TL;DR A message reached an industrial equipment maker carrying a machine-generated subject line and two large clickable banner images. Both images pointed at a domain registered roughly forty-five minutes before the email was sent. The body was a Portuguese newsletter opt-in confirmation for Ipea, a Brazilian government research institute, and its visible confirmation link genuinely resolved to the real Ipea site. Authentication passed, but for a small online retailer whose Amazon SES sending identity was being used by someone else. DMARC returned a permerror, so no alignment check ever questioned the brand mismatch.
Severity: High Brand Impersonation Authenticated Sender Abuse Newly Registered Domain Bulk Mail Platform Abuse MITRE: T1566.002 MITRE: T1583.001 MITRE: T1204.001

The subject line read like something a system had written rather than a person: a bracketed external-mail tag, a bracketed notification code, a bracketed message-ID string, and nowhere in it a sentence a human would compose. It landed in mailboxes at an industrial equipment maker, including one in the accounts-payable function. It passed SPF. It passed DKIM twice.

Two large banner images sat at the top of the message, both clickable, both pointing at the same destination. WHOIS on that destination put its registration roughly forty-five minutes before this message was sent.

Below the images the body switched to Portuguese: a newsletter double opt-in confirmation, telling the reader they had requested email updates from Ipea, the Brazilian government's applied economics research agency, and asking them to confirm the subscription. The visible confirmation link resolved to the real Ipea site. Not a lookalike, not a typosquat, not a homoglyph. The genuine government domain.

Real Authentication, Borrowed From a Bystander

The headers hold up under inspection. SPF passed. DKIM passed with valid signatures for two separate domains: the domain in the sender address, and Amazon's own bulk-mail signing domain. The sending address itself was a long randomized string in the local part, styled to look like an automated quarantine notice, sitting on a randomly generated subdomain beneath a real apex domain.

That apex domain belongs to a small online retailer. It had been registered for about a year when this message went out, sat behind a standard privacy proxy, and mapped to an unremarkable consumer storefront with no relationship to Brazil, to public-sector research, or to the recipient. Its own published sending policy lists Amazon's bulk-mail service, which is exactly why every authentication check came back clean.

Nothing in the record suggests the retailer ran this campaign. What the campaign acquired was the retailer's sending identity on a large bulk-mail platform, and with it the platform's infrastructure, its signing keys, and a year of quiet, uncontroversial reputation. No domain to register, no IP space to warm, no history to build.

The one control that should have objected did not get the chance. DMARC on the visible From domain returned a permerror, meaning the receiving side found a record it could not evaluate. A permerror is not a pass and it is not a fail, it is an absence: no policy applied, no alignment check performed. Under RFC 7489 the whole purpose of that check is to ask whether the domain a reader sees matches the domain that authenticated. Here, nothing ever asked why a Brazilian government newsletter arrived signed by a consumer retailer. Broken records are common and largely invisible without DMARC management and monitoring watching the reports come back.

Forty-Five Minutes of Domain History

The destination behind both banner images was a generically named domain with no content history, no category assignment, and no reputation of any kind. It could not have had one. It had existed for less than an hour.

That is the part reputation systems structurally cannot price. Blocklists, category feeds, and domain-reputation scores are all built on observed behavior, and observation takes time. A domain registered in the same hour as the send has produced nothing to observe, so it arrives as neutral rather than suspicious. The 2024 Verizon Data Breach Investigations Report puts the median time to click a phishing link at 21 seconds. Reputation data accumulates over days and weeks. Forty-five minutes falls on the wrong side of both numbers, which is why domain age belongs in the verdict alongside advanced malware and URL attack protection rather than after it.

One precision note: both images were embedded in the message and carried the same link target, but what they depicted is not recorded. The verified facts are where they pointed and when that destination came into existence.

See Your Risk: Calculate how many threats your SEG is missing

The Genuine Link Was the Point

The visible text link, the one the Portuguese copy actually invited the reader to click, went to a real subscription activation endpoint on the institute's genuine government site. It was live and it was authentic.

That is not carelessness on the attacker's side, it is construction. The link a cautious recipient inspects is the one written into the visible call to action. Hover it, copy it, paste it into a scanner, and it comes back as a government domain, which retroactively validates everything above it. Meanwhile the only objects leading somewhere new were the images, which most people click as banners and few inspect at all.

