We Monitored 364 Domains Owned by One of America's Top Real Estate Teams. 79 Were Sending Emails From China, Russia, and a Dozen Other Countries.

DMARC monitoring heatmap showing 48 days of failed email authentication across the dormant domain portfolio — every day red.

Nobody hacked anything. Nobody needed to: The domains were parked, forgotten, and unprotected — like most of the domains owned by most real estate teams in the country.

In the world of real estate, Gary Ashton needs no introduction. His team, The Ashton Real Estate Group at RE/MAX Advantage in Nashville, is the No. 1 RE/MAX team in the world and one of the most recognizable names in the industry.

Like every team that has reached this level of success, they own a lot of domains: farm sites for neighborhoods, old brands, defensive registrations, campaign ideas, etc. In total, they own 364 domains, and only a handful of them have email actively running.

But, unlike many organizations, this team actually decided to take a look at their parked domains. As part of a portfolio-wide security program (which aimed to protect the buyers and sellers who trust mail with their name on it, in addition to the brand itself), they had us connect all 364 domains to DMARC monitoring on July 16. The reports started arriving immediately:

We found that 79 supposedly dormant domains were sending email. These domains were sending a slow, steady stream of unauthenticated messages from IP addresses in more than a dozen countries, led by China and Russia. These weren’t coming from Gary’s team, or from any vendor they had ever used. And not one of those domains had a policy telling mailbox providers to refuse mail sent in their name.

Bar chart of failed-authentication email traffic by source country: China 44, Russia 34, Australia 28, US 26, Brazil 21, followed by Pakistan, India, Vietnam, Ukraine, Japan, Hong Kong and Korea
Failed-authentication traffic across the dormant portfolio by source country over 90 days. China and Russia lead, followed by Australia, the US, and Brazil.

What was in these messages? Aggregate DMARC reports show the traffic, not the message bodies, but this type of traffic typically exists for a few purposes: fake invoices and wire instructions timed to real transactions, password-reset lookalikes that phish agents' CRM and email logins, and scams that borrow a trusted name to slip past spam filters. In a business where a single closing can turn on one email, this is exactly the type of illegitimate mail nobody wants to have sent in their name.

In the five weeks after monitoring went live, the dormant portion of the portfolio produced 235 delivery reports from mailbox providers around the world. The authentication compliance across all of these messages was 0.0%. Not a single message was legitimate, which makes sense, since one would expect the legitimate volume on these parked domains to be zero.

DMARC monitoring dashboard showing 0.0% compliance, 0.0% DKIM pass and 0.0% SPF pass across 278 records, with a 90-day heatmap showing 48 bad days
The dormant portion of the portfolio since monitoring began in July: 278 reports in total (235 in the five weeks before enforcement, 43 after), 0% passing authentication, and failures observed on 48 separate days.
We put a lot of effort into marketing and lead generation, and buying domains that could help now or in the future was the logical next step. If someone is sending email with our name on it, we want it shut down before it ever reaches a client or anyone we weren't actually sending to.‍

— Gary Ashton, Founder, The Ashton Real Estate Group.

Anyone can send email "from" your domain. That's not a bug — it's how email works.

The From line in an email is just text. Any server on the internet can put any domain in the From line and hit send, unless a domain's DNS records say otherwise. SPF, DKIM, and DMARC exist precisely to close that gap: DNS records let a domain owner determine not only who is allowed to send emails as them, but also what the world's mailbox providers should do with everything else.

If no one ever publishes those records on a given domain, "sending as you" is allowed by default.

And, in our experience, nobody is thinking about parked domains at all, much less publishing those crucial DNS records.

How we can see this

With DMARC aggregate reporting, a domain owner can see all the messages the world's mailbox providers receive that claim to come from their domain(s) — not just the mail they send as the legitimate domain owners, but everything that is sent in their name. Gmail, Microsoft, Yahoo, Mail.Ru, and hundreds of other providers report this information daily to any domain that asks. The only problem is that almost nobody asks, especially not for domains they think nobody uses.

DMARC report rows showing unauthenticated mail claiming to come from dormant domains, with source IPs in Russia, Korea, India, Vietnam, Bulgaria, Brazil and China, every row failing SPF and DKIM, including a Google quarantine of a message claiming to be theashtongroup.com
A single view of the incoming reports: unauthenticated mail claiming to come from the team's dormant domains, from source IPs in Russia, Korea, India, Vietnam, Bulgaria, Brazil, and China. Every row fails both SPF and DKIM. Note the Google row: Gmail has quarantined a message claiming to be sent from theashtongroup.com, indicating that mailbox providers have already been treating the portfolio's name as suspect.

