A Lapsed Dover-Era Domain Is Still Leaking Email and DMARC Reports for JE Pistons and Wiseco

Catch-all inbox for a re-registered corporate domain, showing live vendor mail, motorsport-industry newsletters, and DMARC reports still arriving weeks after registration.

I registered a long-abandoned corporate domain out of curiosity. Within weeks it was quietly collecting live mail, DMARC telemetry, and forwarded correspondence for two brands that are still very much in business.

Every company leaves a trail of domains behind it. Product names that never shipped, campaign microsites, regional variants, and the dangerous ones: the corporate domains of businesses that were acquired, merged, or rebranded. When the org chart changes, someone remembers to move the website. Almost nobody remembers the domain was also carrying email, DNS records, and third-party account registrations that quietly keep working long after the nameplate comes down.

This is a story about one of those domains. It is a clean, real-world example of a class of problem I run into constantly in deliverability and DNS security work, and it shows how little effort it takes to turn an administrative oversight into a serious interception and impersonation surface. There were no exploits and no hacking involved. There was a domain that was available to register, and a credit card.

The short version: a former corporate email domain for two well-known performance-parts brands, doverpmi.com, had lapsed and was free to register. I registered it. Almost immediately it began receiving more than 800 live emails intended for former employees, plus daily DMARC aggregate reports for two brands that are still actively trading. Mail addressed to people at other companies was being forwarded into it. And it pulled in a steady stream of phishing and fraud aimed at the old mailboxes. Anyone could have registered this domain. Whoever holds it is handed a ready-made business email compromise toolkit, and it takes no technical skill to use.

A corporate domain that outlived its owner

doverpmi.com was the corporate domain of Performance Motorsports, Inc. (PMI), a holding company that consolidated a portfolio of high-performance engine-component brands during the years it operated under the industrial conglomerate Dover Corporation. Under that umbrella sat names anyone in the performance-parts world will recognize, including JE Pistons and Wiseco, each running its own consumer-facing website while sharing PMI's corporate back-office and email identity.

You don't have to take my word for the lineage. The public archive tells the whole story. Here is the PMI corporate site as it stood in 2007, complete with the PMI and Wiseco branding, the "owned by Dover Corporation" description, and a live Dover stock ticker.

Internet Archive capture of the Performance Motorsports (PMI) corporate homepage from 2007, showing "A Dover Company" branding and text describing PMI as a group of businesses owned by Dover Corporation.
The domain in its working life, 2007. A functioning corporate presence, not a parking page. Captures of the site as a live corporate property continue through at least 2016.

At some point after the mid-2010s the portfolio changed hands and was rebranded, and the brands live on today under new ownership. The doverpmi.com domain itself was quietly dropped. By early 2022 the archive shows it had already flipped to a domain-reseller parking page, listed for sale, complete with a view counter.

Internet Archive capture from 2022 showing doverpmi.com displaying a domain-reseller parking page that lists the domain for sale.
The domain up for grabs, 2022. From a living corporate domain to an open-market listing, with the email plumbing behind it never cleaned up

That gap is the entire vulnerability: a domain abandoned at the registration level while still being referenced by live DNS records, live mail senders, and live third-party accounts. This is the same failure mode I wrote about when a client's domain came under attack days after a lapse, in Never Let Your Domain Expire (Hackers Are Watching). The difference here is that the domain didn't just get spoofed. It kept doing its old job.

Step one: register it, then wait

Confirming the domain was unregistered took seconds. I registered it through ordinary channels and pointed it at a catch-all, so that any address, anything@doverpmi.com, would resolve to a single inbox. No privileged access and no exploitation of anyone's systems. I registered an available domain, the way anyone can register an available domain.

Then the mail started arriving, and it arrived in volume and variety I didn't expect.

Gmail catch-all inbox filtered to doverpmi.com, listing dozens of live messages including vendor invoices, motorsport-industry newsletters, sales enquiries and phishing attempts, with sender names blurred.
A catch-all inbox weeks after registration, filtered to doverpmi.com. Vendor invoices and accounts-receivable notices, a supplier reply still addressed to "Performance Motorsports Inc," a live purchase order, motorsport-industry mail, personalized business-development outreach, and threaded through all of it, heavy phishing and advance-fee fraud. Marketers, automated systems, and opportunists all still treat the domain as live.

