TL;DR An attacker set a Zoom account name to a scam script, triggered a sign-in code email, and let Zoom render and DKIM-sign the lure itself. The result passed DKIM and DMARC because Zoom genuinely signed it. They then resent the authenticated message through a brand-new privacy-protected domain to a company COO. The only payload was a fabricated $986.37 PayPal charge and a callback number, a TOAD scam with no malicious link or attachment for filters to catch. It shows why a valid signature proves origin, not intent, and why behavioral analysis must sit in front of the inbox.
Severity: High Brand-Impersonation Callback-Phishing Social-Engineering MITRE: T1566 MITRE: T1656 MITRE: T1036.005

A chief operating officer opened an email that was, by every cryptographic measure, genuinely from Zoom. DKIM verified against zoom.us. DMARC passed under a p=reject policy. The message carried Zoom's real logo, footer address, and support line. It also told him his PayPal account was about to be auto-debited $986.37 for a monthly renewal, and that if this was not him, he should call +1-805-600-1572. That phone number was the entire attack.

This is the case that breaks the "just check for a valid signature" heuristic. The signature was not forged. Zoom signed the lure itself.

How Zoom Came to Sign a Scam

Zoom's sign-in verification email personalizes its greeting: "Hi {name},". The name is pulled straight from the account profile. So the attacker created a Zoom account and set its name field to an entire social-engineering script: "Dear Customer, Your PayPal will be auto debited with $986.37 for your Zoom active monthly renewal. Not You? Call +1-805-600-1572,". Then they triggered a sign-in.

Zoom did exactly what it was built to do. It rendered that string into the greeting, wrapped it in the standard sign-in-code template (a six-digit code, a fake "unusual sign-in from Utah" activity block, the real "If this wasn't you" link back to us05web.zoom.us), and signed the finished message with its production DKIM key (s=sg; d=zoom.us). The body hash in the DKIM-Signature header matches the delivered content byte for byte, which is precisely why the signature verifies. Nothing was altered after signing. The malicious content was present before Zoom ever put its key to it.

DKIM proves two things: that the message came from a zoom.us key holder, and that it was not modified in transit. It proves nothing about whether the content is safe. When an attacker can inject text into a field that the brand faithfully renders and signs, a valid signature stops being evidence of trust and becomes a delivery advantage.

Then They Mailed It to Someone Else

The genuine Zoom message was addressed to the attacker's own account. To weaponize it against a target, they resent it. The headers give up the tell: Resent-From, Resent-To, and Resent-Message-ID, with an envelope return-path of receipts+acct_1@mailjetstream[.]com. That domain was registered on 2025-06-16, sits behind privacy protection and Cloudflare name servers, and has no relationship to Zoom's mail platform. It has since been suspended.

From there the message hopped through a self-hosted relay and a throwaway Microsoft 365 tenant before landing in the inbox of the COO at an enterprise software company. Along the way the envelope produced SPF=None, because a days-old throwaway domain publishes no SPF record. Here is the part defenders miss: it did not matter. DMARC only requires one aligned authentication mechanism, and the Zoom DKIM signature carried alignment on its own. DMARC passed. SPF being absent is a footnote when DKIM has already done the job, and any allow-list rule for "trusted sender zoom.us" waves the message straight through.

The Payload Is a Phone Number

There is no malicious link in this email. The only clickable destination, the "here" link, resolves to a real us05web.zoom.us URL. There is no attachment. URL sandboxes, attachment detonation, and domain-reputation engines have nothing to bite on, because every technical artifact points at Zoom.

The attack lives entirely in the text: a fabricated $986.37 charge, manufactured urgency ("auto debited," "Not You?"), and an unfamiliar callback number. This is a telephone-oriented attack delivery, or TOAD. The goal is to move the victim off email and onto a phone call with a live operator who will offer to "cancel" the charge, which in practice means capturing card details, opening a remote-access session, or steering a payment. Verizon's 2026 Data Breach Investigations Report draws on gateway telemetry from a contributing vendor and puts attempts to get the victim to call the attacker at a median of roughly 5% of the attacks email security gateways block, small in count but disproportionately effective because it defeats content filtering by simply not placing the payload in content a filter can read. The FBI's 2024 IC3 report continues to rank this family of social-engineering fraud among the costliest by reported dollar loss.

It also leans on two brands at once. The message impersonates a Zoom billing notice while invoking PayPal as the payment method, a masquerade MITRE ATT&CK tracks as impersonation and masquerading via a legitimate name, stacked on core phishing.

See Your Risk: Calculate how many threats your SEG is missing

Reading the Signals a Signature Cannot

A control that trusts the DKIM pass and stops there delivers this straight to the COO. Our Adaptive AI treats authentication as one input among many, not a verdict.

Several signals fire at once here. A sign-in verification email does not talk about PayPal auto-debits, so the billing language is a content-context mismatch. An unfamiliar phone number colocated with a fear-based billing claim is a textbook callback tell. The greeting is a generic "Dear Customer" with no account identifier, which is odd for a message Zoom supposedly generated for one specific account. And the Resent headers, plus an envelope-from on a domain registered days earlier with no tie to Zoom's real sending infrastructure, describe a path a legitimate Zoom notification would never take. Weighed together, the message is plainly hostile even though each brand asset and the signature are authentic.

This is also why callback attacks reward vishing awareness that survives contact with a convincing email. The technical layer did its job and still passed a lie. IRONSCALES sees the roughly 67.5 phishing emails per 100 mailboxes that gateways miss every month, and authenticated-but-weaponized brand mail like this is a growing share of them. Verizon ties 62% of breaches to the human element for exactly this reason: when the infrastructure checks out, the person is the last control standing.

Indicators of Compromise

TypeIndicatorContext
Callback number+1-805-600-1572Attacker-controlled TOAD callback number injected into the greeting
Relay / envelope domainmailjetstream[.]comResend domain, registered 2025-06-16, privacy-protected, since suspended
Envelope senderreceipts+acct_1@mailjetstream[.]comReturn-path used to relay the authenticated message; SPF=None
Fabricated charge$986.37Fake PayPal auto-debit amount used to manufacture urgency

The Takeaway

A valid DKIM signature answers one question: did this key sign this message. It does not answer whether you should trust what the message says. Any transactional email that echoes a user-controlled field, a name, a note, a memo line, can be turned into signed, authenticated attacker copy. Treat a brand's signature as proof of origin, never as proof of intent, and keep behavioral analysis in front of the inbox so the content gets judged even when the cryptography is flawless.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 36,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
The Partner Invite That Used the Wrong Sending DomainA calendar invite appeared to be from an IRONSCALES employee arranging an ANZ distribution call.
The Benefits Handbook That Came With a Marketing Footer: Homoglyph Domain Meets ESP AbuseAn attacker registered a homoglyph domain (zero replacing the letter O), routed an HR benefits announcement through MailerLite.
Salesforce Pardot Infrastructure Weaponized in Fabricated-Thread CRM Consulting PhishA phishing campaign abused Salesforce Pardot and ExactTarget infrastructure to deliver a fabricated-thread CRM consulting lure with full SPF, DKIM.
Asana Platform Abuse: Authenticated Amazon SES Delivery for a Fake Meta Workspace InviteAn attacker created an Asana workspace and sent an invitation claiming to be from Meta.
The Tooltip Said Coupa. The Link Said Genesis Cleaning. Only One of Them Was Real.A phishing email passed SPF, DKIM, and DMARC for a UAE law firm domain while its CTA button displayed a Coupa procurement portal tooltip but linked to an...

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.