigns happen entirely outside anything DMARC was built to inspect.

A Dark Reading readership poll released this month found that 48% of security professionals now rank agentic AI as the top attack vector heading into the rest of 2026, ahead of deepfakes, board-level cyber awareness, and passwordless adoption. That is not a poll about a hypothetical. Microsoft has been tracking phishing-as-a-service platforms, Tycoon2FA among them, that already generate tens of millions of phishing messages a month reaching more than 500,000 organizations worldwide. The part worth sitting with is not the volume. It is who, or what, is doing the work.

The Attacker Is Increasingly an Agent, Not a Person

For years, “AI phishing” meant an operator typing a prompt to draft one convincing email. What security researchers are now describing as agentic phishing removes the operator from most of the loop. An agent can pull a target’s public footprint, cross-reference GitHub commits and cloud documentation, map who reports to whom inside an organization, and generate a specific, plausible pretext, then repeat the entire process for the next ten thousand organizations without anyone reviewing the output in between. Reconnaissance that used to take a human analyst hours per target now scales the way a batch job scales.

That same agent does not stop at drafting. It can register the infrastructure, send the message, watch how a target responds, and adjust the next message in the sequence based on that response, across email, a chat app, or a phone call, without a person deciding what happens next. The lure is no longer a static artifact a defender can fingerprint once and block everywhere. It is a live conversation being run by software.

Microsoft Is Fighting Agent With Agent

Microsoft’s own response is instructive. Its Security Copilot Phishing Triage Agent now handles a large share of user-submitted phishing reports autonomously, classifying incoming alerts, clearing false positives, and escalating only what actually needs a human analyst. That is not a coincidence of timing. When the volume and adaptiveness of an attack comes from automation, the only realistic way to match its speed is defensive automation running on the receiving end. Security teams that are still routing every reported phishing email through a human triage queue are bringing a person to a machine-speed fight.

Why DMARC Never Sees the Part That Changed

DMARC, SPF, and DKIM answer one narrow question: did this message’s claimed domain actually authorize the server that sent it. Platforms like Tycoon2FA route their campaigns through freshly registered domains and adversary-in-the-middle reverse proxies the attacker controls outright, so those messages pass their own authentication checks trivially. Passing DMARC on infrastructure the attacker registered an hour ago says nothing about the intent behind the message.

More importantly, everything that actually changed about this threat, the automated reconnaissance, the org-chart mapping, the pretext generation, the mid-conversation adaptation, happens upstream of the message or downstream of the click. None of it is a header, a signature, or a sending IP. DMARC was built to stop a specific and still-common failure, a forged domain, and it remains one of the best tools available for exactly that job. It was never built to evaluate whether the entity on the other end of an email thread is still a person, or whether the next message in that thread was generated in response to your reply thirty seconds ago.

What This Means for Your Program

Keep DMARC enforced at reject on every domain you own. Agentic phishing platforms overwhelmingly rely on domains they control, not on spoofing yours, but the domains that do spoof you are exactly the ones DMARC enforcement stops cold.

Push your security team toward automated triage, not more headcount. A queue of reported phishing emails reviewed one at a time by analysts cannot keep pace with a platform generating tens of millions of messages a month. Automating the first pass, the way Microsoft has with its own reporting pipeline, is what makes the human review that follows sustainable.

Train people to notice a conversation that keeps adapting, not just a message that looks off. The old advice, check for typos, verify the sender, still applies, but the newer risk is a thread that responds intelligently to pushback. A message that answers your skeptical reply a little too well is itself a signal.

Treat reconnaissance-resistant information hygiene as a control, not a nice-to-have. Public org charts, out-of-office replies with project details, and permissive GitHub commit histories are exactly the raw material an agent uses to build a convincing pretext at scale.

The Takeaway

The volume numbers from Microsoft and the sentiment in that Dark Reading poll are both describing the same shift: the marginal cost of running a convincing, adaptive phishing campaign against one more target has collapsed to nearly zero. DMARC enforcement remains non-negotiable, because a forged domain is still one of the cheapest ways to earn a click, and closing that door stays worth doing regardless of what else is changing. Just do not mistake that door for the whole house. The attacker on the other end of tomorrow’s phishing thread may not review a single message before it reaches your inbox, and the defense that matches it will need to be just as automated.


Excello Mail helps you enforce DMARC, SPF, and DKIM correctly on every domain you own, closing the forged-domain door that phishing platforms still rely on by default while your team builds the automated defenses the agentic threats need. Sign up for free to Excello Mail and get full visibility into who is sending as your domain.