Lappu AI Research · July 2026

DNS Attribution
Laundering

How legacy CNAMEs can place trusted institutional names beside externally controlled spam infrastructure—and distort how humans and systems interpret sender identity.

Research by Vivek Uppal · Lappu AI Research · Revision 1

The attribution path

01Trusted namespaceinstitution.edu
CNAME
02External controlthird-party.net
A / PTR
03Observed contextSMTP source IP

The visible relationship can look authoritative even when the institution neither operates nor authorizes the sender.

The core idea

DNS can lend a trusted name without lending trusted control.

DNS Attribution Laundering describes the deliberate use of a DNS relationship to make external infrastructure appear associated with a more trusted organization. The study's email-specific subtype—CNAME-Assisted SMTP Attribution Laundering—focuses on trusted hostnames that alias to infrastructure used in SMTP context.

The research also defines the intent-neutral condition DNS Attribution Contamination. That distinction matters: a risky DNS relationship can be proven from evidence, while deliberate abuse requires separate evidence of intent.

Point-in-time research graph · July 13, 2026

What the Utah-seeded expansion revealed

The aggregate graph is investigative context, not a claim that every associated asset is malicious.

1,449IP lookup records
412domain lookup records
3,487lineage edges
42countries observed
01

A distinct mechanism

The trusted name appeared through a DNS control path, not through SPF, DKIM, or alignment with the visible sender.

02

Confirmed mail evidence

Two phishing-source IPs were observed in the university case studies. The broader expanded graph was analyzed separately from those direct observations.

03

Address ballooning

Legacy aliases could resolve into large, shifting address sets—a warning sign when the hostname's documented purpose is narrow and historical.

04

Authentication stayed separate

SPF, DKIM, envelope-sender, and visible From identities did not implicate the universities in sending or authorizing the messages.

A careful vocabulary

Condition, technique, and authenticated identity are not the same thing.

Observed condition

DNS Attribution Contamination

A trusted DNS name becomes associated with external infrastructure in a way that may mislead attribution. This label makes no claim about intent.

Technique class

DNS Attribution Laundering

A DNS relationship is deliberately exploited or knowingly retained to borrow the attribution value of a more trusted namespace.

CNAME-Assisted SMTP Attribution Laundering

A trusted hostname follows a CNAME into external control and appears in SMTP infrastructure context, such as reverse/forward DNS or received-message evidence.

Why this is not SubdoMailing

SubdoMailing uses a compromised subdomain as an authenticated sending identity. Here, the trusted hostname supplies infrastructure context while the actual authenticated mail identities remain unrelated.

Investigation workflow

Reconstruct the chain before assigning the name.

  1. 01

    Preserve receiver evidence

    Retain complete headers, source IPs, authentication results, timestamps, and gateway observations.

  2. 02

    Reproduce the DNS chain

    Correlate PTR, forward lookup, CNAME lineage, and terminal A or AAAA records at the time of observation.

  3. 03

    Separate direct from associated

    Keep confirmed SMTP sources distinct from assets reached through forward, reverse, provider, and secondary-domain expansion.

  4. 04

    Classify evidence and intent separately

    Document the technical condition first. Escalate to intentional laundering only when evidence supports deliberate exploitation or knowing retention.

For domain owners

Retire trust you no longer control.

Inventory external CNAMEs, verify target ownership continuously, alert on unexpected address expansion, and preserve evidence before removing a risky record.

For mail receivers

Treat DNS names as context—not identity.

Compare infrastructure hostnames with SPF, DKIM, envelope sender, visible From, and HELO/EHLO. Notify the trusted domain owner without over-attributing the sender.

Canonical research

Read the evidence, case studies, methodology, and limitations.

This page is an independent, plain-language overview. The original Lappu AI publication is the authoritative record and includes the Stanford and University of Utah case studies, disclosure timeline, limitations, corrections policy, references, and dataset notes.