TL;DR A phish impersonating a known contact reached a staffing firm from an unrelated hotmail[.]co[.]nz address. On the first hop it failed every authentication check. A compromised mailbox carrying a malicious auto-forwarding rule then resent the message through Microsoft, and the re-signed copy passed SPF, DKIM, DMARC, and ARC. The bare one-line lure pointed to a recently registered throwaway domain. The inbox rule effectively laundered failing authentication into passing authentication, defeating any control that trusts a clean auth stamp as proof of intent.
Severity: High Credential Phishing Account Takeover Display Name Impersonation MITRE: T1566 MITRE: T1114 MITRE: T1078

Email authentication was supposed to end this argument. If a message passes SPF, DKIM, and DMARC, the reasoning goes, then the sender is who they claim to be and the mail can be trusted. A recent case at a staffing and professional services firm shows how a single compromised mailbox turns that reasoning into a liability. The attacker did not defeat authentication. The attacker made a failing phish pass, on purpose, by bouncing it through a malicious inbox rule.

The message that got better on the way in

The lure itself was almost aggressively minimal. It carried the exact display name of a known contact, the kind of familiar name that lands in an inbox and gets a reflexive click. The body was a single word, "photos," followed by a link to a throwaway domain. No branding, no urgency script, no attachment. Just enough social proof in the sender name to make one line feel normal.

Underneath the friendly name, though, the real address was an unrelated consumer webmail account on the hotmail[.]co[.]nz service, with no relationship to the impersonated person or to the recipient's organization. On its first hop, the message looked exactly as suspicious as it was. SPF returned a softfail, there was no DKIM signature at all, and DMARC and composite authentication both failed. Any policy tuned to reject on DMARC failure would have stopped it cold.

That is not the copy that reached the mailbox.

How a mailbox rule launders authentication

Between the original send and final delivery, the message passed through a second Hotmail mailbox that was carrying a malicious auto-resend rule. The header evidence is unambiguous: X-MS-Exchange-Generated-Message-Source listed the Mailbox Rules Agent, the fingerprint of an inbox rule acting on its own rather than a human forwarding a note. This pattern is consistent with a compromised mailbox running an attacker-planted rule that automatically resends inbound mail.

The resend is where the laundering happens. When that intermediary mailbox pushed the message back out through Microsoft's infrastructure, Microsoft re-signed it as outbound mail from a legitimate tenant. The delivered copy passed SPF, passed DKIM for both hotmail[.]co[.]nz and hotmail[.]com, passed DMARC, and carried an ARC chain with cv=pass. A message that started life failing every authentication check arrived wearing a clean bill of health.

Nothing about the intent changed. The impersonation, the throwaway link, and the one-word lure were identical. Only the envelope improved. Authentication verifies the path a message took and the keys that signed it. It says nothing about whether the human, or the rule, that sent it means you harm. A compromised mailbox is a trusted path, so anything it resends inherits that trust.

The link the auth stamp was vouching for

The single link resolved to a recently registered throwaway domain, privacy-protected at registration and resolving to NXDOMAIN by the time of analysis. It was the disposable, use-once infrastructure typical of credential harvesting, staged behind a subdomain and burned quickly. The clean authentication result on the delivered message was, in effect, vouching for a dead-drop domain. That is the whole trick. Signal-only filtering reads the pass and moves on, never asking why a "known contact" is sending a nameless one-word message to a link on a domain nobody has ever seen.

MITRE ATT&CK mapping

  • T1566 Phishing. The initial access attempt is a targeted phishing message using display name impersonation of a trusted contact.
  • T1114 Email Collection. The X-MS-Exchange-Generated-Message-Source Mailbox Rules Agent header points to an auto-forwarding or resend rule operating inside a mailbox, the classic email-rule abuse pattern.
  • T1078 Valid Accounts. The resend depends on a legitimate, compromised mailbox to re-sign the message through Microsoft and launder its authentication result.

Indicators of Compromise

IndicatorTypeNote
wogwz[.]ltufesnxd[.]comDomain (link host)Throwaway subdomain in the one-line lure
ltufesnxd[.]comDomainRecently registered, privacy-protected, resolving to NXDOMAIN
A mailbox on hotmail[.]co[.]nzSender addressUnrelated consumer webmail, first-hop origin
A resending mailbox on hotmail[.]comRelayCarried the malicious auto-resend rule
X-MS-Exchange-Generated-Message-Source: Mailbox Rules AgentHeaderFingerprint of an automated inbox rule resend

Detecting the thing authentication cannot see

The lesson is not that authentication is broken. SPF, DKIM, and DMARC did their jobs, they just answered a different question than the one that mattered. Verizon's 2024 Data Breach Investigations Report still puts phishing behind roughly 15 percent of breaches and the human element in 68 percent of them, and Microsoft's Digital Defense Report 2024 documents how routinely attackers operate from inside trusted mailboxes and identities. CISA's guidance on stopping the phishing attack cycle is blunt that technical controls have to be layered, because any single check can be gamed. An auth pass is one signal, not a verdict.

What flags this message is context that no header can launder. A known display name mapped to an address the organization has never corresponded with. A body of one word pointing at a never-before-seen domain. A resend fingerprint that means a rule, not a person, sent the mail. IRONSCALES applies Adaptive AI through the Themis analyst to weigh sender relationship, content, and behavior together, so a clean authentication stamp does not override the fact that the rest of the message makes no sense. Layered defense against account takeover and native Microsoft 365 augmentation catches the malicious inbox rule and the laundered resend that a DMARC check alone will wave straight through.

The takeaway is uncomfortable but simple. Treat a passing authentication result as necessary, never sufficient. The moment an attacker owns a trusted mailbox, they can make a failing phish pass any check you own. Judge intent, not just the envelope.

See how exposed your mailboxes are to laundered authentication attacks. Get your free email risk assessment.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
The Government Email That Authenticated Itself After TransitA compromised county government M365 account sent a password-protected PDF with the passcode in the body.
Trusted Vendor, Attacker's Form: How a Compromised Lab Account Delivered a Zoho Credential HarvestAn attacker compromised a legitimate contract laboratory email account and used it to deliver a Zoho public form dressed as an onboarding workflow.
Compromised M365 Mailbox Passes DMARC, Fails SPFA scanned-document lure arrived DKIM-signed and DMARC-aligned from a CEO's real mailbox.
When a Trusted University Account Delivers a Same-Day-Registered Phishing LinkA compromised university email account delivered a curiosity-lure reply carrying a same-day-registered domain.
State Farm Spoof Rides a Compromised Law FirmEvery authentication check passed because the email genuinely came from a law office, not State Farm.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.