Subdomail phishing
Share this article

Email Subdomail Phishing

Subdomail phishing is a sneaky trick that makes their fake emails look authentic — even to email security checks. It’s called subdoMailing (or subdomain emailing). In short: attackers take over a subdomain that looks like it belongs to a real company, then send emails from that name so the messages pass technical checks and land in your inbox.

What are SPF and DMARC?

SPF and DMARC can be throught of as two simple rules for email carriers:

SPF (Sender Policy Framework) is a list published by a company saying, “These are the servers allowed to send email for us.”

DMARC is a policy published by the domain owner that tells mail systems what to do if a message fails SPF/DKIM checks — for example, mark it as spam or reject it.

These systems are designed to prevent unauthorised people or services sending email that pretends to be from a trusted company. But the subdomailing trick finds a way around them.

How the subdomain trick (SubdoMailing) works — in plain English

  1. A genuine organisation sets up a subdomain (like news.example.com) for a service (analytics, helpdesk, email marketing).
  2. That external service is shut down, or the company stops using it, but the DNS entry (the pointer that says where news.example.com lives) isn’t removed.
  3. The domain with that pointer expires or becomes available again. An attacker registers it and “takes over” that subdomain.
  4. Because SPF and DMARC checks can inherit permission from those old entries, the attacker can now send email that appears to be legitimate and passes normal safety checks.

In simple terms, this means that a malicious actor (scammer) can send a very genuine-looking and somewhat scary email that bypasses robust spam checks and is quite likely to get a response.

How does this happen?

The environment of domain registrations and DNS records is constantly evolving, but in our experience, their administration can fall between the two stools of web developer and IT support provider. Of course, your IT folks will create and maintain your email services, but should they be responsible for managing the records needed by your marketing manager?

Subdomail phishing
Simply checking the full email address can reveal a lot about the origin of the message. If it doesn’t exactly match the company’s website, you should treat it with caution.

What can I do about Subdomail phishing?

As ever, a few simple email safety rules can help keep you safe:

  1. Never click a link inviting you to a website from any email, enter the web address manually and click through (eg. mybank.com)
  2. Always carefully look at the email address. If it doesn’t match the official company web domain exactly, it’s a big red-flag (look out for close spellings or subdomains, eg: scammer@subdomain.officialdomain.com)
  3. If in any doubt, contact the company directly

OK, this sounds like an epic headache. Can I talk to someone who can help?

This is where we’re a little different from an internal marketing person or a regular marketing agency. We have a team of expert web developers with decades of experience in managing domains and DNS records that support our marketing department. Our clients know that they can call on our fully in-house team any time. Not only can they call on the expertise of their marketing account manager, but they also have the full firepower of our expert team of designers and developers in their corner. We offer simple, scalable and hassle-free support SLAs for everything from simple website maintenance to fully outsourced marketing as a service.

Wanna chat some more? Give us a shout any time!

Huge thanks to the experts over in Redsift for the expert knowledge and insights on Subdomail phishing