Why Legacy Subdomains Without DMARC Become Spoofing Havens
Many Australian organisations unknowingly leave digital back doors open through old subdomains created for past campaigns, pilot projects, or temporary microsites. Once the project ends, the subdomain often sits dormant, still pointing to an obsolete mail server or still able to send email with no authentication checks. Attackers spot these gaps long before the domain owner does, then exploit the reputation of the parent domain to push convincing phishing into inboxes from Sydney to Perth.
The Australian Cyber Security Centre regularly flags business email compromise as one of the most reported cybercrimes locally. A surprising share of those campaigns rides on the coat-tails of forgotten infrastructure. Understanding how legacy subdomains and missing DMARC records combine to create an attack surface is the first step toward shutting it down.
The quiet decay of forgotten DNS records
Subdomains tend to accumulate quietly. A marketing team in Brisbane spins up a landing page for a webinar. A regional office in Adelaide hosts a temporary portal. An IT contractor retires a CRM integration but leaves the mail exchange record intact. None of these subdomains appear on the organisation's main radar, yet they remain resolvable in DNS and, in many cases, still accept or send mail.
Because the parent domain, such as an example.com.au, carries established trust, mail gateways often treat mail from any subdomain as legitimate by default. Attackers register similar-looking sender identities on these dormant hosts, or they relay messages through servers the subdomain still trusts. The result is a spoofed email that passes rudimentary reputation checks and lands in the inbox asking the recipient to "verify" their myGov account or update their CommBank details.
Why the absence of DMARC makes everything worse
DMARC tells receiving servers what to do when a message fails SPF or DKIM checks. A domain that publishes no DMARC record leaves that decision entirely to the receiver, which usually means the message is accepted without complaint. For a dormant subdomain, this absence is almost guaranteed, because the original team never set the policy and the current team does not know the record exists.
Australia's .au namespace, administered by auDA, enforces strict registration rules for the main domain but does not extend that governance to subdomains. Once you own your.com.au, you control every prefix beneath it, including the ones nobody remembers. Without a reject or quarantine policy pushed down through subdomain records, spoofers can impersonate newsletters, internal IT alerts, or supplier invoices with very little effort. Running the how to use Trusted Sender Score platform across all known subdomains quickly surfaces which ones are missing this critical layer of protection.
Patterns observed in Australian phishing campaigns
Local reporting through ACCC Scamwatch and the ACSC shows a steady rise in business email compromise, and post-incident analyses often point to legacy subdomains as the launch point. Common patterns include invoices sent from a finance subdomain the organisation retired years earlier, password reset prompts routed through a forgotten partner portal, and HR communications from a subdomain that once hosted a careers page.
Telstra and Optus customers have been targeted through lookalike subdomains set up by attackers who purchased the dormant prefix after the original certificate lapsed. Smaller operators, including medical practices in regional Victoria and logistics firms in Western Australia, are particularly exposed because they often lack the in-house resources to audit DNS at a granular level. The shared characteristic across these incidents is the same: the spoofed address resolved, and the receiving server had no DMARC instruction to reject it.
The downstream damage of a successful spoof
When a spoofed email slips through, the cost is rarely just a single clicked link. Recipients who wire funds to a fraudulent account may not realise the mistake until reconciliation. Customers who hand over credentials to a fake ATO portal can face ongoing identity theft. Internal staff who follow what looks like a genuine IT instruction can inadvertently hand attackers remote access to their environment.
Under Australia's Notifiable Data Breaches scheme, organisations that suffer a likely-eligible breach must notify the Office of the Australian Information Commissioner and affected individuals. A successful spoof that leads to a credential dump therefore triggers legal, reputational, and financial consequences well beyond the original attack. Tracking the source of the inbound message, including whether it came from a known-but-unmonitored subdomain, forms a key part of any post-incident review and can inform a practical bounce attack detection workflow.
Closing the gap before attackers find it
The fix is rarely glamorous, but it is well within reach. Start by enumerating every subdomain your organisation has ever registered, including those hosted on cloud platforms and partner integrations. For each one, publish or inherit a DMARC policy of at least p=none with reporting enabled, then move progressively toward p=quarantine and p=reject as you confirm legitimate traffic.
Pair this audit with regular reputation checks so that dormant subdomains that suddenly start sending mail are flagged immediately. Make subdomain lifecycle management a formal part of project closeout, and ensure that retiring a service means removing its MX record and revoking any certificates. The organisations that suffer the worst incidents in Australia are rarely the ones facing the most sophisticated adversaries; they are the ones who simply forgot an old address still pointed at the open internet.