SubdoMailing Guard: stop attackers sending from your subdomains
SubdoMailing is a real campaign that hijacked thousands of abandoned subdomains at well-known brands to send spam that passed authentication, because the parent domain's DNS still vouched for them. This page finds the records that make that possible on your domains.
- Where to find it
- Monitoring & Risk → SubdoMailing Guard
What you'll see
- A count of active exposures, broken down by type: dangling MX, broken SPF, dangling CNAME.
- A table of exactly which record is exposed and what service it points at.
Fixing one
These records live in your DNS, so DMARCS can't remove them for you. Each row has a Copy Record to Remove button that puts the exact record on your clipboard; delete it at your DNS provider. It disappears from the table on the next scan.
Check before deleting that nobody still uses the subdomain. A record that looks abandoned might belong to a system that only sends once a quarter. When in doubt, ask, then delete.
To discover subdomains you didn't know existed in the first place, see Subdomain Monitor.
Still need a hand?
Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.