I registered a long-abandoned corporate domain out of curiosity. Within weeks it was quietly collecting live mail, DMARC telemetry, and forwarded correspondence for two brands that are still very much in business.
Every company leaves a trail of domains behind it. Product names that never shipped, campaign microsites, regional variants, and the dangerous ones: the corporate domains of businesses that were acquired, merged, or rebranded. When the org chart changes, someone remembers to move the website. Almost nobody remembers the domain was also carrying email, DNS records, and third-party account registrations that quietly keep working long after the nameplate comes down.
This is a story about one of those domains. It is a clean, real-world example of a class of problem I run into constantly in deliverability and DNS security work, and it shows how little effort it takes to turn an administrative oversight into a serious interception and impersonation surface. There were no exploits and no hacking involved. There was a domain that was available to register, and a credit card.
The short version: a former corporate email domain for two well-known performance-parts brands, doverpmi.com, had lapsed and was free to register. I registered it. Almost immediately it began receiving more than 800 live emails intended for former employees, plus daily DMARC aggregate reports for two brands that are still actively trading. Mail addressed to people at other companies was being forwarded into it. And it pulled in a steady stream of phishing and fraud aimed at the old mailboxes. Anyone could have registered this domain. Whoever holds it is handed a ready-made business email compromise toolkit, and it takes no technical skill to use.
A corporate domain that outlived its owner
doverpmi.com was the corporate domain of Performance Motorsports, Inc. (PMI), a holding company that consolidated a portfolio of high-performance engine-component brands during the years it operated under the industrial conglomerate Dover Corporation. Under that umbrella sat names anyone in the performance-parts world will recognize, including JE Pistons and Wiseco, each running its own consumer-facing website while sharing PMI's corporate back-office and email identity.
You don't have to take my word for the lineage. The public archive tells the whole story. Here is the PMI corporate site as it stood in 2007, complete with the PMI and Wiseco branding, the "owned by Dover Corporation" description, and a live Dover stock ticker.

At some point after the mid-2010s the portfolio changed hands and was rebranded, and the brands live on today under new ownership. The doverpmi.com domain itself was quietly dropped. By early 2022 the archive shows it had already flipped to a domain-reseller parking page, listed for sale, complete with a view counter.

That gap is the entire vulnerability: a domain abandoned at the registration level while still being referenced by live DNS records, live mail senders, and live third-party accounts. This is the same failure mode I wrote about when a client's domain came under attack days after a lapse, in Never Let Your Domain Expire (Hackers Are Watching). The difference here is that the domain didn't just get spoofed. It kept doing its old job.
Step one: register it, then wait
Confirming the domain was unregistered took seconds. I registered it through ordinary channels and pointed it at a catch-all, so that any address, anything@doverpmi.com, would resolve to a single inbox. No privileged access and no exploitation of anyone's systems. I registered an available domain, the way anyone can register an available domain.
Then the mail started arriving, and it arrived in volume and variety I didn't expect.

Three things in that first inbox preview everything that follows. The mailboxes are person-specific, with outreach still personalized to named former staff. Brand-relevant intelligence arrives on its own: industry newsletters and supplier mail that tell a holder what the old company bought and who it dealt with, including a reply still addressed to "Performance Motorsports Inc." And the domain is already a magnet for fraud, which sets up the most dangerous problem of all.
The DMARC reports of two live brands were still flowing in
This is the finding with the clearest, most provable link to businesses that are still operating.
DMARC lets a domain owner tell mailbox providers how to handle mail claiming to be from them. As part of that, you publish a rua address: a mailbox where providers send aggregate reports, which are daily XML summaries of everyone who sent mail claiming to be your domain, whether it authenticated, and from where.
Here is the problem. The DMARC records for jepistons.com and wiseco.com, both live and both trading, still list a rua address on doverpmi.com. So every compliant mailbox provider ships those brands' DMARC reports to a domain I now control.


