Lappu AI Research · July 2026
DNS Attribution
Laundering
How legacy CNAMEs can place trusted institutional names beside externally controlled spam infrastructure—and distort how humans and systems interpret sender identity.
Research by Vivek Uppal · Lappu AI Research · Revision 1
The attribution path
The visible relationship can look authoritative even when the institution neither operates nor authorizes the sender.
The core idea
DNS can lend a trusted name without lending trusted control.
DNS Attribution Laundering describes the deliberate use of a DNS relationship to make external infrastructure appear associated with a more trusted organization. The study's email-specific subtype—CNAME-Assisted SMTP Attribution Laundering—focuses on trusted hostnames that alias to infrastructure used in SMTP context.
The research also defines the intent-neutral condition DNS Attribution Contamination. That distinction matters: a risky DNS relationship can be proven from evidence, while deliberate abuse requires separate evidence of intent.
Point-in-time research graph · July 13, 2026
What the Utah-seeded expansion revealed
The aggregate graph is investigative context, not a claim that every associated asset is malicious.
A distinct mechanism
The trusted name appeared through a DNS control path, not through SPF, DKIM, or alignment with the visible sender.
Confirmed mail evidence
Two phishing-source IPs were observed in the university case studies. The broader expanded graph was analyzed separately from those direct observations.
Address ballooning
Legacy aliases could resolve into large, shifting address sets—a warning sign when the hostname's documented purpose is narrow and historical.
Authentication stayed separate
SPF, DKIM, envelope-sender, and visible From identities did not implicate the universities in sending or authorizing the messages.
A careful vocabulary
Condition, technique, and authenticated identity are not the same thing.
DNS Attribution Contamination
A trusted DNS name becomes associated with external infrastructure in a way that may mislead attribution. This label makes no claim about intent.
DNS Attribution Laundering
A DNS relationship is deliberately exploited or knowingly retained to borrow the attribution value of a more trusted namespace.
CNAME-Assisted SMTP Attribution Laundering
A trusted hostname follows a CNAME into external control and appears in SMTP infrastructure context, such as reverse/forward DNS or received-message evidence.
SubdoMailing uses a compromised subdomain as an authenticated sending identity. Here, the trusted hostname supplies infrastructure context while the actual authenticated mail identities remain unrelated.
Investigation workflow
Reconstruct the chain before assigning the name.
- 01
Preserve receiver evidence
Retain complete headers, source IPs, authentication results, timestamps, and gateway observations.
- 02
Reproduce the DNS chain
Correlate PTR, forward lookup, CNAME lineage, and terminal A or AAAA records at the time of observation.
- 03
Separate direct from associated
Keep confirmed SMTP sources distinct from assets reached through forward, reverse, provider, and secondary-domain expansion.
- 04
Classify evidence and intent separately
Document the technical condition first. Escalate to intentional laundering only when evidence supports deliberate exploitation or knowing retention.
For domain owners
Retire trust you no longer control.
Inventory external CNAMEs, verify target ownership continuously, alert on unexpected address expansion, and preserve evidence before removing a risky record.
For mail receivers
Treat DNS names as context—not identity.
Compare infrastructure hostnames with SPF, DKIM, envelope sender, visible From, and HELO/EHLO. Notify the trusted domain owner without over-attributing the sender.
Canonical research
Read the evidence, case studies, methodology, and limitations.
This page is an independent, plain-language overview. The original Lappu AI publication is the authoritative record and includes the Stanford and University of Utah case studies, disclosure timeline, limitations, corrections policy, references, and dataset notes.