Threat Overview
Attackers increasingly leverage legitimate mail-sending infrastructure, either by compromising accounts, abusing third-party services, or spoofing subdomains, to deliver phishing emails that appear authentic. These methods boost deliverability, credibility, and success rates.
Common Techniques Used by Attackers
Rather than blatantly impersonating a brand, attackers often use legitimate mail‑sending infrastructure or make the message look like it came from such infrastructure. That gives the email better deliverability and credibility. There are three common variants:
- Compromised Sending Account:
A malicious actor gains access to a bona fide bulk‑mailing account (e.g., an org’s Mailgun, SendGrid, or corporate notification system) and sends phishing content from an otherwise reputable sender. - Abuse of Third‑party Services:
Attackers register or exploit third‑party transactional email services (or free tiers) to send high‑volume messages that appear to be from a trusted service domain or subdomain. - Spoofing & Subdomain Trickery:
The attacker forges headers (From, Reply‑To, Return‑Path) or uses look‑alike subdomains (e.g., notify.example‑mail.com or em123.example.com) to mimic legitimate traffic. They may also chain redirects so a seemingly safe link first goes to the sending service, then to a phishing page.
All three increase the chance the email reaches an inbox and that the recipient trusts it enough to click a link or open an attachment.


