Unexpected DMARC Reports Flood emvdmarc[.]com After Domain Acquisition

December 1, 2025

After acquiring emvdmarc[.]com, DMARC reports from 12 unrelated organizations started arriving, highlighting potential misconfigurations or routing issues.

Unexpected DMARC Reports Flood emvdmarc[.]com After Domain Acquisition

We recently purchased the domain emvdmarc[.]com, and after configuring a catch all mailbox, we started receiving DMARC aggregate reports for random domains.

Within a few days, we received reports for 12 organizations, and we haven’t been able to determine who previously owned emvdmarc[.]com AND why email addresses under this domain are still being used as reporting endpoints.

BECAUSE none of the domains whose reports we’re receiving list an @emvdmarc[.]com address in their current DMARC policy.

My guess is that some routing rules are still in place, causing certain reporters to forward DMARC XML to @emvdmarc[.]com. But the question is why only a subset of reporters continue sending reports to these addresses.

If anyone can help identify & tag the previous owner or if you can share this post to help surface the right contact, we're happy to facilitate the domain transfer back to the appropriate party.

Related posts
All posts
Backscatter Injection Attacks Exploiting Legitimate Infrastructure

Attackers use backscatter emails to bypass filters, harming servers and delivering phishing content.

Backscatter Injection Attacks Exploiting Legitimate Infrastructure
The Risks of Abruptly Enforcing DMARC p=reject in Organizations

Sudden DMARC enforcement can disrupt workflows, block emails, and impact organizational operations significantly.

The Risks of Abruptly Enforcing DMARC p=reject in Organizations
How a Fake Bank Transfer Email Nearly Fooled Me

Spoofed emails can mimic trusted senders, highlighting risks in elementary school communications.

How a Fake Bank Transfer Email Nearly Fooled Me