ArchivedNo longer active, data collection ran March 2024 to September 2026|9,442 records|3,409 source IPs|138 countriesAbout this archive
Shame on you, stupid spammers..DMARC Spoof Detection

DMARC Spoof Detection, Bhutan

ClearClear Filter

This page shows DMARC authentication failures originating from Bhutan. Learn more about this data.

Bhutan accounts for 3 DMARC authentication failures observed by sh4meful over the observation window, sourced from 3 distinct IP addresses across 2 networks. This represents approximately 0.1% of total failure volume observed. Activity from Bhutan has held roughly steady over the last 30 days. The most active source is GELEPHUTHROMDE-BT with 1 failures across 1 IP address.

Failures (Filtered)

3

IPs (Filtered)

3

Networks (Filtered)

2

Messages (Filtered)

10

Top Networks in Bhutan

Ten most active networks sourcing DMARC failures from Bhutan:

NetworkOrganizationFailuresDistinct IPsTop City
GELEPHUTHROMDE-BTโ€”11โ€”
TYANGTSEDZ-NETโ€”22โ€”

GELEPHUTHROMDE-BT and TYANGTSEDZ-NET together account for 100% of failure volume from this country. Concentration in a small number of networks suggests targeted infrastructure rather than diffuse compromise.

Failure Activity Over Time

Failures

Showing 1-3 of 3 failures, affecting 10 messages
Date โ–ผ Source IP Country City Network Messages
2/10/2025 157.10.140.0 BT Bhutan GELEPHUTHROMDE-BT 6
11/21/2024 202.144.134.145 BT Bhutan TYANGTSEDZ-NET 1
11/21/2024 202.144.134.144 BT Bhutan TYANGTSEDZ-NET 3

What This Means

Country-level patterns don't imply that mail from Bhutan is inherently malicious. Many failures reflect misconfigured legitimate senders, forwarded messages that break authentication, or automated infrastructure operating without authorization. Domain owners investigating a specific failure should look at the source IP and network details rather than the country alone. Our DMARC guide explains how to interpret these signals in your own reports.