ArchivedNo longer active, data collection ran March 2024 to September 2026|9,442 records|3,409 source IPs|138 countriesAbout this archive
Shame on you, stupid spammers..Sh4meful  DMARC Spoof Detection

About this archive

Collection ran March 2024 through September 2026. This site is now a frozen snapshot.

Sh4meful was a public view into a private DMARC corpus. Every entry was an IP address that failed both SPF and DKIM authentication for a domain under my administration, drawn from DMARC aggregate reports and enriched with geolocation, network ownership and reverse DNS. It ran continuously for 31 months and then stopped, having done what it set out to do.

Ran for
31
months of continuous collection
Authentication records
9,442
each one a failed SPF and DKIM check
Messages represented
16,064
summed across DMARC aggregate reports
Source IPs
3,409
distinct sending addresses
Networks
1,350
distinct owning networks
Countries
138
by GeoIP of the sending address
Aggregate reports
2,318
parsed from reporting providers

What is still here

The pages are exactly as the application last rendered them: the country, network, owner and IP intelligence pages, the activity charts, the choropleth map, and the written analysis on the blog. Nothing is recalculated and nothing will change again.

What is gone

Search, sorting by querystring, pagination and the MCP endpoint all belonged to the running application. Tables still sort and filter, but in your browser rather than on a server. Any address that used to take a query parameter now lands on a short notice instead of an error.

Where the work continues

The thinking behind this dataset feeds DmarcSignal, a free DMARC monitoring service. The rest of my work is at Christian Ricci, LLC.


Snapshot generated 2026-09-22.