Three things in that first inbox preview everything that follows. The mailboxes are person-specific, with outreach still personalized to named former staff. Brand-relevant intelligence arrives on its own: industry newsletters and supplier mail that tell a holder what the old company bought and who it dealt with, including a reply still addressed to "Performance Motorsports Inc." And the domain is already a magnet for fraud, which sets up the most dangerous problem of all.

The DMARC reports of two live brands were still flowing in

This is the finding with the clearest, most provable link to businesses that are still operating.

DMARC lets a domain owner tell mailbox providers how to handle mail claiming to be from them. As part of that, you publish a rua address: a mailbox where providers send aggregate reports, which are daily XML summaries of everyone who sent mail claiming to be your domain, whether it authenticated, and from where.

Here is the problem. The DMARC records for jepistons.com and wiseco.com, both live and both trading, still list a rua address on doverpmi.com. So every compliant mailbox provider ships those brands' DMARC reports to a domain I now control.

A Google DMARC aggregate report for the live brand jepistons.com delivered to a doverpmi.com mailbox.
Google's DMARC report for jepistons.com, delivered to doverpmi.com. The reporting domain is a live brand; the destination is a domain I registered off the open market.
A Zoho DMARC aggregate report for the live brand wiseco.com delivered to a doverpmi.com mailbox, confirming the same reporting gap on a second brand through a different provider.
The same for wiseco.com, via Zoho. Different brand, different provider, both delivering to the lapsed domain, confirming this is the published record in live DNS and not a one-off.

I have watched this exact pattern before. When a domain we monitored was acquired, it began receiving a flood of other organizations' DMARC reports overnight, which I documented in Unexpected DMARC Reports Flood emvdmarc[.]com After Domain Acquisition. It happens for the same reason a documentation domain in Cloudflare's own DMARC guidance turned out to be unregistered: a rua address is a promise that a mailbox will exist and be controlled by the right people, and DNS has no way to enforce that promise.

People wave away DMARC reports as low-value metadata, and that is a mistake. Aggregated across a stream of daily reports, they reconstruct a detailed, continuously updated map of how a brand sends email:

  • Every sending source and service in use: ESPs, the Microsoft 365 or Google Workspace tenant, transactional providers, security gateways, and any shadow-IT senders.
  • The specific IPs and sending hosts behind each source, including internal and origin infrastructure.
  • Per-source volumes, which shows which platforms carry the most mail and how campaigns are timed.
  • SPF and DKIM pass or fail per source, which shows exactly where authentication is weak.
  • Overall DMARC compliance and enforcement policy.
  • Envelope-to domains and forwarder results, which show which organizations receive the brand's mail and who forwards it.

To make it concrete, parsing the feed for one brand showed most traffic routing through a single marketing platform (Klaviyo), with an internal MTA cluster of several servers and a Microsoft 365 tenant handling a few thousand messages a month behind it.

A DMARC analytics dashboard reconstructed from jepistons.com reports, showing sending sources, per-source message counts and DKIM/SPF pass-fail results, with recipient addresses and source IPs masked.
jepistons.com, reconstructed: sending sources, host patterns, source-IP counts, volumes, DKIM and SPF results, and flags for misconfigured and unauthenticated traffic. The brand's entire mail footprint, assembled from reports it never received.
A DMARC analytics dashboard reconstructed from wiseco.com reports, showing high overall compliance but a much lower SPF pass rate, with recipient addresses and source IPs masked.
wiseco.com, reconstructed. Compliance and DKIM sit around 83 percent, but SPF passes on only about 50 percent of mail. That gap is exactly the weakness an attacker studies to craft spoofed mail that slips past filters, visible here to whoever holds the domain rather than to the brand.

This is the same category of exposure a fintech left open for years, mapped in detail in FinTech AccessPay Exposed Internal Email Infrastructure Data for Years. The consequence is worth stating plainly: re-registering the domain does not fix it. The root cause lives in the brands' own DNS. As long as jepistons.com and wiseco.com publish a rua pointing at doverpmi.com, every provider keeps shipping their reports to whoever controls that domain. The repair has to be made in the brand-side DMARC records, and until it is, the brands are flying blind, not receiving the telemetry that would reveal spoofing or deliverability problems.

Where are your DMARC reports actually going?

Free domain review covering DMARC reporting, SPF, and spoofing exposure across your full domain estate.

Book a 30-Minute Review

It still receives live business mail

Beyond automated reports, the domain receives genuine, human business correspondence, from real senders who believe a specific person still reads mail here.

