Network · 204 days ago
Threat actors are abusing .arpa and ip6.arpa reverse PTR records to hide phishing links and bypass domain-reputation checks. Email gateways and reputation services often miss PTR-derived hostnames, reducing detection especially for IPv6-based campaigns.
3 sources covering this story
Hacker abusing .arpa domain to evade phishing detection, says Infoblox
The tactic combines IPv6 tunneling and domain abuse to redirect victims to malicious websites.
Internet Infrastructure TLD .arpa Abused in Phishing Attacks
Abusing DNS record management controls, the threat actor hides the location of malicious content via Cloudflare.
Hackers abuse .arpa DNS and ipv6 to evade phishing defenses
Threat actors are abusing the special-use ".arpa" domain and IPv6 reverse DNS in phishing campaigns that more easily evade domain reputation checks and email security gateways.
Part of the PlainSec briefing for 2026-03-09