Where this stands: Within a day of our LinkedIn post going live on August 20, 2026, Eden Park removed spamcontrol.co.nz from its DMARC record. Nobody from Eden Park contacted us at the time. On 24 August, after the post passed 90,000 impressions, an Eden Park IT manager we had been given as a contact months earlier replied for the first time. We offered to hand over the roughly one year of aggregate reports we held or delete them. Eden Park asked for deletion, and we deleted them on August 26. The domain is out of their DNS.
The original owner turned out to be Fujitsu, which had run spamcontrol.co.nz as a New Zealand email-filtering service and retired it in June 2021 — the reference in Eden Park's DNS simply outlived the service. We still hold the domain and have offered to transfer it back to Fujitsu. iTnews covered the case here, with confirmation from both Eden Park and Fujitsu. Details on the domain below.
What the record looked like
The DMARC record for edenpark.co.nz was:
v=DMARC1; p=none; sp=none; rua=mailto:abuse@spamcontrol.co.nz, mailto:dmarc_agg@vali.email; ruf=mailto:abuse@spamcontrol.co.nz; rf=afrf; pct=100; ri=86400;
p=none and sp=none mean no DMARC enforcement. A message can fail DMARC as @edenpark.co.nz and the published policy still doesn't ask the receiver to quarantine or reject it. Whatever filtering happens after that is the receiver's own.
rua= is where aggregate reports go. Every day, Google, Microsoft, Yahoo and other providers send a summary of every message they received claiming to be from edenpark.co.nz: sending IPs, volumes, whether SPF and DKIM passed. One of the two addresses pointed at spamcontrol.co.nz.
ruf= is where forensic reports go. These carry message-level detail for failures. The only address in that tag was at spamcontrol.co.nz. The remaining tags are defaults.

What spamcontrol.co.nz used to be
Certificate transparency logs for the domain show quarantine, smtp and smtp2 subdomains, which is the shape of a hosted email filtering service. The Wayback Machine has nine captures of a live site between May 22, 2010 and August 10, 2018, and nothing after that.

How long Eden Park's record had pointed at a dead domain we can't pin down precisely. .co.nz registry history is much harder to trace than .com. What we can say is that the last archived capture is from August 2018, and when we looked in September 2025 the domain was unregistered and available to anyone with a registrar account and a few dollars.
What arrived once we owned it
There was nothing to break into. Eden Park's own DNS was instructing the world to send the reports to whoever held spamcontrol.co.nz, so once we held it, they simply started arriving. We accepted mail to the report address only. Everything else to the domain was rejected at SMTP.
No forensic reports arrived during the period we held the domain; the major providers do not send them.
Over the reporting window shown in the dashboard below, the domain received 12,615 report records for edenpark.co.nz. Compliance ran at 96.28% aligned, with DKIM passing on 96.3% of traffic and SPF on 85.4%. That gap is typical of a domain whose mail is carried by hosted platforms: DKIM does the work and SPF fails wherever the envelope domain belongs to the vendor rather than to Eden Park.

The per-IP view shows a weekly rhythm. The four busiest sources are UK-hosted IPv6 addresses, each peaking around 100 messages a day, with a smaller US-hosted source underneath. Aggregate volume peaked around 600 messages a day. Volume is modest. This is a working business domain for a venue that deals with a lot of outside organizations.
With p=none and sp=none, the record asks receivers to do nothing. The 0.22% under "policy enforced" were spoofed messages that a few receivers quarantined or rejected on their own and reported as such.
How aggregate reports turn into a partner directory
Aggregate reports are designed to tell a domain owner who is sending as them. On their own, they don't say who the domain emails. The recipient side comes from a field that some reporters populate and some don't: envelope_to.
Microsoft's Enterprise Outlook reports include it; Google's do not. In the records table below, every row with google.com as the report origin shows a dash in the envelope-to column, and the rows from Enterprise Outlook and the multi-origin rows carry counts. The largest sending source alone shows 928 distinct envelope-to values across 383 source IPs.

Deduplicating envelope-to values across the reporting period gave us roughly 600 organizations that Eden Park exchanges mail with: sponsors, sports associations, event and catering companies, construction contractors, traffic management firms, government agencies, celebrity and talent agents.
Any one of those entries means little. All 600 together, updated daily, is a map of who Eden Park does business with: who handles construction, who runs event traffic control, which caterer is current, how often the venue deals with government, who owns sales and marketing. That is the list an attacker would otherwise have to build by hand. With p=none on the domain, the next step is a spoofed @edenpark.co.nz email to any one of them, and nothing in the record stops it.
We didn't act on any of the data beyond confirming the scope of the exposure.
Disclosure
We first reported this to Eden Park's published security and IT contacts in October 2025. Over the following months we tried leadership mailboxes, LinkedIn outreach to IT and security staff, and personal contacts at a New Zealand MSP who put it in front of an Eden Park IT manager. On August 7, 2026 we reported it to the NCSC, New Zealand's national cyber security centre, which acknowledged the report the same day. The domain came up for renewal that month and we renewed it, because letting it drop would hand the same visibility to whoever registered it next. We published on LinkedIn on August 20. The record was changed on 21 August, and Eden Park replied to us for the first time on August 24.
We found other New Zealand organizations with the same problem during this work, including one on a govt.nz domain. Those were reported and fixed.
Nobody we reached at Eden Park appeared to own the DNS record. Whoever wrote it was most likely the vendor, and the vendor was gone.
Who owned spamcontrol.co.nz
Registry data can't confirm this, but the public evidence is consistent. The subdomain history matches a hosted filtering and quarantine service, and publicly indexed business-directory listings show several Fujitsu New Zealand employees with @spamcontrol.co.nz addresses. The listings suggest the service was run by or for Fujitsu NZ, and that Eden Park's DMARC record was written while Eden Park was a customer of it. At some point the service was retired, the domain lapsed, and the record stayed.
If you ran this service or know who did, we would like to transfer the domain to you. No mail flows to it now other than the last of the report feeds, and we have no use for it beyond keeping it out of the wrong hands.
The same failure, three times this year
Eden Park is the third organization we've written about in 2026 with an expired domain in a DMARC reporting address:
- doverpmi.com: a lapsed corporate domain still receiving DMARC reports and live mail for two operating brands.
- gca-emailauth.org: the collection address in published DMARC guidance, expired, with the guidance still live and 86 domains still reporting to it.
- edenpark.co.nz: this post.
We find these because we scan DNS for exactly this failure, and it turns up constantly. DMARC gets set up once, usually by a vendor, and then nobody reads the record again. The vendor changes, the domain lapses, and the reports keep flowing to whoever picks it up.
Check your own domain
Look up the TXT record at _dmarc.example.com. Take every domain in the rua= and ruf= addresses. Confirm each one is registered, owned by you or by a vendor you currently pay, and has a working mailbox behind it. While you're there, look at the policy. If it still says p=none, the reports are telling you about spoofing that the record is doing nothing to stop.
If you have more than a handful of domains, dmarc.cc will check the reporting addresses in bulk for free.
SH Consulting audits DMARC records and reporting destinations for clients every week. If you want yours checked, book a call.
Alex Shakhov is the founder of SH Consulting, an email security and deliverability consultancy. SH Consulting monitors DMARC for 1,300+ domains across 900+ companies.






