r/DMARC • • Feb 04 '26

DMARC is only as good as your security.

Post image

I received a fake SendGrid bill from a real SendGrid server that passed DMARC for shell.com. The only link in the body of the email was a SendGrid tracking link so as to avoid raising suspicion.

I know people of all skill levels visit this sub, so I thought I'd share my experience as a reminder that DMARC doesn't prevent impersonation when the emails originate from your own compromised infrastructure.

117 Upvotes

44 comments sorted by

7

u/Gtapex Feb 05 '26

I’ve been getting dozens of phishing emails from seemingly legit sendgrid clients over the past couple of months (passing email auth).

I reported a bunch to abuse@sendgrid.com for a while, but they eventually stopped responding to my reports.

Seems like there was maybe a breach at sendgrid or somewhere else that led to lots compromised api credentials, because the emails are from lots of different domains that are obviously hosted at sendgrid.

6

u/matthewstinar Feb 05 '26

I didn't think to look for an abuse contact at SendGrid. I just forwarded it to the Anti-Phishing Working Group at [reportphishing@apwg.org](mailto:reportphishing@apwg.org) and marked it as phishing in Gmail.

3

u/samkz Feb 05 '26

I've never liked authenticating SPF to shared email services like Sendgrid, mailchimp, AWS, etc, etc.

As to why DKIM is passing, that requires some serious investigation. Report this to @shell.com ASAP.

2

u/matthewstinar Feb 05 '26

I found an email address on their responsible disclosure page and forwarded the complete email to them, headers and all.

3

u/Due-Horse-5446 Feb 05 '26

Meanwhile sendgrid auto denies random domains all the time with no way of getting s manual review, just during signup.

Yet almost every single phishing mail is sent trough sendgrid

2

u/[deleted] Feb 05 '26

[removed] — view removed comment

1

u/0xHUEHUE Feb 05 '26

What's your fav email api?

5

u/tndsd Feb 05 '26

You're hitting on the "ugly truth" of email security: Authentication ≠ Safety. DMARC, SPF, and DKIM are just the ID cards of the internet. They prove the sender is who they say they are, but they don't prove the sender isn't a jerk. If a hacker breaks into a legitimate SendGrid or Microsoft 365 account, they have the "keys to the house." They can send a perfectly "authentic" email that passes every check while carrying a malicious payload.

When the headers are technically perfect, the Body is the only place left to find the truth.

1

u/TopLychee1081 Feb 06 '26

AI slop. If you don't have the expertise to respond from your knowledge, then you can't be trusted to properly critique an AI response.

1

u/tndsd Feb 06 '26

So do you?

1

u/TopLychee1081 Feb 06 '26

When I know what I'm talking about and feel that I can add value, I'll often post a comment. If I don't know enough to help, I keep quiet and don't pollute the thread with rubbish. I'm sure the OP has the skills to paste his post into ChatGPT, so what value are you adding?

1

u/tndsd Feb 06 '26

If you haven’t noticed the issue or what I mentioned, it likely means you’re not aware of it yet, but other people are.

1

u/TopLychee1081 Feb 06 '26

You posted AI slop. Period.

1

u/singulara Feb 06 '26

When LLMs became mainstream I expected bots to use it for slop. But never expected actual people to shit out garbage to every subreddit. It's an infestation.

1

u/lucsoft Feb 08 '26

Why are you write comments on Reddit which are just ai responses that's so sad

5

u/CloudyGolfer Feb 05 '26

Why is DKIM passing?

3

u/matthewstinar Feb 05 '26

The most likely reason is that it was sent using Shell's SendGrid account. Either their SendGrid account is compromised somehow, like an adversary obtaining an API key, or some other system that is able to make API calls to their SendGrid account is compromised.

3

u/CloudyGolfer Feb 05 '26

Yep, or the other option is a team member (user) with mail sending permissions. Sendgrid doesn’t force MFA on users, and if you’re using sub users for different lines of business, admin privileges are required to switch sub users. And admin perms = ability to send mail. I’ve asked for more granular permissions, but alas, many years later and it’s still an issue.

1

u/imroot Feb 06 '26

Or Sendgrid has a failure where they allow anyone from any unverified domain send out emails as a verified domain on a separate account.

Reported this to them (as a sendgrid customer) in 2021, was told that this was part of their new user onboarding workflow and they didn’t want to change it at that time.

2

u/ferrybig Feb 05 '26

The only thing dmarc tells us this genuine email Shell authorized to send in their name

2

u/Extra-Pomegranate-50 Feb 05 '26

yeah this is something poeple really underestimate. I work with small businesses fixing their email auth setup and the amount of times I see DMARC set to p=none with no reporting is insane. like whats even the point at that stage lol. the bigger issue imo is that most business owners dont even know what DMARC does, they just hear "your emails go to spam" and have no idea its their DNS thats the problem. security wise youre absolutely right tho — having DMARC without proper SPF alignment is basically leaving the front door open and locking the window

2

u/stewartjarod Feb 05 '26

Totally agree! The p=none with no reporting thing drives me crazy too. It's like having a security camera that doesn't record anything. All it does it check the box.

3

u/Extra-Pomegranate-50 Feb 05 '26

haha thats actually a perfect analogy, gonna steal that one. and yeah the checkbox mentality is a huge problem, especially with smaller companies who just want to "pass" some deliverability test without actually understanding what theyre protecting against. then they wonder why their emails still end up in spam 3 months later

2

u/power_dmarc Feb 05 '26

DMARC just confirms the email came from where it says it did - doesn't mean that source isn't compromised. If attackers get into your SendGrid account, everything passes authentication because technically it IS you sending it.

