364 Parked Domains Got DMARC Records. 79 of Them Were Being Spoofed.

October 11, 2026 · 13 min read

364 Parked Domains Got DMARC Records. 79 of Them Were Being Spoofed.

TL;DR - An admin posted to r/sysadmin in the first week of October with the kind of hard number most of us never publish: he inventoried the 364 parked domains his company still owned but had forgotten, published DMARC records on all of them, and 79 came back with mail claiming to be from domains that send nothing. That is one admin's dataset from one week, not a research finding, and I am treating it that way here. The number is not the lesson. The lesson is that a domain with no DMARC record is invisible: no record means no policy for receivers to follow and no reports for you to read, so the spoofing was already happening and nobody could see it. What you need to do: spend an afternoon building the list of every domain you own, publish DMARC with a rua address so you can see what turns up, and set a parked domain to p=reject on day one, because there is no legitimate mail to lose.


By The Numbers

ItemValueWhy it matters
Parked domains the company still owned364Found by inventory, not by asking anyone
Parked domains with no DMARC record before the sweepEvery one of themNo record means no policy and no reports
Domains whose reports showed an unaligned sender7921.7% of the estate, on one admin's numbers
Domains that came back with nothing to look at285Quiet is not the same as clean, see the caveat below
Policy published on a parked domainp=reject, sp=rejectStraight to reject. There is nothing to protect
SPF published alongside itv=spf1 -allAuthorise nothing, fail everything
Alignment mode set on the recordadkim=s, aspf=sCloses the relaxed alignment path
Time the whole exercise tookOne afternoonThen an afternoon of DNS

These are one administrator's numbers for one estate in one week. I am reproducing them because they are concrete, not because they describe the average Australian business.


I read a r/sysadmin thread this week with my coffee going cold, because it was not the usual shape. No breach write-up, no CVE, no vendor apology video. Somebody posting his own homework. He had gone through the 364 parked domains his company still owned but nobody had looked at in years, published a DMARC record on every single one, and then waited for the reports. 79 of them came back with somebody else's mail attached.

Then I did the thing I always do with a good number, which is try to break it. Where did 364 come from. Is "79 being spoofed" the same as 79 attacks, or 79 something softer and more boring. Can you even receive mail from a parked domain, and if so, who is sending it. I went looking for the dataset and there is not one, because he did not publish one. That is fine. It is one admin's estate, one week, his tooling, his judgement calls. I am not going to launder that into a statistic about Australian businesses.

What survives that poking is the shape, and the shape is the part that should change your afternoon. A domain that sends nothing and has no DMARC record is not secure. It is dark. You have published no instruction for receivers to follow, so they fall back to their own heuristics, and you receive no aggregate reports, so you never hear a thing. Meanwhile that domain is sitting in a registrar account you still pay for, wearing your brand, and the only people getting value from it are the ones emailing your customers a password reset from a lookalike address.

Let me walk you through what he actually did, why a parked domain is the one place where p=reject on day one is the correct call rather than a reckless one, and the record shape that does the work.

The inventory was the actual job

The afternoon he spent on inventory was not optional overhead. Without it there is nothing to configure. All four sources are free, which is the part I wish more people knew.

Your registrar account export. Every domain you have ever bought sits in one of these. Agencies are the usual culprit here. A client leaves, the campaign microsite goes quiet, and the domain stays in somebody's account forever because deleting it requires somebody to admit it is dead. Pull the full list, not the favourites. Note the year each one was registered and whether anybody inside the company can say what it is for.

Certificate Transparency logs. Every publicly trusted TLS certificate gets logged, and those logs are searchable. crt.sh is the interface most people use. You look up your base domain and get back every subdomain anybody has ever issued a certificate for, including the ones an agency spun up for a campaign that ended in 2021, and the ones somebody pointed at a parked-page service. A lot of it will look like noise. Some of it will not.

Historical WHOIS. Registration dates, registrar history, nameserver changes. A domain that changed handservers three times since you last asked questions about it has a story. You are not always going to like what you find. You are always going to know more than you knew this morning.

Your own marketing archive. Old invoices, old campaign briefs, the website you took down two years ago. This sounds unserious. It resolves the ambiguous ones, because somewhere there is a PDF with the domain printed on it and a purchase order number next to it.

