GCE-hosted spoofing toolkit sending email with header_from spoofed to fuzweb.com, DKIM absent, SPF a ...
show moreGCE-hosted spoofing toolkit sending email with header_from spoofed to fuzweb.com, DKIM absent, SPF auth on RFC1918 (10.88.0.x Docker bridge), rejected by Google with local_policy 550-5.7.1 β observed in DMARC aggregate report for May 5, 2026 UTC.
show less
Spoofed-sender abuse on GCP europe-west4 (AS396982).
er Google's own DMARC aggregate report:
- DKI ...
show moreSpoofed-sender abuse on GCP europe-west4 (AS396982).
er Google's own DMARC aggregate report:
- DKIM: no signature
- SPF auth domain: 10.88.0.4 (RFC1918 β Docker bridge IP leaking through)
- envelope_from: empty
- Disposition: quarantine
- Reason: local_policy "Sender requirement failed: 550-5.7.1"
show less
DMARC-failing mail spoofing fuzweb.com header_from. SPF authenticates against private RFC1918 10.88. ...
show moreDMARC-failing mail spoofing fuzweb.com header_from. SPF authenticates against private RFC1918 10.88.0.3 (Docker bridge egress without envelope rewrite β toolkit fingerprint). DKIM completely absent. Google's own infrastructure rejects with SMTP 550-5.7.1 (REASON local_policy in DMARC record).
show less
DMARC quarantine: spoofing fuzweb.com From: header, no DKIM, empty envelope. Same toolkit signature ...
show moreDMARC quarantine: spoofing fuzweb.com From: header, no DKIM, empty envelope. Same toolkit signature as 176.100.36.92 (also AS58087) from 24h earlier.
show less
DMARC quarantine: spoofing fuzweb.com From: header, no DKIM, empty envelope. 4 attempts in 24h, all ...
show moreDMARC quarantine: spoofing fuzweb.com From: header, no DKIM, empty envelope. 4 attempts in 24h, all rejected. Brand-impersonation phishing toolkit.
show less
Observed 2026-04-23 sending email forging From: fuzweb.com (domain spoofing). DKIM fail (no signatur ...
show moreObserved 2026-04-23 sending email forging From: fuzweb.com (domain spoofing). DKIM fail (no signature), SPF softfail, header_from=fuzweb.com. Reported by Google in DMARC aggregate report; correctly quarantined by our p=quarantine policy.
Netblock 45.138.16.0/24 belongs to AS210558 (1337 Services GmbH), known bulletproof hosting. Same operator as 185.241.208.173 (reported separately on 2026-04-22) β IP rotation within same allocation to evade enforcement. Subnet hosts multiple Tor exit nodes and brand-impersonating hostnames (powered.by.amazon.com, .ebay.com, mail.adobesiqn.com, coinbase.websupport.ltd).
show less
DMARC-documented sender spoofing for domain fuzweb.com. Event: Apr 20 2026. DKIM fail + SPF softfail ...
show moreDMARC-documented sender spoofing for domain fuzweb.com. Event: Apr 20 2026. DKIM fail + SPF softfail. Envelope from forged as @fuzweb.com. Host: Bell Canada BACOM (AS577), Ottawa. First non-cloud/non-hosting IP to attempt spoofing of this domain (consumer/business ISP IP). Abuse report sent to [email protected] on Apr 22 β awaiting response. Quarantined by Google thanks to DMARC p=quarantine policy.
show less
DMARC-documented sender spoofing for domain fuzweb.com. Event: Apr 10-11 2026. DKIM fail + SPF softf ...
show moreDMARC-documented sender spoofing for domain fuzweb.com. Event: Apr 10-11 2026. DKIM fail + SPF softfail. Envelope from forged as @fuzweb.com. Host: DigitalOcean, Singapore range (128.199.0.0/16). Abuse report sent to DigitalOcean on Apr 22 β awaiting response. Quarantined by Google thanks to DMARC p=quarantine policy.
show less
DMARC-documented sender spoofing for domain fuzweb.com. Event: Apr 8 2026. DKIM fail + SPF softfail. ...
show moreDMARC-documented sender spoofing for domain fuzweb.com. Event: Apr 8 2026. DKIM fail + SPF softfail. Envelope from forged as @fuzweb.com. Host: Spinservers (AS8100). Abuse report filed via Spinservers official form β ticket #175448 opened, reseller escalation in progress. Quarantined by Google thanks to DMARC p=quarantine policy.
show less
DMARC-documented sender spoofing for domain fuzweb.com. Events: Apr 2 (DMARC p=none, delivered) and ...
show moreDMARC-documented sender spoofing for domain fuzweb.com. Events: Apr 2 (DMARC p=none, delivered) and Apr 9 2026 (DMARC p=quarantine, blocked). DKIM fail + SPF softfail. Envelope from forged as @fuzweb.com. Host: 1337 Services GmbH (AS210558) bulletproof hosting. IP listed on Spamhaus ZEN, Sender Score, Abusix, MAILSPIKE, UCEPROTECT L1/L2/L3 (12+ blocklists). Abuse report sent to [email protected] on Apr 22 β no response. Recurring attacker.
show less
Email SpamSpoofing
By clicking βAccept allβ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.