Unauthorized DNS Changes Suggest Possible GoDaddy Issue

April 28, 2025

Domain saw unauthorized SPF/CNAME changes allowing emails to bypass DMARC p=reject, suggesting potential interference from GoDaddy systems.

Unauthorized DNS Changes Suggest Possible GoDaddy Issue

We monitor one domain that sees minimal legitimate traffic - approx. 10 emails/mo via Google Workspace, and has DMARC set to p=reject due to a really high volume of spoofing attempts.

About a week ago, URIports sent a notification about unexpected change to the SPF record. Previously, it only included Google servers. It was altered to:

v=spf1 include:spf.em.secureserver[.]net include:_spf.google[.]com ~all

Upon checking the DNS zone, we also found two new CNAME records pointing to secureserver[.]net. No internal stakeholders made these changes, and the domain has no history of using GoDaddy’s (or any other provider's) email services besides Google.

We removed the unauthorized records. However, a few days later, they reappeared, and 2 SPF-aligned emails were sent from the domain, bypassing DMARC p=reject. A follow-up review confirmed only two people (myself included) had DNS access, and neither made the changes.

This strongly suggests the modifications were made by GoDaddy or an affiliated system without owner consent. Given the domain is not used for communication, and the spoofing volume is high + the fact that the domain belongs to a well-known person in their field, this raises serious concerns.

GoDaddy doesn’t provide logs, so if anyone can tag relevant contacts at GoDaddy to investigate this further, it would be really helpful. Right now, it seems like we got scammed by GoDaddy itself, and I really hope that’s not the case.

Related posts
All posts
Why a 24-Email Batch Triggered a Gmail Lockout

Why a Google Drive link in a Follow Up Boss batch email triggered spam flags and a Gmail sending limit error and how proper domain authentication fixes it

Why a 24-Email Batch Triggered a Gmail Lockout
Google Postmaster v2 API Signals Upcoming v1 Deprecation

Google has updated its Postmaster v2 API documentation, signaling that the v1 API is likely approaching deprecation.

Google Postmaster v2 API Signals Upcoming v1 Deprecation
Why Email Has So Many Rules (And Why That’s a Good Thing)

Email has more rules than ever, and for good reason. Different inbox providers enforce strict standards to protect users and control spam.

Why Email Has So Many Rules (And Why That’s a Good Thing)