Phishers Use .arpa IPv6 Reverse DNS to Evade Email Defenses

Threat actors are abusing .arpa and ip6.arpa reverse PTR records to hide phishing links and bypass domain-reputation checks. Email gateways and reputation services often miss PTR-derived hostnames, reducing detection especially for IPv6-based campaigns.

Part of the PlainSec briefing for 2026-03-09

Sources