A live purchase enquiry addressed to "Sales" at a doverpmi.com mailbox, with sender details blurred.
A purchase enquiry opening with "Hello Sales," directed at a legacy sales contact. Someone is trying to transact with a business that, as far as they know, still lives here.
An account notification from an HR and payroll platform still delivering to a legacy administrative address at doverpmi.com, with personal details blurred.
A message from an HR and payroll platform, DKIM-signed by the vendor, still delivering to a legacy admin address. This is the same class of system that sends password resets and security alerts.
Personalized business-development outreach addressed to a former staff member at doverpmi.com, with names blurred.
Business-development outreach addressed by first name. The sender believes a specific human still reads this inbox.

What separates this from ordinary spam is the mix: person-specific correspondence, vendor relationship mail, and live sales enquiries. Those are the exact categories that let whoever holds the domain not just read the old company's mail, but convincingly reply as it.

Mail meant for other companies gets forwarded in

Some messages arrive at doverpmi.com mailboxes even though their visible recipient is an address at a completely different company. Legacy alias and forwarding rules, set up years ago and never torn down, still funnel third-party mail through the lapsed domain.

The visible headers say one thing and the mail server's delivery record says another. Take this bulk supplier offer, addressed on its face to a sales address at another company entirely:

A supplier's bulk-pricing offer nominally addressed to a sales contact at another company, with sender, recipient and pricing details blurred.
Volume pricing for thousands of fuel injectors, DKIM-signed by the sender's domain, nominally addressed to a sales address at a different company. That is not where it landed.

In the inbound Received: line, the real delivery recipient, the SMTP envelope RCPT TO, is a doverpmi.com mailbox:

Raw email headers recording delivery "for <…@doverpmi.com>" despite a visible To address at a different company, with identifying fields masked.
Google's inbound server records the message delivered for <…@doverpmi.com>, with the sender's SPF and DKIM both passing, despite the visible To: pointing at another company's domain.

The same pattern shows up with authenticated corporate mail addressed to a person at another firm entirely. Gmail's own analysis confirms the sender passed DKIM and DMARC:

A Gmail security summary for a corporate sender at a different company, showing DKIM and DMARC pass under a p=reject policy, with the sender identity blurred.
A fully authenticated corporate sender whose mail nonetheless ends up at the lapsed domain.

And the raw headers again show the envelope terminating at a doverpmi.com mailbox:

Raw email headers recording delivery "for <…@doverpmi.com>" for an authenticated corporate sender, with sender domain, IPs and personal names masked.
The inbound Received: line records delivery for <…@doverpmi.com> while the sender's DMARC passes with a reject policy.

These are not marketing lists. The mail server's own records show the lapsed domain is the true SMTP destination for authenticated business mail directed at named individuals, including people at other organizations. Legacy forwarding is quietly redirecting live third-party correspondence into a domain anyone could have bought.

Dead mailboxes still receive password resets

This is the part that ties everything into genuine account-takeover risk.

When an employee leaves, their accounts on external services are rarely deleted. They are abandoned. Many vendors never clean their lists, so they keep mailing dead addresses for years with account notifications, security alerts, and password-reset links. If the domain those addresses live on has been abandoned too, whoever controls the domain receives the reset mail, and taking over the old account is often trivial. It is the same mechanism that makes a dropped domain so dangerous in the JustDropped password-reuse example: the domain becomes the recovery channel for everything ever registered under it.

To confirm this, I briefly allowed a single message through the domain, a live password reset for a former employee's account at a major enterprise vendor (SAP), then re-enabled rejection. Here is that reset, with the recipient, the date, and the entire reset token removed:

A redacted password-reset email from a major enterprise identity service, delivered to a doverpmi.com address for a former employee, with the recipient, timestamp and reset token removed.
A password reset from a major enterprise identity service, delivered to a @doverpmi.com mailbox for a long-departed employee. Recipient, timestamp, and the full reset token are redacted. The point is not the token but that a live credential-recovery link reached a domain anyone could register. Multiply that across every service a former employee ever signed up for.

This is what turns a passive nuisance into an active threat. A former corporate domain doesn't only leak old mail. It becomes a skeleton key to the accounts registered under it, precisely because companies keep mailing credentials to addresses that stopped existing long ago.

Why this adds up to a business email compromise kit

Take the four pieces together. A single lapsed domain, registered by anyone with a few dollars, delivers the ability to receive a live company's vendor, partner, and sales mail and to reply as that company. It delivers account-takeover leverage over every external service a former employee registered under the domain, through password-reset interception. It delivers a continuously updated intelligence feed on two active brands' sending infrastructure and authentication gaps, from misrouted DMARC reports. And it delivers inbound third-party correspondence from other companies, funneled in by forgotten forwarding rules.