I have watched this exact pattern before. When a domain we monitored was acquired, it began receiving a flood of other organizations' DMARC reports overnight, which I documented in Unexpected DMARC Reports Flood emvdmarc[.]com After Domain Acquisition. It happens for the same reason a documentation domain in Cloudflare's own DMARC guidance turned out to be unregistered: a rua address is a promise that a mailbox will exist and be controlled by the right people, and DNS has no way to enforce that promise.
People wave away DMARC reports as low-value metadata, and that is a mistake. Aggregated across a stream of daily reports, they reconstruct a detailed, continuously updated map of how a brand sends email:
- Every sending source and service in use: ESPs, the Microsoft 365 or Google Workspace tenant, transactional providers, security gateways, and any shadow-IT senders.
- The specific IPs and sending hosts behind each source, including internal and origin infrastructure.
- Per-source volumes, which shows which platforms carry the most mail and how campaigns are timed.
- SPF and DKIM pass or fail per source, which shows exactly where authentication is weak.
- Overall DMARC compliance and enforcement policy.
- Envelope-to domains and forwarder results, which show which organizations receive the brand's mail and who forwards it.
To make it concrete, parsing the feed for one brand showed most traffic routing through a single marketing platform (Klaviyo), with an internal MTA cluster of several servers and a Microsoft 365 tenant handling a few thousand messages a month behind it.


This is the same category of exposure a fintech left open for years, mapped in detail in FinTech AccessPay Exposed Internal Email Infrastructure Data for Years. The consequence is worth stating plainly: re-registering the domain does not fix it. The root cause lives in the brands' own DNS. As long as jepistons.com and wiseco.com publish a rua pointing at doverpmi.com, every provider keeps shipping their reports to whoever controls that domain. The repair has to be made in the brand-side DMARC records, and until it is, the brands are flying blind, not receiving the telemetry that would reveal spoofing or deliverability problems.
It still receives live business mail
Beyond automated reports, the domain receives genuine, human business correspondence, from real senders who believe a specific person still reads mail here.



What separates this from ordinary spam is the mix: person-specific correspondence, vendor relationship mail, and live sales enquiries. Those are the exact categories that let whoever holds the domain not just read the old company's mail, but convincingly reply as it.
Mail meant for other companies gets forwarded in
Some messages arrive at doverpmi.com mailboxes even though their visible recipient is an address at a completely different company. Legacy alias and forwarding rules, set up years ago and never torn down, still funnel third-party mail through the lapsed domain.
The visible headers say one thing and the mail server's delivery record says another. Take this bulk supplier offer, addressed on its face to a sales address at another company entirely:

In the inbound Received: line, the real delivery recipient, the SMTP envelope RCPT TO, is a doverpmi.com mailbox:

The same pattern shows up with authenticated corporate mail addressed to a person at another firm entirely. Gmail's own analysis confirms the sender passed DKIM and DMARC:

And the raw headers again show the envelope terminating at a doverpmi.com mailbox:

These are not marketing lists. The mail server's own records show the lapsed domain is the true SMTP destination for authenticated business mail directed at named individuals, including people at other organizations. Legacy forwarding is quietly redirecting live third-party correspondence into a domain anyone could have bought.
Dead mailboxes still receive password resets
This is the part that ties everything into genuine account-takeover risk.
When an employee leaves, their accounts on external services are rarely deleted. They are abandoned. Many vendors never clean their lists, so they keep mailing dead addresses for years with account notifications, security alerts, and password-reset links. If the domain those addresses live on has been abandoned too, whoever controls the domain receives the reset mail, and taking over the old account is often trivial. It is the same mechanism that makes a dropped domain so dangerous in the JustDropped password-reuse example: the domain becomes the recovery channel for everything ever registered under it.
To confirm this, I briefly allowed a single message through the domain, a live password reset for a former employee's account at a major enterprise vendor (SAP), then re-enabled rejection. Here is that reset, with the recipient, the date, and the entire reset token removed:

