Hidden SPF Abuse via Look-Alike SendGrid Domain

April 2, 2025

During an SPF audit, DNS lookup limits were exceeded despite only Google and SendGrid being expected. Investigation revealed a typo-squatted include domain masquerading as SendGrid, exposing a serious email security and supply-chain risk.

Hidden SPF Abuse via Look-Alike SendGrid Domain

While investigating the SPF record for a company, I was surprised to find that even with only Google and SendGrid servers, the SPF DNS lookups exceeded the maximum of 10. Upon further inspection, I discovered that the SPF record included IPs from suspicious servers hidden behind the "include" parameter. Initially, I assumed SendGrid's servers had been compromised.

However, a closer examination revealed that the parameter was not "include:sendgrid.net" but rather "include:sengrid.net". This subtle difference, a missing "D", raises significant concerns.

One of the questions is how such a major service provider like SendGrid doesn't own domains that closely resemble their primary one. This oversight can be exploited by malicious actors, leading to severe security implications. Isn't it a fundamental rule in cybersecurity to protect and secure look-alike domains to prevent such vulnerabilities?

Related posts
All posts
Google.com Scam Sent via Gmail API - DMARC Passed, No Account Compromise

A scam email sent from @google.com passed SPF, DKIM, and DMARC without a compromised account. Here’s what it reveals about modern email threats.

Google.com Scam Sent via Gmail API - DMARC Passed, No Account Compromise
When Vendors Control Your DNS: A Hidden DMARC Security Risk

A real-world example of how third-party DNS control can silently block DMARC visibility, redirect domain telemetry, and introduce serious email security and data exposure risks.

When Vendors Control Your DNS: A Hidden DMARC Security Risk
2.3 million emails. One exposed API key. $10K bill.

How DMARC forensics exposed an API key leak, 2.3M unauthorized emails, and a $10K bill.

2.3 million emails. One exposed API key. $10K bill.