Unexpected DMARC Reports Flood emvdmarc[.]com After Domain Acquisition

December 1, 2025

After acquiring emvdmarc[.]com, DMARC reports from 12 unrelated organizations started arriving, highlighting potential misconfigurations or routing issues.

Unexpected DMARC Reports Flood emvdmarc[.]com After Domain Acquisition

We recently purchased the domain emvdmarc[.]com, and after configuring a catch all mailbox, we started receiving DMARC aggregate reports for random domains.

Within a few days, we received reports for 12 organizations, and we haven’t been able to determine who previously owned emvdmarc[.]com AND why email addresses under this domain are still being used as reporting endpoints.

BECAUSE none of the domains whose reports we’re receiving list an @emvdmarc[.]com address in their current DMARC policy.

My guess is that some routing rules are still in place, causing certain reporters to forward DMARC XML to @emvdmarc[.]com. But the question is why only a subset of reporters continue sending reports to these addresses.

If anyone can help identify & tag the previous owner or if you can share this post to help surface the right contact, we're happy to facilitate the domain transfer back to the appropriate party.

Related posts
All posts
Coordinated Subdomain Takeover Campaign Targeting US Universities

Attackers are hijacking abandoned .edu subdomains via orphaned CNAME records, serving spam under trusted university domains and exploiting SEO authority.

Coordinated Subdomain Takeover Campaign Targeting US Universities
Cloudflare's DMARC Documentation Exposed an Unregistered Domain And Dozens of Organizations Paid the Price

How an unregistered domain in Cloudflare's DMARC documentation silently exposed infrastructure data from dozens of organizations.

Cloudflare's DMARC Documentation Exposed an Unregistered Domain And Dozens of Organizations Paid the Price
FinTech AccessPay Exposed Internal Email Infrastructure Data for Years

A misconfigured DMARC record sent sensitive email infrastructure data to an unregistered domain, creating a long-term exposure risk.

FinTech AccessPay Exposed Internal Email Infrastructure Data for Years