Google.com Scam Sent via Gmail API - DMARC Passed, No Account Compromise

February 11, 2026

A scam email was sent from a legitimate @google.com address via the Gmail API and passed SPF, DKIM (signed by Google), and DMARC with p=reject. No account was compromised, and there were no phishing links or attachments - just social engineering designed to trigger a reply. This case shows that authentication alone cannot stop abuse when attackers operate through trusted infrastructure.

Google.com Scam Sent via Gmail API - DMARC Passed, No Account Compromise

Someone just sent a scam email from @google[.]com through the Gmail API with DMARC p=reject passed, DKIM signed by Google, and SPF authenticated, bypassing several internal security controls.

Urgency in the subject line, a request to review Q1 ads performance, tailored to the victim's industry, expecting them to reply. No phishing links, payloads, or attachments were inside.

For this scam to work, the threat actor must have access to a @google[.]com mailbox and be able to read incoming replies and continue the conversation.

But this wasn't a classic BEC. No Google account was taken over.

Attacks are getting more sophisticated.

Related posts
All posts
Coordinated Subdomain Takeover Campaign Targeting US Universities

Attackers are hijacking abandoned .edu subdomains via orphaned CNAME records, serving spam under trusted university domains and exploiting SEO authority.

Coordinated Subdomain Takeover Campaign Targeting US Universities
Cloudflare's DMARC Documentation Exposed an Unregistered Domain And Dozens of Organizations Paid the Price

How an unregistered domain in Cloudflare's DMARC documentation silently exposed infrastructure data from dozens of organizations.

Cloudflare's DMARC Documentation Exposed an Unregistered Domain And Dozens of Organizations Paid the Price
FinTech AccessPay Exposed Internal Email Infrastructure Data for Years

A misconfigured DMARC record sent sensitive email infrastructure data to an unregistered domain, creating a long-term exposure risk.

FinTech AccessPay Exposed Internal Email Infrastructure Data for Years