Network: MIMECAST-NET2 โ Confounder
โ Confounder Detected: Mimecast Email Security Gateway
Mimecast is a cloud-based email security gateway that enterprises route all inbound and outbound corporate email through for spam filtering, malware scanning, URL click-protection, and archiving. It breaks DKIM authentication by modifying message bodies during inline security processing โ URL rewriting and footer insertion invalidate the original DKIM body hash. On the SPF side, Mimecast relay IPs become the actual sending IPs, breaking SPF alignment unless the domain owner has explicitly included Mimecast netblocks in their SPF record and enabled SPF alignment in the Mimecast admin console. DMARC failures originating from Mimecast IP ranges are almost always legitimate corporate email with a configuration gap, not spoofing or spam attempts.
Mimecast is a cloud-based email security gateway that enterprises route all inbound and outbound corporate email through for spam filtering, malware scanning, URL click-protection, and archiving. It breaks DKIM authentication by modifying message bodies during inline security processing โ URL rewriting and footer insertion invalidate the original DKIM body hash. On the SPF side, Mimecast relay IPs become the actual sending IPs, breaking SPF alignment unless the domain owner has explicitly included Mimecast netblocks in their SPF record and enabled SPF alignment in the Mimecast admin console. DMARC failures originating from Mimecast IP ranges are almost always legitimate corporate email with a configuration gap, not spoofing or spam attempts.
This page shows DMARC authentication failures originating from the MIMECAST-NET2 network. Learn more about this data.
Analysis
This network has contributed 1 unique IP address across 23 failed authentication events, accounting for 59 messages. Activity spans from October 23, 2024 to March 13, 2026, with peak volume in October 2025 (6 events). The top countries by failure volume are United Kingdom (100%). The most active source IP from this network includes 91.220.42.227 (24 failures). A single IP dominates activity from MIMECAST-NET2 (Mimecast), suggesting a concentrated or persistent source rather than distributed infrastructure.
Failures Detected from this Network
Showing 1-23 of 23 failures, affecting 59 messages| Date โฒ | Source IP | Country | Messages |
|---|---|---|---|
| 10/23/2024 | GB | 8 | |
| 7/31/2025 | GB | 1 | |
| 9/10/2025 | GB | 2 | |
| 9/12/2025 | GB | 3 | |
| 9/17/2025 | GB | 3 | |
| 9/26/2025 | GB | 4 | |
| 10/1/2025 | GB | 3 | |
| 10/3/2025 | GB | 4 | |
| 10/8/2025 | GB | 2 | |
| 10/10/2025 | GB | 3 | |
| 10/24/2025 | GB | 4 | |
| 11/14/2025 | GB | 3 | |
| 11/19/2025 | GB | 1 | |
| 11/21/2025 | GB | 3 | |
| 12/3/2025 | GB | 1 | |
| 12/5/2025 | GB | 2 | |
| 12/10/2025 | GB | 1 | |
| 12/19/2025 | GB | 3 | |
| 1/7/2026 | GB | 1 | |
| 1/14/2026 | GB | 1 | |
| 1/28/2026 | GB | 2 | |
| 2/27/2026 | GB | 1 | |
| 3/13/2026 | GB | 3 |
Countries