Catch-All SPF and DMARC strategies for subdomain spoofing defence
Subdomain spoofing has become a favourite tactic of scammers sending fake ATO overdue notices, false CBA statements, and impersonations of smaller Australian businesses that shoppers trust. These campaigns often use lookalike subdomains on real .au domains, slipping past filters because the parent domain already has a decent reputation. The damage is real: customers lose money, brand trust collapses, and ACSC reports a steady stream of successful impersonations each quarter.
A catch-all SPF and DMARC strategy flips the script. Instead of listing every sending service separately and hoping nothing slips through, you publish a broad Sender Policy Framework record that authorises every possible host, then pair it with a DMARC policy that catches anything unauthorised across all subdomains at once. Combined with regular monitoring, this creates a safety net that closes the gap attackers rely on.
Why subdomain spoofing is rising against Australian brands
The .au namespace carries weight locally. When an email appears to come from billing.bigbank.com.au or refundato.gov.au, recipients are far more likely to click. Cybercriminals exploit that familiarity, registering throwaway subdomains or hijacking forgotten ones to push credential-harvesting pages. Big retailers in Sydney, Melbourne and Brisbane have all been hit through forgotten marketing subdomains pointing to old Mailchimp campaigns.
The shift to remote work has made things worse. Australian organisations now send mail from a sprawl of cloud platforms, including Microsoft 365, Google Workspace, Xero for invoices, and Mailchimp for newsletters. Each one may live on its own subdomain, which leaves gaps if your SPF record was last updated two years ago. ACSC's annual cyber threat report continues to flag business email compromise as one of the most reported incidents in the country.
Building a catch-all SPF record that covers every host
Start with a complete inventory. List every service that sends email on your behalf, including transactional senders, marketing platforms, support ticketing systems, and any office printers or scanners that email documents. For an Australian SMB, this often looks like Outlook on a Telstra connection, Mimecast for filtering, a Mailchimp newsletter list, and an accounting tool like MYOB or Xero.
Your SPF record uses the "include" mechanism to pull in each provider's published range. A typical record might combine Outlook's spf.protection.outlook.com, Google Workspace's _spf.google.com, Mailchimp's servers.mcsv.net, and a +ip4 entry for your office range. Crucially, you end with -all rather than +all, which tells receiving servers to reject anything not on the list. Setting a hard fail stops spoofed messages from reaching Australian inboxes in the first place.
Setting DMARC to sweep every subdomain automatically
DMARC's "sp" tag is the secret weapon for subdomain coverage. While the "p" tag governs the organisational domain, "sp" applies to every subdomain underneath it. Setting "sp=reject" enforces the strictest policy across login.yourcompany.com.au, support.yourcompany.com.au, and any future subdomain you forget to manage.
Reporting is where the real value emerges. Add an "rua" tag pointing to an address you control, and choose a third-party reporter to make sense of the XML data. Learning to read these reports speeds up how quickly you spot a misconfigured service. Reviewing DMARC aggregate reports at least weekly helps catch configuration drift before attackers do, and the format quickly becomes second nature once you know what to look for.
Watching the reports and hunting for rogue subdomains
Subdomain spoofing often begins with a subdomain nobody remembers. A leftover "dev" or "staging" environment pointing at a cloud bucket, an old "careers" page on a discontinued platform, or a forgotten "newsletter" subdomain still talking to Mailchimp all become gift-wrapped attack vectors. Bulk domain checking tools let you audit your entire footprint and flag subdomains that still send mail but are no longer managed.
Reputation dashboards take this further by aggregating send volumes, authentication pass rates, and any blacklisting that has occurred. A platform like Trusted Sender Score gives you a single place to keep tabs on every domain and subdomain you own, surfacing issues before they become headlines. Pair this with monthly reviews of your DMARC RUA reports and you have a continuous feedback loop.
Responding to a live spoofing incident
When a spoofed message lands in customer inboxes, speed matters. Notify your IT or security partner straight away, then report the campaign through ACCC Scamwatch and ACSC's ReportCyber portal so other Australians can be warned. If the impersonation involves a financial brand, alert the relevant bank's fraud team as well.
While the incident is fresh, tighten your DMARC policy from "p=quarantine" to "p=reject" and confirm every legitimate sending service still passes SPF and DKIM. Update your SPF include list if a new platform was missed, and check for subdomains that were created outside your normal change process. Once the policy is at reject and your reporting shows clean traffic, the attacker's infrastructure loses its main advantage, and your domain reputation recovers faster.