Did You Just Get an Email from âsupport.yourcompany.comâ? Think Again.
Imagine this: Your customer gets an email from billing.yourcompany.com asking for payment details. It looks legit. The email address checks out.
đ¨ But wait⌠Your company never sent that email!
This is subdomain spoofingâone of the most overlooked security threats in email authentication. Attackers exploit unprotected subdomains of your domain (like help.yourdomain.com or info.yourdomain.com) to send phishing emails. And if you're not using DMARC properly, you might never even know it's happening.
Scary, right? đ¨
Letâs fix that.
đ How Does Subdomain Spoofing Work?
Attackers take advantage of misconfigured or unprotected subdomains to send fake emails that look like theyâre from your brand.
Hereâs how:
1ď¸âŁ They find a subdomain without proper DMARC protection. 2ď¸âŁ They use it to send phishing emails to your customers or employees. 3ď¸âŁ Because the email âlooks real,â people fall for itâcompromising accounts, sending money, or leaking sensitive data.
And the worst part? Since itâs a subdomain, even your main domainâs DMARC policy might not protect it!
đŚ How to Check if Your Subdomains Are Vulnerable
First things firstâletâs check if your subdomains are properly secured. Run this command in your terminal:
shCopyEditnslookup -type=TXT _dmarc.yourdomain.com
If you see âNXDOMAINâ or no DMARC record, it means your subdomain is not protected.
You can also use a free DMARC checker tool to scan for missing policies.
đĄď¸ The DMARC Fix: Securing Your Subdomains Against Spoofing
1ď¸âŁ Apply a DMARC Policy to Every Subdomain
By default, DMARC does NOT inherit the policy from your main domain. This means each subdomain needs its own protection.
â Solution: Publish a wildcard DMARC record:
txtCopyEdit_dmarc.yourdomain.com TXT "v=DMARC1; p=reject; rua=mailto:dmarc-reports@yourdomain.com"
This ensures that ANY subdomain under yourdomain.com follows the DMARC policy.
2ď¸âŁ Use a Strict DMARC Policy (Not Just âNoneâ)
A "p=none" policy is like putting a lock on your door but leaving the key under the mat. Attackers can still spoof your subdomain!
â Better Approach: Change this:
txtCopyEditv=DMARC1; p=none
To this:
txtCopyEditv=DMARC1; p=reject; sp=reject
đ¨ That âsp=rejectâ part is critical! It tells email servers to reject spoofed emails sent from ANY subdomain under your main domain.
3ď¸âŁ Enable DMARC Reports to Catch Attackers in the Act
Wouldnât it be great if you could see exactly whoâs trying to spoof your domain? Thatâs where DMARC reports come in.
â Solution: Set up an email to receive DMARC reports:
txtCopyEditv=DMARC1; p=reject; rua=mailto:dmarc-reports@yourdomain.com; ruf=mailto:dmarc-forensics@yourdomain.com
This will give you real-time insights into spoofing attempts, so you can act fast.
4ď¸âŁ Lock Down SPF and DKIM for Extra Security
DMARC is powerful, but it works best with SPF and DKIM.
đš SPF Setup: Make sure your SPF record includes only authorized mail servers and is strict:
txtCopyEditv=spf1 include:_spf.google.com -all
đš DKIM Setup: Enable DKIM signing for all outgoing emails. Run this check to see if itâs active:
shCopyEditnslookup -type=TXT default._domainkey.yourdomain.com
If nothing shows up, you need to enable DKIM in your email provider settings.
đ Final Thoughts: Donât Let Subdomain Spoofing Ruin Your Reputation
Attackers love exploiting subdomains because theyâre often unprotected. Donât make it easy for them!
â Action Plan Recap:
âď¸ Check for missing DMARC records on subdomains âď¸ Apply a strict DMARC policy with âsp=rejectâ âď¸ Set up DMARC reports to monitor spoofing attempts âď¸ Lock down SPF and DKIM for extra protection
Youâve worked hard to build trust in your brand. Donât let subdomain spoofing destroy it. Signup & try free today! đ