Two details in the data tell you who is doing the sending. First, the traffic is sparse. For most of these domains, just a handful of messages are sent per day; for the worst cases we monitor, it can be hundreds per day, which still might not be enough to cause suspicion. This means no single domain ever generates enough to trip an alarm anywhere. Second, the sending hostnames resolve to consumer ISP ranges scattered across the world, including a Japanese cable provider, a Vietnamese telecom, and a Brazilian broadband network. That pattern — distributed across residential connections in a dozen countries — is the signature of botnet traffic, rather than any single spammer with a server.

List of dozens of dormant domains with failing email traffic, including tnrealestate.com, buyingnashville.com, wesellnashvillehomes.com and titansrealestate.com
The breadth of the issue: dozens of the team's domains with failing traffic in a single 90-day window. These include neighborhood farm sites, old brands, and defensive registrations.

Why a parked domain isn't a harmless domain

It's perfect camouflage. Every one of these domains is a real domain registered to a real, recognizable business. According to the FBI, business email compromise attacks cost victims more than $3 billion in 2025; in an industry where wire fraud runs on impersonating agents, a genuine domain owned by a famous team beats any lookalike a scammer could register. And this specific portfolio is on the quiet end of what we see: Another real estate team we monitor gets roughly a thousand spoofed messages a day sent from a single legacy domain, with some of them landing in the inboxes of the team's own agents.

It's building a criminal record in your name. Mailbox providers and blocklist operators keep reputation history on every sending domain, and they don't care whether you knew about the traffic. A parked domain that is leaking spam over a long enough period of time ends up getting blocklisted like any other spam source. Then, when you finally launch something on that domain, you’re greeted with an unpleasant surprise: Your messages go straight to the spam folder.

LinkedIn comment by Steve Freegard, Senior Product Owner of Abusix Intelligence: "FYI – if we see any parked domains doing any significant volume or hitting any type of trap – the domain is immediately listed.
Steve Freegard of Abusix Intelligence, one of the industry's major blocklist operators, responding to our findings on LinkedIn.

This isn't just a real estate problem, either. We've found the same pattern in both manufacturing and sports venues, as well as in our earlier research into hijacked university subdomains. When organizations accumulate domains faster than they retire them, the forgotten ones are likely to leak.

Publishing four DNS records immediately fixes the problem

For a domain that should never send email, having a small, standardized record set tells every mailbox provider on earth that this domain should not be sending anything, and that the provider should therefore reject anything coming from that domain.

DNS lockdown record set for a dormant domain: null MX record, SPF v=spf1 -all, empty wildcard DKIM key, and DMARC p=reject policy
The lockdown set: a null MX (the domain accepts no mail), v=spf1 -all (no server may send for it), an empty wildcard DKIM key (revokes any leftover signing keys), and DMARC p=reject (discard anything that fails).

‍We rolled these records out across the affected domains, and the results were immediate. In the five weeks before enforcement, there were 235 reports of unauthorized mail. In the five weeks after enforcement, there were 43 — and every one of them was discarded at the mailbox provider instead of being delivered. Once the mail stopped getting through, most of the senders simply moved on. Botnets don't waste capacity on domains that fight back.

DMARC report rows after enforcement: spoofed mail claiming to come from locked-down dormant domains now shows disposition reject at the mailbox provider
After enforcement: The remaining spoofed mail claiming to come from locked-down domains is rejected at the mailbox provider instead of delivered. The little traffic that still arrives no longer gets through.

It’s important to keep this monitoring on permanently, both to watch the enforcement hold, and to make sure that any domain that goes back into real use is properly configured before the first campaign.

If you own more than 10 domains, assume this is happening to you

Count your domains. All registrars, all accounts; even the ones your old brokerage bought. Most team leaders are off from what they initially thought by double digits.

Split them into two piles: domains that legitimately send email, and domains that should send nothing. The second pile is bigger — and it's probably made up of all the domains nobody ever secured.

Lock down the second pile and monitor everything. Publishing the record set above takes mere minutes per domain, and DMARC reporting is free to receive. If none of this means anything to you, a note including the sentence "Please lock down our unused domains for email and put all of them under DMARC monitoring." should be more than enough instruction for any competent provider.

For a takeaway message, it is worth saying that nothing here is unique to this portfolio. Low-grade abuse of parked domains is the background radiation of the internet — we find it in nearly every large portfolio we connect. What is unusual is for a team to actually go looking for it, shut it down within weeks, and then publish the results to encourage their peers to check their own portfolios. That is what taking client security seriously looks like as an industry leader.

The full technical case study on the Ashton portfolio can be found here: https://www.sh.consulting/ashton-real-estate-dormant-domains

Get the free Email Deliverability Guide

15 rules for reaching the inbox. Used by 450+ organizations.

Download the Guide
Try dmarc.cc — check DMARC for 200 domains at once. Built by SH Consulting ✕