DMARC Spoof Detection, Failed Authentications
About this Project
โถSh4meful tracks IP addresses caught sending unauthorized email, detected through DMARC report analysis across millions of authentication records.
Every entry here is an IP address that failed both SPF and DKIM authentication checks for domains I monitor. In most cases, that means someone (or something) used the domain name without permission; a signature pattern of email spoofing, phishing, spam, and other abusive mail activity.
The dataset is drawn from DMARC aggregate reports and represents a fraction of a larger corpus spanning millions of messages. Each record shows what failed and where: the source IP, its network, its geography, and limited metadata from the authentication event. Determining intent, whether a failure is hostile or incidental, requires context beyond what DMARC provides, but the patterns speak clearly enough at volume.
Not every failure is malicious. Some legitimate services (email security gateways, spam filters, phishing analysis platforms) break authentication as a side effect of message inspection or forwarding. I track these confounders separately and hide them by default, though they remain available for review. Much of that traffic is benign infrastructure noise. Some isn't.
Elements of this dataset and supporting models will eventually be open-sourced on GitHub. (More)
8,275
2,513
973
13,851
Failures
Showing 1-10 of 8,275 failures, affecting 13,851 messages| Date โผ | Source IP | Country | City | Network | Messages |
|---|---|---|---|---|---|
| 5/31/2026 | KZ Kazakhstan | Pavlodar | 2 | ||
| 5/31/2026 | KG Kyrgyzstan | 6 | |||
| 5/31/2026 | PK Pakistan | Faisalabad | 1 | ||
| 5/30/2026 | RU Russia | Ulan-Ude | 9 | ||
| 5/30/2026 | KG Kyrgyzstan | Bishkek | 6 | ||
| 5/30/2026 | PH Philippines | Angeles City | 1 | ||
| 5/30/2026 | IN India | Guwahati | 1 | ||
| 5/30/2026 | RU Russia | Nizhniy Novgorod | 1 | ||
| 5/30/2026 | VN Vietnam | Hanoi | 1 | ||
| 5/29/2026 | JP Japan | 1 |
DMARC Activity
Most Active Networks by Spoof Volume (30 days)
Top networks by failed message volume over the last 30 days.
KYRGYZTELECOM_ADSL_PPPOE
RIPE-ERX-158-94-0-0
spaceshipnetworks
CHITATTK-NET
FRTR-LEGACY-FTR13
LT-HOSTBALTIC-10
OTS549865
ALEXHOST
RIPE
SAKURA-NET
GOOGL-2
GOOGLE-IPV6
ERTH-SPB-PPPOE-15-NET
OMEGATECH
Most Active IPs by Spoof Volume (30 days)
Top IP addresses by failed message volume over the last 30 days.
IP Intelligence Report for 176.104.136.223
IP Intelligence Report for 62.60.130.125
IP Intelligence Report for 50.127.181.82
IP Intelligence Report for 158.94.210.212
IP Intelligence Report for 141.98.10.42
IP Intelligence Report for 80.72.177.69
IP Intelligence Report for 31.149.213.145
IP Intelligence Report for 212.241.24.232
IP Intelligence Report for 45.131.64.143
IP Intelligence Report for 151.3.217.133
IP Intelligence Report for 188.187.110.66
IP Intelligence Report for 178.16.52.253
IP Intelligence Report for 153.125.138.166
IP Intelligence Report for 219.128.0.2
IP Intelligence Report for 194.102.104.50
IP Intelligence Report for 202.53.164.26
IP Intelligence Report for 103.79.247.224
IP Intelligence Report for 158.94.210.93
IP Intelligence Report for 181.115.171.151
IP Intelligence Report for 95.78.169.171
Top Threat Countries
- China - Email Spoofing Analysis
- United States - Email Spoofing Analysis
- Russia - Email Spoofing Analysis
- Germany - Email Spoofing Analysis
- India - Email Spoofing Analysis
- United Kingdom - Email Spoofing Analysis
- France - Email Spoofing Analysis
- Brazil - Email Spoofing Analysis
- Japan - Email Spoofing Analysis
- Canada - Email Spoofing Analysis
- Netherlands - Email Spoofing Analysis
- Australia - Email Spoofing Analysis
- South Korea - Email Spoofing Analysis
- Italy - Email Spoofing Analysis
- Spain - Email Spoofing Analysis
- Turkey - Email Spoofing Analysis
- Poland - Email Spoofing Analysis
- Ukraine - Email Spoofing Analysis
- Mexico - Email Spoofing Analysis
- Argentina - Email Spoofing Analysis