ArchivedNo longer active, data collection ran March 2024 to September 2026|9,442 records|3,409 source IPs|138 countriesAbout this archive
Shame on you, stupid spammers..DMARC Spoof Detection

DMARC Spoof Detection, Kenya

ClearClear Filter

This page shows DMARC authentication failures originating from Kenya. Learn more about this data.

Kenya accounts for 28 DMARC authentication failures observed by sh4meful over the observation window, sourced from 26 distinct IP addresses across 5 networks. This represents approximately 0.5% of total failure volume observed. Activity from Kenya has declined over the last 30 days compared with the prior 30-day period. The most active source is SFC-GPRS-EDGE-3G-SERVICE-POOL2 with 3 failures across 3 IP addresses.

Failures (Filtered)

28

IPs (Filtered)

26

Networks (Filtered)

5

Messages (Filtered)

73

Top Networks in Kenya

Ten most active networks sourcing DMARC failures from Kenya:

NetworkOrganizationFailuresDistinct IPsTop City
SFC-GPRS-EDGE-3G-SERVICE-POOL2โ€”33Nairobi
Flinkโ€”11Nairobi
SFC-GPRS-EDGE-3Gโ€”11Nairobi
SPRINKVILLE-NETWORKSโ€”11Nairobi
Mobile_Data_3G_LTE_8โ€”22Nairobi

SFC-GPRS-EDGE-3G-SERVICE-POOL2 and Flink together account for 18% of failure volume from this country. Distribution across many networks is consistent with commodity spoofing infrastructure operating from this geography.

Failure Activity Over Time

Peak activity was observed in the week of August 3, 2026 with 10 failures recorded. Activity in the most recent 30-day window declined sharply compared with the prior period (4 vs 16 failures).

Regional Context

Compared with peer geographies in Eastern Africa, Kenya's failure volume is above the regional median. Countries in this region collectively contributed 1% of failures observed.

Failures

Showing 1-10 of 28 failures, affecting 73 messages
Date โ–ผ Source IP Country City Network Messages
8/24/2026 102.219.210.254 KE KenyaNairobiN/A4
8/6/2026 105.21.41.166 KE KenyaNairobiN/A1
8/5/2026 102.0.30.22 KE KenyaN/A4
8/4/2026 154.159.253.254 KE KenyaNairobiN/A2
8/3/2026 102.0.2.174 KE KenyaNairobiN/A3
8/2/2026 105.21.41.166 KE KenyaNairobiN/A4
7/27/2026 102.0.24.32 KE KenyaN/A2
7/26/2026 105.21.41.166 KE KenyaNairobiN/A1
7/24/2026 41.206.59.254 KE KenyaNairobiN/A3
7/16/2026 154.159.237.43 KE KenyaN/A4
7/12/2026 102.0.21.140 KE KenyaNairobiN/A2
6/28/2026 102.0.2.114 KE KenyaNairobiN/A3
6/23/2026 41.220.227.170 KE KenyaNairobiN/A4
6/21/2026 154.79.248.180 KE KenyaN/A1
6/19/2026 154.159.244.35 KE KenyaNairobiN/A1
6/17/2026 102.220.12.234 KE KenyaNairobiN/A1
6/17/2026 105.27.99.110 KE KenyaNairobiN/A3
6/17/2026 41.215.57.66 KE KenyaNairobiN/A2
4/4/2026 41.90.144.117 KE KenyaN/A4
2/18/2026 102.0.24.182 KE KenyaN/A1
7/2/2025 105.161.28.212 KE KenyaNairobi SFC-GPRS-EDGE-3G 4
6/24/2025 41.90.181.197 KE KenyaNairobi SFC-GPRS-EDGE-3G-SERVICE-POOL2 1
4/19/2025 41.90.185.35 KE KenyaNairobi SFC-GPRS-EDGE-3G-SERVICE-POOL2 4
4/18/2025 102.213.95.51 KE KenyaNairobi Flink 4
11/23/2024 102.215.15.14 KE KenyaNairobi SPRINKVILLE-NETWORKS 4
11/16/2024 41.90.175.109 KE KenyaNairobi SFC-GPRS-EDGE-3G-SERVICE-POOL2 4
6/30/2024 154.159.254.193 KE KenyaNairobi Mobile_Data_3G_LTE_8 1
6/30/2024 154.159.237.33 KE Kenya Mobile_Data_3G_LTE_8 1

What This Means

Country-level patterns don't imply that mail from Kenya is inherently malicious. Many failures reflect misconfigured legitimate senders, forwarded messages that break authentication, or automated infrastructure operating without authorization. Domain owners investigating a specific failure should look at the source IP and network details rather than the country alone. Our DMARC guide explains how to interpret these signals in your own reports.