Stack the layers and the message is almost entirely composed of things security tooling likes. Valid SPF. Valid DKIM. Reputable bulk-mail infrastructure. A year-old sending domain. A real government URL in the body. One element was unfamiliar, and it was unfamiliar because it was forty-five minutes old.

Mapping to MITRE ATT&CK

  • T1566.002 Phishing: Spearphishing Link covers the delivery. The payload is a link target, carried by embedded images rather than by anchor text.
  • T1583.001 Acquire Infrastructure: Domains covers the redirect destination, registered immediately before use so that no reputation could attach to it.
  • T1204.001 User Execution: Malicious Link covers the required next step, since nothing happens until a recipient clicks one of the banners.
  • The abuse of a third party's bulk-mail sending identity is deliberately left unmapped. The evidence shows the identity and its reputation being used, and does not establish how that access was obtained.

Indicators of Compromise

TypeIndicatorContext
Domainmessagekeeping[.]comClick destination behind both embedded banner images. WHOIS registration roughly forty-five minutes before the message was sent
Domainbestwearablebreastpump[.]comAuthenticating sending domain. An unrelated online retailer's own domain, abused as a sending identity, with no affiliation to the impersonated institute
Emailquarantine-east946-...[@]AUgvqpeCN.bestwearablebreastpump[.]comSender address. Randomized quarantine-style local part on a randomly generated bulk-mail subdomain
IP54[.]240[.]8[.]24Amazon SES sending IP
URLhxxps://www[.]ipea[.]gov[.]br/portal/component/phocaemail/activate/...Real, live newsletter activation endpoint on the genuine government domain, embedded to lend the lure legitimacy
Subject[EXTERNAL] [Notification-677EVYNLP1]: MessageID:[G1SSI4TOT-IDISTPK4QM]System-notification disguise: bracketed codes only, no human-readable subject
Auth patternSPF pass, DKIM pass on sending domain and on the bulk-mail provider domain, DMARC permerror on header FromClean authentication with no enforceable alignment check

Where the Catch Came From

This record carries no confidence score. The determination came from the combination of signals sitting inside the message itself: an authenticated sender with no plausible relationship to the brand in the body, a bulk-mail identity that did not fit the pretext, a DMARC record that could not be evaluated, and a link destination with no past. The incident was resolved as phishing automatically, without waiting for a third party to categorize the new domain.

That ordering matters. A pipeline that waits for reputation to catch up is, by definition, always behind a same-hour registration. Reading relationship, pretext, and infrastructure freshness together is the terrain Themis, our Adaptive AI analyst, is built for, and it is the only view in which this message looks wrong at the moment it arrives rather than days later.

The Takeaway

Three habits follow from this one.

Treat a DMARC permerror as an enforcement gap rather than a neutral result. It reads as a header-dump technicality and functions as a disabled control, and the domains most likely to publish a broken record are the ones nobody is monitoring.

Put domain age in the verdict, not in the post-incident report. Registration timing was the single strongest signal in this message and it was available before delivery, not after.

And stop reading a legitimate link as evidence of a legitimate message. An authentic destination in the visible copy says nothing about the objects around it, and here it was the reason the rest of the message was believable. CISA's phishing guidance (https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one) and NIST's definition of phishing (https://csrc.nist.gov/glossary/term/phishing) are useful anchors when a message passes every mechanical check and still does not fit.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
A Pixel-Perfect Sephora Delivery Notice Shows Why Email Authentication Alone Can't Protect YouA fully authenticated Sephora delivery notification passed SPF, DKIM, and DMARC with perfect scores.
Adobe Sign Impersonation Misspelled Its Own Display NameA contract-signing lure aimed at a multinational cinema chain's most senior executive passed SPF, DKIM, and DMARC through Amazon SES.
The Procore Footer Was Real. The Document Was Not.Every link scanner called the Procore and ExxonMobil URLs clean.
The B2B Content Marketing Email That Borrowed a Brand, a Relay Allow-List, and a Security Vendor's Own URL WrapperA polished B2B research report offer used SelectHub branding, passed through an allow-listed mail relay at SCL -1.
The Email That Passed Every Security Check (Because Adobe Sent It)A phishing campaign targeting school district staff used Adobe's own sending infrastructure, real DKIM signatures.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.