Shame on you, stupid spammers.. Sh4meful  DMARC Spoof Detection

IP Address: 54.227.64.76 โš  IP Confounder

Dormant. IP address 54.227.64.76 is registered to Amazon Technologies Inc and geolocates to Ashburn, United States. It first appeared in sh4meful's dataset on March 13, 2024 and was most recently observed on June 24, 2026. Over the observation window, it has failed DMARC alignment 166 times across 8 distinct sender domains. Its reverse DNS resolves to nat.perception-point.io. Network context: this address sits within AMAZON-2011L (Amazon Technologies Inc), a network sh4meful has observed producing 24 failures across 13 distinct IPs during the same window. This volume is elevated relative to most IPs observed in sh4meful's dataset and warrants closer scrutiny.

Failure Activity Over Time

This page shows DMARC authentication failure data for this IP address. Learn more about this data.

Geolocation Information
Country:
US United States
Region:
Virginia
City:
Ashburn
Coordinates:
39.0469, -77.4903
WHOIS Information
Network Name:
AMAZON-2011L
CIDR:
54.224.0.0/11
Owner:
Amazon Technologies Inc.
Org ID:
AT-88-Z
Address:
410 Terry Ave N., Seattle, WA 98109
Reverse DNS:
nat.perception-point.io
Last updated: 2/5/2026

Analysis

This IP is classified as a confounder: Fortinet Workspace Security - US. Failures observed from this source are expected artifacts of legitimate mail-handling behavior, typically email forwarding or mailing-list processing, and do not indicate spoofing attempts.

The host is operated by Amazon Technologies Inc and geolocates to Ashburn, United States. Its presence in DMARC aggregate reports is an artifact of how forwarded mail interacts with SPF and DKIM authentication, not a sign of abuse originating from this address.

Administrators observing this IP in their DMARC aggregate reports should not block or treat it as hostile. Google Workspace relay addresses appear in DMARC reports for mail routed through Google's filtering infrastructure. Ensure your SPF record includes Google's published mail server ranges if you use Google Workspace.

IP Confounder: Fortinet Workspace Security - US

This IP is associated with a legitimate email security service that may break DKIM/SPF authentication. Failed attempts from this source may not represent actual spoofing.

Failures Detected from this IP
Showing 1-50 of 166 failures, affecting 2,408 messages
Date โ–ผ Messages
6/24/2026 13
6/19/2026 2
6/18/2026 10
6/17/2026 1
6/5/2026 1
6/4/2026 10
6/3/2026 1
5/15/2026 1
5/14/2026 10
5/13/2026 1
4/10/2026 1
4/9/2026 9
4/8/2026 1
3/27/2026 1
3/26/2026 9
3/25/2026 1
3/13/2026 1
3/12/2026 10
3/11/2026 1
2/26/2026 10
2/25/2026 1
2/24/2026 1
1/31/2026 3
1/30/2026 3
1/29/2026 3
1/28/2026 8
1/17/2026 3
1/16/2026 3
1/15/2026 3
1/14/2026 8
1/10/2026 3
1/9/2026 3
1/8/2026 3
1/7/2026 9
12/18/2025 10
12/17/2025 1
12/16/2025 1
12/13/2025 3
12/12/2025 3
12/11/2025 3
12/10/2025 9
12/6/2025 3
12/5/2025 4
12/4/2025 13
12/3/2025 10
12/2/2025 1
11/22/2025 3
11/21/2025 4
11/20/2025 13
11/19/2025 10
External Reputation Lookups

Look up this IP in external threat intelligence and reputation databases (opens in new tab):

Recommended Action

If this IP appears in your own DMARC reports, treat it as an unauthorized sender unless you have specifically verified it as a legitimate service you use. Ensure your DMARC policy is at p=quarantine or p=reject to prevent delivery of messages this IP claims to send from your domain. If you're new to DMARC, our complete guide walks through the mechanics.