Blog article

10 Sep 20266 minutes read

Author Profile PictureWaseem OsmanDMARC Practitioner

RaaS Attacks: Why Your Email Domain Is the Real Target

Laptop displaying a digital padlock icon surrounded by red warning alert symbols against a dark blue cyber network background

RaaS overview:

  • RaaS affiliates target email domains deliberately
  • Decentralized operators and affiliates make the model resilient to takedowns
  • Domain exposure sits at the edges: acquired business units or regional marketing domains
  • A DMARC policy set to p=reject blocks impersonation before and during an incident
  • First, they can conduct pre-attack reconnaissance using phishing messages that pass basic sender checks.
  • Second, during an active incident, they can impersonate internal communications to delay detection, sending instructions that appear to be from IT, finance, or the executive team.
  • Third, before negotiations even begin, mailbox access lets them read internal financial records, revenue figures, and cyber insurance policy details, then use those specifics to calibrate the ransom demand.
  • Which domains and subdomains are at p=reject today, and which remain at p=none or p=quarantine
  • Whether DMARC aggregate reports are being received and reviewed, who reviews them, and the escalation path for unknown senders
  • Whether the organization can produce a sender inventory listing every platform, tool, and vendor authorized to send email on behalf of each domain
  1. Audit your DMARC policy coverage across all domains. This includes parked domains, legacy domains, and any subdomain used by a third-party sender. A domain at p=none provides reporting but no enforcement. An attacker can send from that domain freely. The goal is p=reject across every domain.
  2. Review your SPF record. An SPF record that includes too many authorized senders, or one that hasn’t been reviewed since the last platform migration, creates two problems: failed authentication for legitimate email and standing access for services that are no longer in use. Review include statements against your current vendor list. Remove senders that are no longer active.
  3. Confirm DKIM signing for all critical outbound email streams. Critical streams include executive communications, finance email, HR notifications, and any system-generated alert that might be spoofed during an incident.
  4. Check subdomain policy explicitly. A p=reject policy on your root domain already covers every subdomain by default. What breaks that coverage is a subdomain that publishes its own DMARC record, which always takes precedence over the root policy.
  5. Review your DMARC aggregate report pipeline. If aggregate reports are sent to a mailbox no one monitors, they provide no operational value. Reports should feed into a platform that flags unknown or unauthorized senders. During an active RaaS incident, this level of domain control is the difference between detecting lateral movement through email and missing it entirely.

Share

Get our latest blogs delivered to your inbox each month

Leave a reply

Your email address will not be published. Required fields are marked *

Useful Tools

DNS Lookup
Free toolNo sign-up

DNS Lookup

Use Sendmarc's DNS lookup tool to instantly analyze domain records, verify configurations, and detect DNS issues for better performance.

Email Header Analyzer
Free toolNo sign-up

Email Header Analyzer

Quickly analyze email headers with Sendmarc’s email header analyzer. Check SPF, DKIM, and DMARC results, detect phishing, and improve email deliverability.

Domain Checker
Free toolNo sign-up

Domain Checker

Use the Sendmarc domain checker to test against malicious use - free, no sign-up required, with results in under a minute.