Real companies are being spoofed right now
These attacks used a real company's exact domain — not a look-alike — which is what spoofing means. Their domain publishes no DMARC policy, or one set to “do nothing”, so anyone in the world can send email as them. This is what a missing DMARC record costs you.
Live data from LastSpam, our sister email-security service, updated hourly.
Why no numbers?
How many messages were blocked is a vanity metric. What matters is whether your domain can be used against your customers — and that is a yes or no question.
Why no company names?
Naming them would expose their customers further and confirm to attackers that the technique works. But the owner is not powerless: mail sent from their exact domain is stopped by an enforcing DMARC policy, and they are the only ones who can publish one.
Could this be your domain?
If your DMARC record is missing, or set to p=none, your domain can appear in traffic like this and you would never know. DMARC reporting is how you find out.
Is your domain one of them?
Check your DMARC, SPF and DKIM in about ten seconds. Free, no account, no obligation.