Expect the list to be uncomfortable. Expect plenty of it to be domains nobody in the building can explain. That is not a failure of your memory, it is the normal state of a company that has been trading for a decade.

A parked domain is the one place p=reject on day one is right

Here is where I want to push back on most of the advice floating around, because it will cost you real mail if you follow it here.

The standard rollout guidance for DMARC, and it is sound guidance, is to start at p=none, read the reports for a while, then move to quarantine, then to reject. Do not do that to a parked domain. Go straight to p=reject.

The reason is simple and it is the whole reason. That staged rollout exists to protect mail you care about from breaking. It assumes you have legitimate senders and you are worried about missing one. A parked domain has no legitimate senders. There is no newsletter going out. There is no CRM, no password reset flow, no shared mailbox, no invoice system. There is no legitimate mail to lose, so there is nothing for the cautious rollout to protect.

If you start a parked domain at p=none you have bought yourself nothing except extra weeks of somebody else's mail landing in your customers' inboxes with your domain on the From line. Reject is not the brave option here. It is the accurate description of reality.

The one genuine risk on a parked domain is the forgotten service. Somebody wired a service to that domain years ago and nobody wrote it down. A SaaS password reset flow, an old support portal, a marketing tool still sending from it. That is why I get to rua in a moment, and it is the only thing that argues for a softer landing.

The record that does the work

The shape he landed on, and the one I would land on, looks like this across three records.

DMARC:

v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s

SPF:

v=spf1 -all

DKIM: nothing. No keys published.

Read those together and they say one thing: no mail is authorised to leave this domain, and if any does, throw it away. That is the pattern DMARC guidance describes for a domain that sends nothing. It is sometimes called a null reverse, because there is nothing to forward-confirm and nothing to sign with.

Two bits deserve a plain-English gloss because they are the ones people leave out.

Why sp=reject as well as p=reject. If you leave the subdomain policy out, receivers fall back to the organisational-domain policy. Setting it explicitly covers subdomains by name rather than by inference, which is one fewer thing to reason about at 5pm on a Friday.

Why adkim=s and aspf=s. By default, DMARC's alignment modes are relaxed. Relaxed alignment is generous: it accepts an authenticated domain that matches at the organisational-domain level, which in plain English means a sibling or a subdomain can count as aligned. Strict alignment requires an exact match on the domain in the From header. On a domain with no legitimate mail, there is no reason to leave a generous path open. Tighten it.

Now the reporting address, which is the part people skip and the part I would not.

rua=mailto:dmarc@yourreportingdomain.com

DMARC aggregate reports are XML files sent by receiving mail servers that processed a message claiming to be from your domain. They tell you the source IP, whether SPF and DKIM passed, whether either was aligned, and the disposition. Publishing rua is not enforcement. It is turning the lights on. Without it you published a policy into a room with nobody in it and you will never know what came back.

Use it for a defined window. Read it. Sort out the 79, work out whether each one was an attack or a forgotten service. Once a parked domain has sat quiet through a window or two, drop the rua and leave the policy doing the enforcement work on its own. Useful early, then out.

A parked domain with no DMARC record is not defended. It is simply unobserved, and unobserved is where spoofing lives.

What the 79 actually means, and what it does not

This is the part I would read twice, because "79 were being spoofed" is doing a lot of work in that headline and most of it is fair.

What the reports showed is this: for 79 of the 364 domains, at least one aggregate report arrived describing a message where the From domain was that parked domain, and neither SPF nor DKIM passed with alignment to it. Put plainly, mail was claiming to be from a domain that does not send mail, and the authentication that would have tied it to the real owner did not hold.

What that is not:

It is not 79 successful phishing campaigns. A report means a receiving server processed a message. It does not mean somebody clicked, and it does not mean the message was delivered rather than junked. Most of these were almost certainly filtered. Some may have been junked on sight.

It is not 79 confirmed attackers. Unaligned does not automatically mean hostile. On your main sending domain an unaligned report is often a legitimate service you forgot about. On a parked domain that is less likely, but a third party somebody configured years ago is not impossible, and a report will not tell you which one you are looking at.

It is not a floor or a ceiling, it is a sample. Reports only come from receivers that run DMARC and choose to send them. Domains with no record at all sent none, which is the entire problem. And the 285 quiet ones are not certified clean, they are just domains nobody tried to use. Quiet is the absence of evidence, not evidence of absence.

