Shame on you, stupid spammers.. Sh4meful  DMARC Spoof Detection

IP Address: 100.24.129.5 โš  IP Confounder

Dormant. IP address 100.24.129.5 is registered to Amazon.com, Inc and geolocates to Ashburn, United States. It first appeared in sh4meful's dataset on March 13, 2024 and was most recently observed on June 24, 2026. Over the observation window, it has failed DMARC alignment 107 times across 9 distinct sender domains. Its reverse DNS resolves to ipw-outbound.inkyphishfence.com. Network context: this address sits within AMAZO-4 (Amazon.com, Inc), a network sh4meful has observed producing 64 failures across 9 distinct IPs during the same window. This volume is elevated relative to most IPs observed in sh4meful's dataset and warrants closer scrutiny.

Failure Activity Over Time

This page shows DMARC authentication failure data for this IP address. Learn more about this data.

Geolocation Information
Country:
US United States
Region:
Virginia
City:
Ashburn
Coordinates:
39.0469, -77.4903
WHOIS Information
Network Name:
AMAZO-4
CIDR:
100.24.0.0/13, 100.20.0.0/14
Owner:
Amazon.com, Inc.
Org ID:
AMAZO-4
Address:
Amazon Web Services, Inc. P.O. Box 81226, Seattle, WA 98108-1226
Reverse DNS:
ipw-outbound.inkyphishfence.com
Last updated: 2/5/2026

Analysis

This IP is classified as a confounder: Kaseya/Inky. Failures observed from this source are expected artifacts of legitimate mail-handling behavior, typically email forwarding or mailing-list processing, and do not indicate spoofing attempts.

The host is operated by Amazon.com, Inc and geolocates to Ashburn, United States. Its presence in DMARC aggregate reports is an artifact of how forwarded mail interacts with SPF and DKIM authentication, not a sign of abuse originating from this address.

Administrators observing this IP in their DMARC aggregate reports should not block or treat it as hostile. Consult the documentation for this mail-handling service to determine whether your SPF record should be updated to include its relay addresses, or whether ARC sealing is appropriate for your configuration.

Amazon Web Services (AWS)

This is (part of) the AWS public cloud. Some email protection services run in AWS, but it is also an attack/spam vector.

Last updated: 1/29/2026

IP Confounder: Kaseya/Inky

Anti-Phishing, Anti-Malware, Spam filter Uses AI to blocks impersonation and ransomware with intuitive user coaching. Can break SPF and DKIM validation

Failures Detected from this IP
Showing 1-50 of 107 failures, affecting 273 messages
Date โ–ผ Messages
6/24/2026 7
6/20/2026 1
6/19/2026 2
6/18/2026 4
6/17/2026 1
6/5/2026 2
6/4/2026 3
6/3/2026 2
5/15/2026 1
5/14/2026 5
4/10/2026 2
4/9/2026 3
4/1/2026 1
3/26/2026 3
3/21/2026 1
3/17/2026 4
3/13/2026 1
3/12/2026 1
2/27/2026 4
2/26/2026 3
1/30/2026 1
1/29/2026 1
1/28/2026 3
1/14/2026 2
1/9/2026 1
1/7/2026 2
12/18/2025 4
12/10/2025 4
12/5/2025 1
12/4/2025 3
12/3/2025 2
11/21/2025 1
11/20/2025 4
11/13/2025 1
10/24/2025 1
10/23/2025 5
10/11/2025 1
10/10/2025 2
10/9/2025 3
10/3/2025 3
10/2/2025 4
10/1/2025 6
9/26/2025 3
9/25/2025 3
9/24/2025 7
9/23/2025 1
9/19/2025 5
9/18/2025 1
9/17/2025 8
9/12/2025 3
External Reputation Lookups

Look up this IP in external threat intelligence and reputation databases (opens in new tab):

Recommended Action

If this IP appears in your own DMARC reports, treat it as an unauthorized sender unless you have specifically verified it as a legitimate service you use. Ensure your DMARC policy is at p=quarantine or p=reject to prevent delivery of messages this IP claims to send from your domain. If you're new to DMARC, our complete guide walks through the mechanics.