Network: MIMECAST-NET โ Confounder
โ Confounder Detected: Mimecast Email Security Gateway
Mimecast is a cloud-based email security gateway that enterprises route all inbound and outbound corporate email through for spam filtering, malware scanning, URL click-protection, and archiving. It breaks DKIM authentication by modifying message bodies during inline security processing โ URL rewriting and footer insertion invalidate the original DKIM body hash. On the SPF side, Mimecast relay IPs become the actual sending IPs, breaking SPF alignment unless the domain owner has explicitly included Mimecast netblocks in their SPF record and enabled SPF alignment in the Mimecast admin console. DMARC failures originating from Mimecast IP ranges are almost always legitimate corporate email with a configuration gap, not spoofing or spam attempts.
Mimecast is a cloud-based email security gateway that enterprises route all inbound and outbound corporate email through for spam filtering, malware scanning, URL click-protection, and archiving. It breaks DKIM authentication by modifying message bodies during inline security processing โ URL rewriting and footer insertion invalidate the original DKIM body hash. On the SPF side, Mimecast relay IPs become the actual sending IPs, breaking SPF alignment unless the domain owner has explicitly included Mimecast netblocks in their SPF record and enabled SPF alignment in the Mimecast admin console. DMARC failures originating from Mimecast IP ranges are almost always legitimate corporate email with a configuration gap, not spoofing or spam attempts.
This page shows DMARC authentication failures originating from the MIMECAST-NET network. Learn more about this data.
Analysis
This network has contributed 2 unique IP addresses across 24 failed authentication events, accounting for 54 messages. Activity spans from October 23, 2024 to April 10, 2026, with peak volume in December 2025 (6 events). The top countries by failure volume are United Kingdom (100%). The most active source IPs from this network include 195.130.217.221 (22 failures), 195.130.217.76 (2 failures). A single IP dominates activity from MIMECAST-NET (Mimecast), suggesting a concentrated or persistent source rather than distributed infrastructure.
Failures Detected from this Network
Showing 1-24 of 24 failures, affecting 54 messages| Date โฒ | Source IP | Country | Messages |
|---|---|---|---|
| 10/23/2024 | GB | 4 | |
| 7/31/2025 | GB | 2 | |
| 9/10/2025 | GB | 1 | |
| 9/12/2025 | GB | 3 | |
| 9/26/2025 | GB | 2 | |
| 10/3/2025 | GB | 2 | |
| 10/8/2025 | GB | 1 | |
| 10/10/2025 | GB | 3 | |
| 10/24/2025 | GB | 2 | |
| 11/14/2025 | GB | 3 | |
| 11/19/2025 | GB | 2 | |
| 11/21/2025 | GB | 3 | |
| 12/3/2025 | GB | 2 | |
| 12/5/2025 | GB | 3 | |
| 12/5/2025 | GB | 1 | |
| 12/10/2025 | GB | 1 | |
| 12/19/2025 | GB | 2 | |
| 12/19/2025 | GB | 1 | |
| 1/7/2026 | GB | 2 | |
| 1/14/2026 | GB | 2 | |
| 1/28/2026 | GB | 1 | |
| 2/27/2026 | GB | 5 | |
| 3/13/2026 | GB | 3 | |
| 4/10/2026 | GB | 3 |
Countries