Network & Infrastructure · Phishing / BEC
Phishers Use .arpa IPv6 Reverse DNS to Evade Email Defenses Threat actors are abusing .arpa and ip6.arpa reverse PTR records to hide phishing links and bypass domain-reputation checks. Email gateways and reputation services often miss PTR-derived hostnames, reducing detection especially for IPv6-based campaigns.
3 sources · Mar 9
Timeline Sources Mar 9 CSO Online
Hacker abusing .arpa domain to evade phishing detection, says Infoblox
The tactic combines IPv6 tunneling and domain abuse to redirect victims to malicious websites.
original Mar 9 SecurityWeek
Internet Infrastructure TLD .arpa Abused in Phishing Attacks
Abusing DNS record management controls, the threat actor hides the location of malicious content via Cloudflare.
original Mar 8 BleepingComputer
Hackers abuse .arpa DNS and ipv6 to evade phishing defenses
Threat actors are abusing the special-use ".arpa" domain and IPv6 reverse DNS in phishing campaigns that more easily evade domain reputation checks and email security gateways.
original Part of the PlainSec briefing for 2026-03-09
Every edition of this story: Phishers Use .arpa IPv6 Reverse DNS to Evade Email Defenses
Network & Infrastructure · Phishing / BEC
Phishers Use .arpa IPv6 Reverse DNS to Evade Email Defenses Threat actors are abusing .arpa and ip6.arpa reverse PTR records to hide phishing links and bypass domain-reputation checks. Email gateways and reputation services often miss PTR-derived hostnames, reducing detection especially for IPv6-based campaigns.
3 sources · Mar 9
Timeline Sources Mar 9 CSO Online
Hacker abusing .arpa domain to evade phishing detection, says Infoblox
The tactic combines IPv6 tunneling and domain abuse to redirect victims to malicious websites.
original Mar 9 SecurityWeek
Internet Infrastructure TLD .arpa Abused in Phishing Attacks
Abusing DNS record management controls, the threat actor hides the location of malicious content via Cloudflare.
original Mar 8 BleepingComputer
Hackers abuse .arpa DNS and ipv6 to evade phishing defenses
Threat actors are abusing the special-use ".arpa" domain and IPv6 reverse DNS in phishing campaigns that more easily evade domain reputation checks and email security gateways.
original Part of the PlainSec briefing for 2026-03-09
Every edition of this story: Phishers Use .arpa IPv6 Reverse DNS to Evade Email Defenses