So the honest version of that headline is: of 364 domains we own and do not use, roughly a fifth had at least one message turn up claiming to be from them, within a single reporting window, from an admin who had never checked before. That is a smaller claim and a much more useful one, because it is a claim you can go and test on your own estate this month.


Key Takeaways

  • A parked domain with no DMARC record is unobserved, not defended. No record means no policy for receivers and no reports for you.
  • The inventory is the job. Registrar export, Certificate Transparency logs, historical WHOIS, your own marketing archive. One afternoon.
  • Parked domains get p=reject on day one. Staged rollout protects mail you care about. A parked domain has none.
  • The record is three lines. v=spf1 -all, no DKIM keys, and v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s.
  • rua turns the lights on. Aggregate reports tell you what is claiming to be your domain. Use it for a window, then drop it.
  • Unaligned does not mean confirmed attack. 79 reports is not 79 successful campaigns. Check each one before you assume.
  • Quiet is not clean. The 285 domains that reported nothing have not been cleared, they have not been checked.

FAQ

Do I need DMARC on a domain that never sends email?

Yes. That is the exact case it is for. A domain that sends nothing can still be used to send mail claiming to be from it. Without a DMARC record you have no policy and no reports, so you find out from a customer, if at all.

Should a parked domain start at p=none?

No. The staged p=none, then quarantine, then reject rollout exists so you do not break legitimate mail. A parked domain has no legitimate mail to break. Start at reject. The one exception is a domain you suspect still has a forgotten service attached, and even then the answer is reject plus a rua address so you find out.

What exactly does p=reject do?

It tells receiving mail servers to refuse any mail that fails DMARC. SPF and DKIM both have to pass, and at least one of them has to be aligned with the domain in the From header. For a domain that sends nothing and authorises nothing, there is nothing left to lose.

What is alignment, in plain English?

DMARC asks whether the domain in the From header matches the one that actually authenticated the message. Relaxed alignment accepts a match at the organisational-domain level, so a sibling or subdomain counts. Strict alignment requires an exact match, which is what adkim=s; aspf=s sets on a parked domain.

How do I find parked domains I have forgotten about?

Four free sources. Export every domain from your registrar account. Search your base domain on Certificate Transparency logs like crt.sh to surface old subdomains. Check historical WHOIS for registration and nameserver changes. Then grep your own old invoices and campaign briefs, because that is where the ambiguous ones get resolved.

Is 79 spoofed domains out of 364 normal?

I do not know, and neither does the admin who posted it. It is one estate in one week with no published dataset. Use it as a reason to go and check yours, not as a benchmark to compare against.

Do I still need rua once the domain is on reject?

Not for enforcement. Reports do not tell receivers to do anything, they tell you what happened. Keep rua while you are working out whether anything legitimate was ever attached to that domain, then drop it once the domain has been quiet through a reporting window or two.

My Take

The number that will stay with me is not the 79. It is the 364.

That is the size of a hole most Australian businesses have and cannot see. A mid-sized firm in Melbourne with fifteen years of trading history has a registrar account nobody has logged into since the founder left. It has an agency relationship that ended in 2022 and never got cleaned up. It has three or four domains that a campaign manager spun up once and nobody has thought about since. None of that is negligence in the way people usually use the word. It is what happens when nobody is ever assigned the job of owning a domain list, and the job therefore does not get done.

The uncomfortable part is what that means on a Tuesday afternoon when nobody is reading. A parked domain with no DMARC record is a domain where an attacker gets to pick the display name, get your domain on the From line, and rely on the receiver's own judgement plus your customer's willingness to click. You contribute nothing to stopping that. You are not misconfigured. You are absent.

The good news is that the fix is boring and costs an afternoon. You cannot patch your way out of this one, you have to go and look. Build the list, because you cannot configure what you cannot name. Then set each dead domain to reject and authorise nothing. None of this is exciting. But it works, and the version of you six months from now who finally opens the registrar account will not have to wonder what you found.


Mathew Clark Founder, SecureInSeconds Currently: auditing my own registrar account for domains I would not be able to name from memory Drafted with AI assistance - read, verified, and fixed by a human.


Further Reading

Share:
Buy me a coffee

You might also like