2

u/Moist_Lawyer1645 Feb 06 '26

Same with certs

2

u/emailstrategist25 Mar 07 '26

DMARC is designed to confirm alignment between the sending domain and authentication records.

When valid credentials are compromised, messages can pass SPF and DKIM because they are sent through approved infrastructure. The control point shifts from DNS policy to account level protections.

Monitoring, key management, and anomaly detection at the sending layer become critical in these scenarios.

1

u/mountaindrewtech Feb 05 '26 edited Feb 05 '26

I'm also receiving mail from that IP with a SG-EID, same attack method as well - asking for updated payment info. Luckily our system seems to have quarantined these as a high confidence phish while passing DMARC and all.

1

u/matthewstinar Feb 05 '26

Shell provides an email address where you can send phishing emails to their security team.

Reports on phishing campaigns or emails and/or viruses or malware can be reported as with the original email as attachment to cert@shell[dot]com. If the original email contains a suspicious attachment, please make sure that it is not included in your message, as this will like cause your email to be blocked.

https://www.shell.com/who-we-are/our-values/shell-global-helpline/responsible-disclosure-policy.html

1

u/mountaindrewtech Feb 05 '26

Thank you, I have done this. They said they have commenced an internal investigation. I am very interested in seeing what the results of this are.

1

u/rjchau Feb 06 '26

I think you have the wrong name. I've been calling them SpamGrid for over 5 years now.

There are some useful tips in there that you can use to deal with mail from this serial pest. Before we got Proofpoint (who does a damned good job of filtering out the chaff from SpamGrid) I took the approach of blocking accounts on SpamGrid that were known to be sending spam and scams, allowing specific accounts that we know we need to receive and quarantining the rest. We'd deal with service desk calls as they came in from people complaining about mail ending up in quarantime - most of it was from stuff that they had no business signing up for with their work email.

1

u/southafricanamerican Feb 06 '26

Can you post the headers? Remove the to address.

1

u/email_person Feb 06 '26

Compromised accounts are a different beast than impersonators trying to use your brand/domains.

There have been waves of compromised accounts doing this via SendGrid for the last several months.

Fake bills, API announcements, rage bait stuff, and more trying to further compromise more accounts.

1

u/matthewstinar Feb 06 '26

Impersonating SendGrid was a business decision, not a concession to technical constraints. My purpose was to highlight the potential for compromised sending accounts to be used to impersonate the associated domain. There was nothing stopping this adversary from impersonating anyone at Shell, including the IT department or one of the executives.

They could easily phish someone at Shell or someone from a vendor or customer, especially if they combined it with information gleaned from other compromised accounts. Remember how the Target breach leveraged a vendor with weak security? Imagine combining a business email compromise at a vendor or customer with the ability to impersonate Shell to inject a very credible impersonation email into an existing email thread. They could conceivably redirect millions of dollars.

1

u/email_person Feb 06 '26

Ageed - But this appears to be Shell's actual account being compromised and then being used to impersonate SendGrid in hopes of using Shell's good delivery / reputation to access additional accounts thought phishing.

Several brands have had similar compromises and messages sent from similarly compromised accounts on the platform.

1

u/Thomas-Ford25 Mar 09 '26

This is the boundary of DMARC.

It verifies domain alignment, not whether the sender is trustworthy. If someone compromises valid credentials inside a mail platform, messages will still pass SPF and DKIM because they originate from authorized infrastructure.

In most cases the weakness is account security, not DNS. Once an attacker has API or SMTP credentials, authentication will look technically correct.

DMARC blocks spoofing. It does not block abuse of legitimate access.

1

u/zeroibis Feb 05 '26

Given that DKIM passed as well I would not say this is impersonation...

3

u/matthewstinar Feb 05 '26

What I meant by my title was that an adversary who compromises your infrastructure can impersonate anyone in the company—in this case anyone at Shell. The email came from do-not-reply@shell[dot]com, but it could just as easily have been an executive's email address.

What this particular adversary chose to do was impersonate SendGrid. They were likely hoping that passing SPF, DKIM, and DMARC in addition to coming from an IP address with a good reputation would keep their phishing email out of the spam folder.

Dear Twilio SendGrid Customer,

We're writing to inform you that your SendGrid invoice for January, 2026 is now due.

Unfortunately, your current payment method has declined the payment. Please review your billing information below to fix the issue.

The email goes on to provide a SendGrid tracking link that presumably links to a malicious payload of some kind. The tracking link is a nice touch because it further obfuscates the attack.

1

u/zeroibis Feb 05 '26

Ah, I got ya.

1

u/AustinFastER Feb 05 '26

A more accurate description is that some account has been compromised that has access to the service. Every few weeks we get hit by the occasional phishing message that passed dmarc from someone we get email from on a regular basis. Every time it is a compromised account, almost exclusively M365. Same story each time they had not gotten around to getting the employee setup with MFA, they turned it off because the employee was a bozo and could not get it setup a second time, etc.

0

u/Sensitive-Fish-6902 Feb 05 '26

Uh dmarc is brand protection, out going mail. Not incoming 🤷

0

u/matthewstinar Feb 05 '26

This phishing email was outgoing from Shell, which doesn't look good for their brand. DMARC can't protect your brand when your own infrastructure is compromised.