Daily DMARC News
  • Home
  • Posts
  • Excello Mail ↗
  • EN
  • ES
  • PT

All Posts

Every post we’ve published — newest first.

News on this site is aggregated and summarized automatically from public industry sources. Occasional inaccuracies are possible and always unintentional — if you spot one, we’ll gladly correct or remove it. Report an issue.

  • August 31, 2026 5 min read

    A Human Was Watching in Real Time and Choosing Your Next Screen. The Emails That Got You There Passed DMARC Anyway.

    Most credential-phishing kits are automated end to end: a victim lands on a cloned login page, types a username and password, and a script silently forwards whatever was typed to wherever the attacker checks in later. …

  • August 30, 2026 5 min read

    50 Requests, 50 Different Pages: A Polymorphic Phishing Kit That Occasionally Breaks Itself

    Most phishing kits get caught the same way: a security vendor fingerprints the page, hashes it, and pushes that hash into a blocklist that every other vendor eventually inherits. It is slow, but it works, because most …

  • August 29, 2026 5 min read

    86 Domains, One Expired Endpoint: How a Squatted DMARC Reporting Address Became Anyone's to Read

    DMARC’s aggregate reporting was built on a simple idea: publish a rua= address in your DNS, and mailbox providers around the world will mail you a daily digest of who is sending as your domain. Most of this …

  • August 28, 2026 5 min read

    Ten Domains, Nine SendGrid Accounts, a Real Docusign Envelope: A $320-a-Month Kit That Passes DMARC on Purpose

    Most of the DMARC-authenticated phishing this blog has covered relies on hijacking somebody else’s trusted domain, a compromised Amazon SES account, a genuinely Microsoft-sent Azure Monitor alert, a real vendor …

  • August 27, 2026 5 min read

    24 npm Packages Became Disposable Phishing Hosting on a CDN Everyone Already Trusts. DMARC Was Never Asked About That Domain.

    A link lands in someone’s inbox or chat window pointing to unpkg.com, the CDN that millions of developers use every day to pull JavaScript straight out of the npm registry. It looks exactly like what it claims to …

  • August 26, 2026 5 min read

    The Subject Line Read Perfectly Normal. Invisible Characters Hidden Inside It Blinded Every Keyword Filter.

    A recipient opening the email saw an ordinary subject line: “Your Password is About to Expire.” Nothing about it looked unusual. But when Jan Kopriva at the SANS Internet Storm Center pulled the raw headers …

  • August 25, 2026 5 min read

    Microsoft Just Took Away One of the Few Free Warning Signs Email Senders Had Left

    For years, Smart Network Data Services has been the closest thing senders had to a direct line into how Microsoft’s consumer mailboxes, Outlook.com and Hotmail, actually judge their traffic. It is free, it is first …

  • August 24, 2026 5 min read

    A New Password-Stealing Malware Never Touches Email. A Researcher Baited Its Operators for 24 Hours to Prove It.

    Researchers at Expel spent this month picking apart a malware family they had never seen before. It calls itself, or at least its file names suggest, SynkLoader, and it reaches victims through a channel that a lot of …

  • August 23, 2026 5 min read

    One Phishing Platform Now Sends Tens of Millions of Messages a Month Without a Human Writing One of Them. DMARC Still Only Asks Who Sent It.

    A Dark Reading readership poll released this month found that 48% of security professionals now rank agentic AI as the top attack vector heading into the rest of 2026, ahead of deepfakes, board-level cyber awareness, and …

  • August 22, 2026 5 min read

    Hackers Poisoned Hotel and Conference Wi-Fi DNS to Hijack Microsoft 365 Accounts. No Phishing Email Was Ever Sent.

    Most of the phishing campaigns we cover here start with an email. This one does not, and that is exactly why it belongs in this newsletter. Threat intelligence firm ReliaQuest published a Threat Spotlight this month …

  • August 21, 2026 5 min read

    Google Traced Three Russian Espionage Crews Hijacking OAuth, App Passwords, and WhatsApp. None of Their Emails Ever Fail DMARC.

    Google’s Threat Intelligence Group published a report this week tracking three suspected Russian-nexus hacking clusters running espionage campaigns against academics, diplomats, defense industry professionals, and …

  • August 20, 2026 6 min read

    DMARCbis Added a Tag to Close the Subdomain Spoofing Hole. On DNSSEC-Signed Domains, It Can Silently Do Nothing.

    We covered RFC 9989, the DMARCbis update, when it landed earlier this year. One of its headline fixes was the np= tag, a policy specifically for subdomains that do not exist. A DNSSEC researcher’s writeup making …

  • ««
  • «
  • 1
  • 2
  • 3
  • 4
  • 5
  • »
  • »»
Daily DMARC News

Daily news, analysis, and guidance on DMARC and email security.

Explore

  • Home
  • All posts
  • RSS feed

From the team

  • Excello Mail ↗
  • About
  • Contact
© 2026 Daily DMARC News. All rights reserved. From the team at Excello Mail.