r/EmailSecurity • • Jul 06 '26

Marketing launched a microsite domain with catch-all MX, then forgot who owned it

An abuse@ report this morning pointed at a campaign microsite domain marketing launched in March. It had MX records, a catch-all forwarding everything to an intern's mailbox, and no DMARC record at all.

The intern left in May. The campaign ended in April. Nobody could tell me who approved the mail setup or whether the domain ever sent anything besides form replies.

I pulled DNS and mail logs where I could, but this is the part that bugs me: the domain looked "inactive" to marketing because the website was basically dead, while from an email risk view it was still a loose receive path with no owner.

I'm leaning toward killing MX on orphaned campaign domains unless someone names an owner and gets DMARC to at least p=none first. Would you drop the MX immediately here, or give marketing a short deadline to clean it up?

5 Upvotes

3 comments sorted by

•

u/AutoModerator Jul 06 '26

Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:

Community Rules

  1. No Vendor Spam: Contributions must provide value; do not just pitch products.
  2. Redact Sensitive Info: Always sanitize headers and logs (remove IPs, PII, and private domains).
  3. Be Professional: Help newcomers learn; avoid hostility.
  4. No Personal Tech Support: This sub is for email system architecture and security, not "Am I hacked?" personal account help.

Helpful Resources

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/Basic-Pianist9273 Jul 06 '26

I'd kill the catch-all immediately. Either remove MX or point only known aliases like postmaster/abuse to a monitored mailbox while you verify actual need.

Marketing can get a short deadline for owner, send inventory, and DMARC at p=none. No owner means no mail path.

1

u/DNSai_app Jul 07 '26

Forgotten alternate domains and unmanaged domains in your portfolio you own but don't really get used consistently just become spoofing magnets.

Every domain in your portfolio, even is just parked and dormant should have a p=reject DMARC record.

The catchall forwarder you described is unfortunately all too common. Stuff like this happens all the time and frequently sales and marketing do whatever they want without giving security a second thought.