DMARC Spoof Detection, Failed Authentications
About this Project
▼Sh4meful tracks IP addresses caught sending unauthorized email, detected through DMARC report analysis across millions of authentication records.
Every entry here is an IP address that failed both SPF and DKIM authentication checks for domains I monitor. In most cases, that means someone (or something) used the domain name without permission; a signature pattern of email spoofing, phishing, spam, and other abusive mail activity.
The dataset is drawn from DMARC aggregate reports and represents a fraction of a larger corpus spanning millions of messages. Each record shows what failed and where: the source IP, its network, its geography, and limited metadata from the authentication event. Determining intent, whether a failure is hostile or incidental, requires context beyond what DMARC provides, but the patterns speak clearly enough at volume.
Not every failure is malicious. Some legitimate services (email security gateways, spam filters, phishing analysis platforms) break authentication as a side effect of message inspection or forwarding. I track these confounders separately and hide them by default, though they remain available for review. Much of that traffic is benign infrastructure noise. Some isn't.
Elements of this dataset and supporting models will eventually be open-sourced on GitHub. (More)
9,323
3,344
1,317
15,778
Failures
Showing 1-10 of 9,323 failures, affecting 15,778 messages| Date ▼ | Source IP | Country | City | Network | Messages |
|---|---|---|---|---|---|
| 8/16/2026 | GB United Kingdom | 1 | |||
| 8/15/2026 | BO Bolivia | Santa Cruz | 1 | ||
| 8/15/2026 | US United States | Visalia | 1 | ||
| 8/15/2026 | BG Bulgaria | Sofia | 1 | ||
| 8/14/2026 | ES Spain | Barcelona | 1 | ||
| 8/13/2026 | BO Bolivia | Santa Cruz | 1 | ||
| 8/13/2026 | US United States | Visalia | 2 | ||
| 8/13/2026 | BR Brazil | Vitória | 24 | ||
| 8/13/2026 | ES Spain | Barcelona | 1 | ||
| 8/12/2026 | CO Colombia | Armenia | 24 |
DMARC Activity
Most Active Networks by Spoof Volume (30 days)
Top networks by failed message volume over the last 30 days.
UZTELECOM
UNE EPM TELECOMUNICACIONES S.A.
Claro NXT Telecomunicacoes Ltda
VIETTEL-VN
CMNET
INC-NET
WEBSURFONLINE-IN
GPON_FTTH_SERVICES
BBN-BD
GOOGL-2
KAPPA-IN
GRAPESC
CABLE-1
BROADBAND-IPOE-STATIC-CUSTOMERS
HURRICANE-6
Most Active IPs by Spoof Volume (30 days)
Top IP addresses by failed message volume over the last 30 days.
IP Intelligence Report for 187.36.152.78
IP Intelligence Report for 181.137.106.39
IP Intelligence Report for 102.69.144.30
IP Intelligence Report for 109.104.228.49
IP Intelligence Report for 103.6.185.78
IP Intelligence Report for 168.194.102.105
IP Intelligence Report for 96.71.227.169
IP Intelligence Report for 105.21.41.166
IP Intelligence Report for 168.245.17.70
IP Intelligence Report for 103.92.219.82
IP Intelligence Report for 197.157.195.105
IP Intelligence Report for 103.118.46.5
IP Intelligence Report for 102.0.30.22
IP Intelligence Report for 196.41.47.226
IP Intelligence Report for 177.152.106.60
IP Intelligence Report for 121.56.214.240
IP Intelligence Report for 95.107.170.87
IP Intelligence Report for 175.208.226.192
IP Intelligence Report for 185.145.184.255
IP Intelligence Report for 179.51.187.214
Top Threat Countries
- China - Email Spoofing Analysis
- United States - Email Spoofing Analysis
- Russia - Email Spoofing Analysis
- Germany - Email Spoofing Analysis
- India - Email Spoofing Analysis
- United Kingdom - Email Spoofing Analysis
- France - Email Spoofing Analysis
- Brazil - Email Spoofing Analysis
- Japan - Email Spoofing Analysis
- Canada - Email Spoofing Analysis
- Netherlands - Email Spoofing Analysis
- Australia - Email Spoofing Analysis
- South Korea - Email Spoofing Analysis
- Italy - Email Spoofing Analysis
- Spain - Email Spoofing Analysis
- Turkey - Email Spoofing Analysis
- Poland - Email Spoofing Analysis
- Ukraine - Email Spoofing Analysis
- Mexico - Email Spoofing Analysis
- Argentina - Email Spoofing Analysis