Why phishers use free mail with SPF records against filters

Email-borne scams continue to hit Australians hard. Scamwatch data consistently ranks phishing among the top loss categories reported from Sydney to Melbourne, and plenty of those messages come from free webmail addresses. That is the exact detail defenders struggle with.

SPF was designed to mark legitimate sending servers, not vouch for content. Big providers like Google and Microsoft publish strict SPF entries and sign millions of legitimate messages daily, so a passing SPF result tells a mail server almost nothing about the human behind the keyboard. Phishers exploit that gap.

What follows is a closer look at how the tactic works, why it slips past the front door of an inbox, and the practical checks that can catch what SPF alone will miss.

SPF was built to authorise servers, not people

SPF, or Sender Policy Framework, lists which IP addresses a domain allows to send mail on its behalf. When a message arrives claiming to be from a gmail.com address, the receiving server checks gmail.com's published record against the sending IP. A match returns an SPF pass. That is the entire job of the protocol.

The pass says nothing about intent, content, or accountability. It does not confirm the sender is who they appear to be or that the mail is wanted. Plenty of small businesses in Australia configure SPF and treat the green tick as a guarantee, which is risky to keep.

Attackers love the ambiguity because it costs them nothing. They open a free account, get an SPF-aligned address, and ride the reputation of the parent domain. The local takeaway is that SPF shows up as trustworthy in tooling, even when the human behind the email is a stranger on the other side of the world.

Free providers lend their reputation to anyone with a signup form

Google, Microsoft, and Yahoo publish aggressive SPF records because they have to. They send billions of legitimate messages and need their mail to land. That scale gives them strong inbox placement across Australia, where major gateways accept almost anything originating from those domains.

A phisher simply registers a free address, often choosing a display name like "ATO Support" or "myGov Help", and inherits that reputation overnight. Recipients in Brisbane or Perth see an @gmail.com or @outlook.com message sail past the first wave of checks. The phishing kit underneath is cheap and sold through dodgy forums.

For an Aussie scam pretending to be from the big four banks or from Optus after the 2022 breach, the choice of platform is a deliberate trust play. People in Bondi or Adelaide are far more likely to reply to an @outlook.com thread than to an unknown sender, even when the body is shaky.

How attackers turn a clean domain into a credible lure

Display names do most of the heavy lifting. A message from "NAB Fraud Team random.user123@gmail.com" looks plausible at a glance, especially on a phone where the address sits below the human-readable name. Some kits rotate the local part of the address to dodge keyword filters that look for exact bank domains.

Compromised legitimate accounts are a sterner problem. Aussie security analysts have seen fraudsters hijack dormant Outlook accounts that have been warm for years. Those accounts pass SPF, often pass DKIM, and only get caught when a human notices the language is off or the link points somewhere suss.

Crooks also lean on the local feel. Phishing campaigns aimed at Australians often reference Centrelink, Medicare, energy rebates, or flood assistance rounds. Pairing familiar branding with an everyday webmail domain is the bait that hooks people who would ignore a raw address from an unfamiliar TLD.

DMARC gaps leave the back door open

DMARC ties SPF and DKIM results back to the visible From address and tells receivers what to do when checks fail. Set to p=none, the policy is monitor-only and no messages are rejected. Set to quarantine or reject, the gate actually closes.

Many Australian organisations, including councils, schools, and mid-tier retailers, still run at p=none or have no DMARC record at all. That gives phishers free rein to impersonate those domains with confidence. Mail that fails DMARC still gets delivered because the owner's policy says to do nothing about it.

Reviewing whether your outbound tools align with your published policy is worthwhile, and a third-party trust guide covers the practical steps Australian admins can take.

What SPF alone misses in the real world

A pass tells you a message came from where the domain said it would. It does not confirm the sender is genuine or that the link leads somewhere legitimate. The Australian Cyber Security Centre flags this in its Essential Eight guidance, where content scanning and DMARC enforcement sit alongside SPF as separate layers.

You can verify a sender's posture quickly through a trust score lookup before engaging with a message that feels off. These tools aggregate SPF, DKIM, DMARC, and reputation data to give a fuller picture than any single check.

Local MSPs in suburbs from Parramatta to Geelong are picking this up. They tell clients that phishing is not defeated at any single protocol and that awareness training still matters even with mail security in place.

Layered defences close the gap

Stopping these campaigns relies on stacking controls, not relying on one. DKIM protects message integrity, DMARC alignment protects the visible From address, and behavioural filtering catches cases where everything passes technical checks but the content reads dodgy. Adding the ACSC's ReportCyber button to the workflow means a quick report from an arvo break can feed into broader disruption efforts.

Locally run audits help too. Spotting whether internal CRMs or marketing platforms send through unapproved routes closes SPF gaps phishers count on, and periodic checks across domain settings surface services using outdated paths. With the basics dialled in, those free-mail phishing runs find much less traction against Australian inboxes.