That is, close to line for line, the toolkit behind business email compromise fraud, which sits consistently among the most expensive categories of cybercrime by reported losses. A real attacker wouldn't disclose it. They would sit quietly, separate the legitimate mail from the noise, and pick their moment.

A domain someone forgot to renew is one of the most dangerous attack vectors around, and part of why is that exploiting it requires no hacking at all. If you own brands with a corporate history of acquisitions, rebrands, or spin-offs, the odds are good that one of your retired domains is still referenced somewhere in live DNS. We audit exactly this kind of exposure across a company's full domain estate, and it is usually the forgotten domains, not the flagship one, that are leaking.

What I did with the domain

For the record, the exposure here is passive in my hands. I registered the domain defensively during legitimate research, accessed no one's systems, and used none of the captured data. Rather than let it sit as a live collection point, I configured it to reject inbound mail outright.

A mail rule configured to reject all inbound messages to doverpmi.com, bouncing them with a notice to remove the address.
The domain rejects mail by default, bouncing inbound messages with a notice to remove the address. The one exception was the brief, deliberate window used to capture the redacted password reset above, after which rejection was restored. That window is the reason the screenshot exists at all, given the domain otherwise bounces everything

How to find and close this gap

If you own brands with a corporate history, here is the checklist.

  1. Fix your DMARC reporting addresses first. Repoint every rua and ruf that references a domain you no longer control to a mailbox on a domain you do. This is the highest priority because it stops the telemetry leak immediately.
  2. Audit every brand and corporate domain for references to retired domains in DMARC, SPF (include: and redirect=), MX, and forwarding or alias rules, including cross-company forwarding you may have forgotten.
  3. Hunt for dangling DNS. Any domain named in any record of your DNS zones, whether a CNAME target, a mail host, or an SPF include, is one you had better still control. If someone else can register it, it is a takeover waiting to happen. This is the same root cause behind the subdomain takeover campaign I found across 34 US universities: a DNS record that outlived the thing it pointed at.
  4. Inventory external accounts still tied to addresses on retired domains, including vendor and SaaS logins, distribution lists, and notification contacts, then migrate them. Treat departed-employee accounts as needing deletion, not just deactivation.
  5. Never fully release a domain that ever carried mail. Retiring a domain the right way means keeping it registered defensively with a null MX, a hard -all SPF, and a p=reject DMARC policy, so it can neither receive mail nor be spoofed. The registration fee is a rounding error against the exposure.

For the vendors on the other side of this, the platforms still mailing password resets to addresses dead for years, list hygiene is a security control. Every credential-recovery email sent to an abandoned address is a small gift to whoever inherits that domain.

Disclosure

Before publishing, I made repeated good-faith attempts to reach Race Winning Brands. I emailed several people at the company directly, wrote to the standard role addresses for abuse, postmaster, and security, and sent connection requests to relevant staff on LinkedIn. Some of the role addresses did not resolve and the LinkedIn requests went unanswered, so the outreach went out across every channel I could find, well ahead of this write-up, to give the affected parties time to act.

A disclosure email to Race Winning Brands, subject "JE Pistons / Wiseco – email security disclosure," with sender and recipient details blurred.
One of several disclosure emails sent to Race Winning Brands ahead of publication, alongside outreach to the standard abuse, postmaster, and security addresses and to staff on LinkedIn. Sender and recipient details are redacted.

This class of exposure almost never shows up on the flagship domain everyone watches. It hides in the domains left behind by an acquisition or a rebrand, and the first sign is usually a DMARC feed nobody is reading. SH Consulting audits full domain estates for exactly these gaps: misrouted DMARC reporting, dangling DNS, and retired domains that still carry live mail. If your company has changed shape over the years, book a call and we'll help you find the doors that were left open. More on how we work at www.sh.consulting.

Disclosure: This issue was reported to the affected brand owner through multiple channels ahead of publication. This write-up describes the class of vulnerability and the mechanics involved. Sensitive third-party details captured incidentally have been redacted or omitted, and no reset tokens, personal recipient addresses, or exploitable material are reproduced. The purpose is to help other organizations find and close the same gap in their own estates.

Get the free Email Deliverability Guide

15 rules for reaching the inbox. Used by 450+ organizations.

Download the Guide
Try dmarc.cc — check DMARC for 200 domains at once. Built by SH Consulting