Shame on you, stupid spammers.. Sh4meful  DMARC Spoof Detection

IP Address: 35.174.145.124 โš  IP Confounder

Dormant. IP address 35.174.145.124 is registered to Amazon Technologies Inc and geolocates to Ashburn, United States. It first appeared in sh4meful's dataset on March 13, 2024 and was most recently observed on July 24, 2026. Over the observation window, it has failed DMARC alignment 212 times across 11 distinct sender domains. Its reverse DNS resolves to us.cloud-sec-av.com. Network context: this address sits within AT-88-Z (Amazon Technologies Inc), a network sh4meful has observed producing 185 failures across 33 distinct IPs during the same window. This volume is elevated relative to most IPs observed in sh4meful's dataset and warrants closer scrutiny.

Failure Activity Over Time

Peak activity was observed in the week of July 20, 2026 with 2 failures recorded. Activity in the most recent 30-day window declined sharply compared with the prior period (0 vs 2 failures).

This page shows DMARC authentication failure data for this IP address. Learn more about this data.

Geolocation Information
Country:
US United States
Region:
Virginia
City:
Ashburn
Coordinates:
39.0469, -77.4903
WHOIS Information
Network Name:
AT-88-Z
CIDR:
35.152.0.0/13, 35.160.0.0/12, 35.176.0.0/13
Owner:
Amazon Technologies Inc.
Org ID:
AT-88-Z
Address:
410 Terry Ave N., Seattle, WA 98109
Reverse DNS:
us.cloud-sec-av.com
Last updated: 2/5/2026

Analysis

This IP is classified as a confounder: Avanan/Check Point Email Security. Failures observed from this source are expected artifacts of legitimate mail-handling behavior, typically email forwarding or mailing-list processing, and do not indicate spoofing attempts.

The host is operated by Amazon Technologies Inc and geolocates to Ashburn, United States. Its presence in DMARC aggregate reports is an artifact of how forwarded mail interacts with SPF and DKIM authentication, not a sign of abuse originating from this address.

Administrators observing this IP in their DMARC aggregate reports should not block or treat it as hostile. Avanan and Check Point are cloud-based email security gateways. Their regional relay IPs appear in DMARC reports when they inspect and re-deliver inbound mail. Adding their ranges to your SPF record or flagging them in your DMARC reporting tool will suppress these entries.

Amazon Web Services (AWS)

This is (part of) the AWS public cloud. Some email protection services run in AWS, but it is also an attack/spam vector.

Last updated: 1/29/2026

IP Confounder: Avanan/Check Point Email Security

Breaks DKIM signatures during email processing

Failures Detected from this IP
Showing 1-50 of 212 failures, affecting 42,291 messages
Date โ–ผ Messages
7/24/2026 2
6/24/2026 339
6/20/2026 55
6/19/2026 117
6/18/2026 54
6/17/2026 96
6/16/2026 10
6/6/2026 44
6/5/2026 117
6/4/2026 59
6/3/2026 99
6/2/2026 12
5/21/2026 2
5/16/2026 53
5/15/2026 114
5/14/2026 62
5/13/2026 98
5/12/2026 1
5/5/2026 2
5/1/2026 1
4/28/2026 1
4/22/2026 1
4/21/2026 2
4/14/2026 3
4/10/2026 113
4/9/2026 57
4/8/2026 95
4/7/2026 13
4/2/2026 10
4/1/2026 3
3/28/2026 2
3/27/2026 126
3/26/2026 66
3/25/2026 98
3/24/2026 14
3/14/2026 54
3/13/2026 124
3/12/2026 64
3/11/2026 91
3/10/2026 13
2/28/2026 47
2/27/2026 149
2/26/2026 72
2/25/2026 120
2/24/2026 16
1/31/2026 29
1/30/2026 107
1/29/2026 99
1/28/2026 88
1/27/2026 49
External Reputation Lookups

Look up this IP in external threat intelligence and reputation databases (opens in new tab):

Recommended Action

If this IP appears in your own DMARC reports, treat it as an unauthorized sender unless you have specifically verified it as a legitimate service you use. Ensure your DMARC policy is at p=quarantine or p=reject to prevent delivery of messages this IP claims to send from your domain. If you're new to DMARC, our complete guide walks through the mechanics.