Shame on you, stupid spammers.. Sh4meful  DMARC Spoof Detection

IP Address: 3.132.108.44 โš  IP Confounder

Dormant. IP address 3.132.108.44 is registered to Amazon Technologies Inc and geolocates to Columbus, United States. It first appeared in sh4meful's dataset on April 17, 2024 and was most recently observed on June 24, 2026. Over the observation window, it has failed DMARC alignment 108 times across 8 distinct sender domains. Its reverse DNS resolves to ipw-outbound.inkyphishfence.com. Network context: this address sits within AT-88-Z (Amazon Technologies Inc), a network sh4meful has observed producing 185 failures across 33 distinct IPs during the same window. This volume is elevated relative to most IPs observed in sh4meful's dataset and warrants closer scrutiny.

Failure Activity Over Time

This page shows DMARC authentication failure data for this IP address. Learn more about this data.

Geolocation Information
Country:
US United States
Region:
Ohio
City:
Columbus
Coordinates:
39.9625, -83.0061
WHOIS Information
Network Name:
AT-88-Z
CIDR:
3.128.0.0/9
Owner:
Amazon Technologies Inc.
Org ID:
AT-88-Z
Address:
410 Terry Ave N., Seattle, WA 98109
Reverse DNS:
ipw-outbound.inkyphishfence.com
Last updated: 2/5/2026

Analysis

This IP is classified as a confounder: Kaseya/Inky. Failures observed from this source are expected artifacts of legitimate mail-handling behavior, typically email forwarding or mailing-list processing, and do not indicate spoofing attempts.

The host is operated by Amazon Technologies Inc and geolocates to Columbus, United States. Its presence in DMARC aggregate reports is an artifact of how forwarded mail interacts with SPF and DKIM authentication, not a sign of abuse originating from this address.

Administrators observing this IP in their DMARC aggregate reports should not block or treat it as hostile. Consult the documentation for this mail-handling service to determine whether your SPF record should be updated to include its relay addresses, or whether ARC sealing is appropriate for your configuration.

Amazon Web Services (AWS)

This is (part of) the AWS public cloud. Some email protection services run in AWS, but it is also an attack/spam vector.

Last updated: 1/29/2026

IP Confounder: Kaseya/Inky

Anti-Phishing, Anti-Malware, Spam filter Uses AI to blocks impersonation and ransomware with intuitive user coaching. Can break SPF and DKIM validation

Failures Detected from this IP
Showing 1-50 of 108 failures, affecting 312 messages
Date โ–ผ Messages
6/24/2026 6
6/19/2026 3
6/18/2026 2
6/5/2026 3
6/4/2026 4
6/2/2026 1
5/16/2026 2
5/15/2026 2
5/14/2026 5
5/13/2026 1
4/10/2026 1
4/9/2026 4
4/8/2026 1
4/1/2026 1
3/27/2026 2
3/26/2026 6
3/24/2026 1
3/13/2026 5
3/12/2026 6
2/27/2026 2
2/26/2026 3
1/28/2026 6
1/16/2026 1
1/14/2026 4
1/9/2026 2
1/7/2026 1
12/18/2025 3
12/12/2025 3
12/10/2025 2
12/5/2025 1
12/4/2025 4
12/3/2025 3
11/21/2025 2
11/20/2025 2
11/19/2025 3
11/13/2025 1
10/24/2025 1
10/23/2025 2
10/10/2025 1
10/9/2025 8
10/8/2025 6
10/3/2025 4
10/2/2025 2
10/1/2025 6
9/27/2025 1
9/26/2025 3
9/25/2025 3
9/24/2025 5
9/19/2025 4
9/17/2025 5
External Reputation Lookups

Look up this IP in external threat intelligence and reputation databases (opens in new tab):

Recommended Action

If this IP appears in your own DMARC reports, treat it as an unauthorized sender unless you have specifically verified it as a legitimate service you use. Ensure your DMARC policy is at p=quarantine or p=reject to prevent delivery of messages this IP claims to send from your domain. If you're new to DMARC, our complete guide walks through the mechanics.