Spotting Phishing from Authenticated Legitimate Subdomains

A phishing email can arrive from a real organisation’s domain and still be malicious. Attackers may exploit a forgotten subdomain, compromise a marketing platform, or create a convincing address such as accounts.company.com. If SPF, DKIM and DMARC pass, the message may appear technically trustworthy while leading recipients to a fake login page or payment request.

This is especially relevant in Australia, where people regularly receive messages claiming to be from myGov, the ATO, Medicare, Australia Post or a major bank. A familiar brand and a padlock in the browser are not proof that an email is safe. Authentication confirms sending authority; it does not confirm the sender’s intentions.

Signal What it can prove What it cannot prove
SPF passes An approved server sent the message for the envelope domain The visible sender or content is genuine
DKIM passes The message has a valid cryptographic signature The signed account or subdomain is trustworthy
DMARC passes The visible From domain aligns with SPF or DKIM The organisation authorised the specific request
Legitimate subdomain The parent domain may have delegated it The subdomain is secure, monitored or safe

Read the Full Sender Address

Start with the complete address rather than the display name. “ATO Support” may appear in the inbox, while the actual address uses billing@secure.ato.example.com or a subdomain controlled by a third-party service. A genuine subdomain still deserves scrutiny because it may have been created for a temporary campaign, forgotten after a project ended, or taken over after a supplier relationship changed.

Check where the address sits in the domain hierarchy. In login.accounts.example.com, the registrable domain is usually example.com, while login.accounts are subdomains. A long chain of words can be designed to place a trusted brand near the beginning and hide the meaningful part of the address.

Understand What Authentication Means

SPF checks whether the sending infrastructure is authorised for a domain. DKIM checks a cryptographic signature, usually identified by the d= value in the message headers. DMARC then examines whether the visible From domain aligns with an authenticated SPF or DKIM domain. A message can pass all three and still be a scam if the attacker is using an authorised but abused service.

This distinction matters when a legitimate organisation uses email automation, customer relationship platforms or outsourced newsletters. A real vendor may send from a branded subdomain, but a compromised vendor account can send malicious content through the same approved infrastructure. Sender reputation and authentication results should therefore be treated as evidence, not a final verdict. FAQ guidance explains how these checks fit together.

Inspect Links Without Opening Them

Hover over each link on a computer, or press and hold carefully on a mobile device, to preview its destination. The visible text may say ato.gov.au, while the actual link points to a newly registered domain, a URL shortener or a cloud-hosted phishing page. Watch for misspellings, extra hyphens, deceptive subdomains and unusual top-level domains.

A link can also redirect several times before reaching its final page. This is common in credential theft campaigns because the first URL may be a legitimate tracking service. Avoid signing in through an email link when the message involves banking, tax, parcels or identity documents. Open the organisation’s known app or type its official address manually instead.

Treat Urgency as a Warning Sign

Phishing messages often create pressure: an unpaid toll, an expiring account, a parcel waiting at a depot or an “ATO refund” that must be claimed today. Australian recipients may recognise the tone from fake Australia Post delivery notices or messages referring to a Medicare detail update. Spelling and grammar can be polished, so a professional appearance does not remove the risk.

Look for requests that break the usual process. A supplier asking for new bank details, a payroll officer requesting a last-minute transfer, or a Microsoft 365 alert demanding password verification should be confirmed through a separate channel. Call a known number from the organisation’s website, not a number supplied in the email.

Examine Headers and Domain History

For higher-confidence analysis, inspect the message headers for the From, Return-Path, Reply-To, DKIM-Signature and Authentication-Results fields. A mismatched Reply-To address can reveal where responses will actually go. Compare the authenticated domains with the organisation’s normal sending patterns and consider whether the subdomain has a credible business purpose.

Security teams and Australian domain owners can check sender reputation, DMARC policy, DKIM configuration and bulk-domain behaviour before allowing messages into a workflow. A sudden increase in bounces, password resets or messages from an unfamiliar subdomain can indicate abuse. This bounce attack guide covers a related pattern that can affect domain reputation.

Verify Before You Act

When a message requests money, credentials, identity documents or access to a business system, pause the transaction. Report suspicious emails through the organisation’s established channel, mark them as phishing in the mail system and preserve the original message for investigators. Do not forward the email in a way that activates its links or attachments.

Businesses can reduce exposure by monitoring subdomain inventory, removing unused DNS records, enforcing strong DMARC policies and reviewing third-party senders. Individual users can rely on independent verification rather than authentication badges. A valid signature tells you that a permitted system sent the email; careful context, link inspection and out-of-band confirmation determine whether the request deserves trust.