Nobody hacked anything. Nobody needed to: The domains were parked, forgotten, and unprotected — like most of the domains owned by most real estate teams in the country.
In the world of real estate, Gary Ashton needs no introduction. His team, The Ashton Real Estate Group at RE/MAX Advantage in Nashville, is the No. 1 RE/MAX team in the world and one of the most recognizable names in the industry.
Like every team that has reached this level of success, they own a lot of domains: farm sites for neighborhoods, old brands, defensive registrations, campaign ideas, etc. In total, they own 364 domains, and only a handful of them have email actively running.
But, unlike many organizations, this team actually decided to take a look at their parked domains. As part of a portfolio-wide security program (which aimed to protect the buyers and sellers who trust mail with their name on it, in addition to the brand itself), they had us connect all 364 domains to DMARC monitoring on July 16. The reports started arriving immediately:
We found that 79 supposedly dormant domains were sending email. These domains were sending a slow, steady stream of unauthenticated messages from IP addresses in more than a dozen countries, led by China and Russia. These weren’t coming from Gary’s team, or from any vendor they had ever used. And not one of those domains had a policy telling mailbox providers to refuse mail sent in their name.

What was in these messages? Aggregate DMARC reports show the traffic, not the message bodies, but this type of traffic typically exists for a few purposes: fake invoices and wire instructions timed to real transactions, password-reset lookalikes that phish agents' CRM and email logins, and scams that borrow a trusted name to slip past spam filters. In a business where a single closing can turn on one email, this is exactly the type of illegitimate mail nobody wants to have sent in their name.
In the five weeks after monitoring went live, the dormant portion of the portfolio produced 235 delivery reports from mailbox providers around the world. The authentication compliance across all of these messages was 0.0%. Not a single message was legitimate, which makes sense, since one would expect the legitimate volume on these parked domains to be zero.

We put a lot of effort into marketing and lead generation, and buying domains that could help now or in the future was the logical next step. If someone is sending email with our name on it, we want it shut down before it ever reaches a client or anyone we weren't actually sending to.
— Gary Ashton, Founder, The Ashton Real Estate Group.
Anyone can send email "from" your domain. That's not a bug — it's how email works.
The From line in an email is just text. Any server on the internet can put any domain in the From line and hit send, unless a domain's DNS records say otherwise. SPF, DKIM, and DMARC exist precisely to close that gap: DNS records let a domain owner determine not only who is allowed to send emails as them, but also what the world's mailbox providers should do with everything else.
If no one ever publishes those records on a given domain, "sending as you" is allowed by default.
And, in our experience, nobody is thinking about parked domains at all, much less publishing those crucial DNS records.
How we can see this
With DMARC aggregate reporting, a domain owner can see all the messages the world's mailbox providers receive that claim to come from their domain(s) — not just the mail they send as the legitimate domain owners, but everything that is sent in their name. Gmail, Microsoft, Yahoo, Mail.Ru, and hundreds of other providers report this information daily to any domain that asks. The only problem is that almost nobody asks, especially not for domains they think nobody uses.

Two details in the data tell you who is doing the sending. First, the traffic is sparse. For most of these domains, just a handful of messages are sent per day; for the worst cases we monitor, it can be hundreds per day, which still might not be enough to cause suspicion. This means no single domain ever generates enough to trip an alarm anywhere. Second, the sending hostnames resolve to consumer ISP ranges scattered across the world, including a Japanese cable provider, a Vietnamese telecom, and a Brazilian broadband network. That pattern — distributed across residential connections in a dozen countries — is the signature of botnet traffic, rather than any single spammer with a server.

Why a parked domain isn't a harmless domain
It's perfect camouflage. Every one of these domains is a real domain registered to a real, recognizable business. According to the FBI, business email compromise attacks cost victims more than $3 billion in 2025; in an industry where wire fraud runs on impersonating agents, a genuine domain owned by a famous team beats any lookalike a scammer could register. And this specific portfolio is on the quiet end of what we see: Another real estate team we monitor gets roughly a thousand spoofed messages a day sent from a single legacy domain, with some of them landing in the inboxes of the team's own agents.
It's building a criminal record in your name. Mailbox providers and blocklist operators keep reputation history on every sending domain, and they don't care whether you knew about the traffic. A parked domain that is leaking spam over a long enough period of time ends up getting blocklisted like any other spam source. Then, when you finally launch something on that domain, you’re greeted with an unpleasant surprise: Your messages go straight to the spam folder.

This isn't just a real estate problem, either. We've found the same pattern in both manufacturing and sports venues, as well as in our earlier research into hijacked university subdomains. When organizations accumulate domains faster than they retire them, the forgotten ones are likely to leak.
Publishing four DNS records immediately fixes the problem
For a domain that should never send email, having a small, standardized record set tells every mailbox provider on earth that this domain should not be sending anything, and that the provider should therefore reject anything coming from that domain.

We rolled these records out across the affected domains, and the results were immediate. In the five weeks before enforcement, there were 235 reports of unauthorized mail. In the five weeks after enforcement, there were 43 — and every one of them was discarded at the mailbox provider instead of being delivered. Once the mail stopped getting through, most of the senders simply moved on. Botnets don't waste capacity on domains that fight back.

It’s important to keep this monitoring on permanently, both to watch the enforcement hold, and to make sure that any domain that goes back into real use is properly configured before the first campaign.
If you own more than 10 domains, assume this is happening to you
Count your domains. All registrars, all accounts; even the ones your old brokerage bought. Most team leaders are off from what they initially thought by double digits.
Split them into two piles: domains that legitimately send email, and domains that should send nothing. The second pile is bigger — and it's probably made up of all the domains nobody ever secured.
Lock down the second pile and monitor everything. Publishing the record set above takes mere minutes per domain, and DMARC reporting is free to receive. If none of this means anything to you, a note including the sentence "Please lock down our unused domains for email and put all of them under DMARC monitoring." should be more than enough instruction for any competent provider.
For a takeaway message, it is worth saying that nothing here is unique to this portfolio. Low-grade abuse of parked domains is the background radiation of the internet — we find it in nearly every large portfolio we connect. What is unusual is for a team to actually go looking for it, shut it down within weeks, and then publish the results to encourage their peers to check their own portfolios. That is what taking client security seriously looks like as an industry leader.
The full technical case study on the Ashton portfolio can be found here: https://www.sh.consulting/ashton-real-estate-dormant-domains