This is what turns a passive nuisance into an active threat. A former corporate domain doesn't only leak old mail. It becomes a skeleton key to the accounts registered under it, precisely because companies keep mailing credentials to addresses that stopped existing long ago.
Why this adds up to a business email compromise kit
Take the four pieces together. A single lapsed domain, registered by anyone with a few dollars, delivers the ability to receive a live company's vendor, partner, and sales mail and to reply as that company. It delivers account-takeover leverage over every external service a former employee registered under the domain, through password-reset interception. It delivers a continuously updated intelligence feed on two active brands' sending infrastructure and authentication gaps, from misrouted DMARC reports. And it delivers inbound third-party correspondence from other companies, funneled in by forgotten forwarding rules.
That is, close to line for line, the toolkit behind business email compromise fraud, which sits consistently among the most expensive categories of cybercrime by reported losses. A real attacker wouldn't disclose it. They would sit quietly, separate the legitimate mail from the noise, and pick their moment.
A domain someone forgot to renew is one of the most dangerous attack vectors around, and part of why is that exploiting it requires no hacking at all. If you own brands with a corporate history of acquisitions, rebrands, or spin-offs, the odds are good that one of your retired domains is still referenced somewhere in live DNS. We audit exactly this kind of exposure across a company's full domain estate, and it is usually the forgotten domains, not the flagship one, that are leaking.
What I did with the domain
For the record, the exposure here is passive in my hands. I registered the domain defensively during legitimate research, accessed no one's systems, and used none of the captured data. Rather than let it sit as a live collection point, I configured it to reject inbound mail outright.

How to find and close this gap
If you own brands with a corporate history, here is the checklist.
- Fix your DMARC reporting addresses first. Repoint every
ruaandrufthat references a domain you no longer control to a mailbox on a domain you do. This is the highest priority because it stops the telemetry leak immediately. - Audit every brand and corporate domain for references to retired domains in DMARC, SPF (
include:andredirect=), MX, and forwarding or alias rules, including cross-company forwarding you may have forgotten. - Hunt for dangling DNS. Any domain named in any record of your DNS zones, whether a CNAME target, a mail host, or an SPF include, is one you had better still control. If someone else can register it, it is a takeover waiting to happen. This is the same root cause behind the subdomain takeover campaign I found across 34 US universities: a DNS record that outlived the thing it pointed at.
- Inventory external accounts still tied to addresses on retired domains, including vendor and SaaS logins, distribution lists, and notification contacts, then migrate them. Treat departed-employee accounts as needing deletion, not just deactivation.
- Never fully release a domain that ever carried mail. Retiring a domain the right way means keeping it registered defensively with a null MX, a hard
-allSPF, and ap=rejectDMARC policy, so it can neither receive mail nor be spoofed. The registration fee is a rounding error against the exposure.
For the vendors on the other side of this, the platforms still mailing password resets to addresses dead for years, list hygiene is a security control. Every credential-recovery email sent to an abandoned address is a small gift to whoever inherits that domain.
Disclosure
Before publishing, I made repeated good-faith attempts to reach Race Winning Brands. I emailed several people at the company directly, wrote to the standard role addresses for abuse, postmaster, and security, and sent connection requests to relevant staff on LinkedIn. Some of the role addresses did not resolve and the LinkedIn requests went unanswered, so the outreach went out across every channel I could find, well ahead of this write-up, to give the affected parties time to act.

This class of exposure almost never shows up on the flagship domain everyone watches. It hides in the domains left behind by an acquisition or a rebrand, and the first sign is usually a DMARC feed nobody is reading. SH Consulting audits full domain estates for exactly these gaps: misrouted DMARC reporting, dangling DNS, and retired domains that still carry live mail. If your company has changed shape over the years, book a call and we'll help you find the doors that were left open. More on how we work at www.sh.consulting.
Disclosure: This issue was reported to the affected brand owner through multiple channels ahead of publication. This write-up describes the class of vulnerability and the mechanics involved. Sensitive third-party details captured incidentally have been redacted or omitted, and no reset tokens, personal recipient addresses, or exploitable material are reproduced. The purpose is to help other organizations find and close the same gap in their own estates.






