How attackers use DKIM-signed domains to bypass SPF-only filters
Email authentication rests on three pillars: SPF, DKIM, and DMARC. Far too often, businesses deploy the first and ignore the rest, leaving a window that phishers know how to walk through. A correctly signed DKIM signature proves a message was not altered in transit, yet it says nothing about whether the sender is who the recipient expects. That single blind spot is what attackers count on.
Australian businesses have watched this pattern play out in real inboxes. Campaigns impersonating the ATO, myGov, and Australia Post routinely use freshly registered domains that publish a DKIM key but skip the SPF record altogether. The result is a message that sails past basic checks and lands in front of staff who are already juggling client calls in Sydney and supplier queries in Brisbane.
The SPF gap in legacy mail gateways
Many on-premise and hosted spam filters built before 2014 only validate the envelope sender against SPF. When the lookup returns a softfail, neutral, or simply nothing, the message is treated as "no SPF opinion" rather than "suspicious." A phisher who knows this can publish any DKIM record they like, sign a clean message, and let the gateway deliver the email because the SPF pass-or-fail branch was never taken seriously.
The economics matter too. A small accounting firm in Adelaide or a logistics broker in Perth is far more likely to keep a default Office 365 or cPanel filter than to licence an enterprise secure email gateway. That default path is exactly the SPF-first logic attackers probe during reconnaissance.
Why DKIM by itself is not a trust signal
DKIM confirms that the bytes of an email match a private key held by the signing domain. It does not check the visible From header, the Reply-To address, or whether the domain has any history of legitimate mail. A criminal can stand up a brand-new zone, generate a 2048-bit RSA key, sign a single phishing email, and present the receiver with a green DKIM result.
Because the attacker controls the entire domain, they can also make the human-readable sender look like a trusted Australian brand. They are not spoofing, technically. They are choosing a fresh name that conveys authority, then authenticating it cleanly. Receivers that lean on DKIM alone will score the message higher, not lower.
A pattern Australian defenders keep seeing
The ACCC's Scamwatch has logged waves of fake ATO and myGov notices that all share the same shape: a .com.au-adjacent or unrelated overseas domain, a passing DKIM signature, and an empty or misconfigured SPF record. The ATO itself has repeatedly warned taxpayers that it will never demand payment via a link in an email, yet the lure still works.
Telstra and Optus impersonation campaigns follow the same recipe, often timed around major sporting events when Australians are distracted by AFL finals or the Boxing Day Test. The criminals rely on the recipient reading the message on a phone, glancing at a brand name, and tapping before any deeper authentication check runs.
What DMARC actually solves
DMARC ties SPF and DKIM to the visible From domain, and asks the receiver to reject mail that fails alignment. When a domain publishes a quarantine or reject policy, a phishing message that does not pass SPF alignment and does not pass DKIM alignment is meant to be dropped at the gateway.
The trouble is that DMARC only protects domains that publish it. If the brand being impersonated has not rolled out a policy, or has rolled it out only in monitoring mode, the receiver has no instruction to act. That leaves the protective load on the recipient organisation's filter, which is the SPF-only filter that started this whole chain.
Red flags worth surfacing in the SOC
A few signals tend to cluster together in these campaigns. A domain that was registered inside the last thirty days. No SPF record, or one that ends in -all while listing only the provider's own servers. A valid DKIM signature from a key that was generated the same week. An HTML body that uses a known brand's colour palette but links to an unrelated redirector.
Security teams in Melbourne and Canberra that aggregate these attributes in a SIEM rule will catch what header-only checks miss. A free tool like Trusted Sender Score makes it easy to surface the SPF, DKIM, and DMARC posture of any suspect domain in seconds, which is enough to triage a batch of reported emails before lunch.
Closing the gap on your own sending domain
If you operate mail for an Australian business, the fix is to publish all three records and to keep an eye on your own reputation. A useful starting point is to monitor your sender score regularly and treat any drop as a prompt to review recent authentication changes.
Pair that habit with a DMARC policy that moves from p=none to p=quarantine and finally p=reject, and the window that phishers exploit through DKIM-only signing shrinks dramatically. Email security is rarely a single switch, but the gap between SPF and DKIM is one of the easiest to close when you know it is there.