Threat actors are abusing .arpa and ip6.arpa reverse PTR records to hide phishing links and bypass domain-reputation checks. Email gateways and reputation services often miss PTR-derived hostnames, reducing detection especially for IPv6-based campaigns.
Part of the PlainSec briefing for 2026-03-09