This cluster centers on 3287 connected domains tagged as HijackLoader, RemcosRAT, screenconnect. 617 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus. The connected infrastructure includes 1649 phone numbers (5408463620, 8552597377, 8007873903) with 7110 FTC complaints; 143 companies (Informative LLC, HomePlus Corporation, Doral Capital Corporation) with 8547081 CFPB complaints; 807 email addresses (kellymoore_64@yahoo.com, schantzsybg7@...
smtp.spamex.com
First seen Feb 24, 2026
- No SSL certificate
- 1 community report from users
Campaign Intelligence
Details
Related Domains
No known connections to other entities yet.
Community Reports
Guide: spamex email forwarding SPF DMARC This is a guide to using SPF and DMARC with Spamex (a disposable email forwarding service that one can setup with a custom domain). I wasn't able to find anything about doing this on my own (probably because not many people use this decades old service), and spamex doesn't have very good FAQ or help info especially regarding custom domain, so figured I'd post a guide after doing it. When using a custom domain with these services, it helps to have valid DMARC and SPF in the DNS of the custom domain, otherwise some things don't think the domain is ok for email. One negative about spamex, they don't enable TLS, so some email providers will show warnings about this regardless if they show pass for SPF/DMARC for the forwarded emails. SPF should be a DNS TXT record, and should be mostly the same for everyone, it's probably possible to narrow this down to fewer entries (likely just the one IP and relay name), but I'm going off of the SPF entry for the spamex just to make sure. Spot checking headers of multiple of the several thousands of emails over a few years shows that these are what's used for SPF: relay01.spamex.com with IP of 107.23.174.199 SPF DNS host/name: @ SPF value: v=spf1 ip4:107.23.174.199/32 ip4:107.23.136.169/32 ip4:107.23.151.155/32 a:smtp.spamex.com a:relay01.spamex.com ~all DMARC should also be a DNS TXT entry. Hostname (note that most DNS providers should properly append the domain name and just need this bit). In the value section, you MUST replace he name@example.com part with your own valid email. It works to use one of the forwarding disposable emails from spamex, the ASPF part is optional, that tells it to use relaxed not strict SPF processing. The p=none part tells it not to quarantine or reject SPF fails. Up to the individual person if they want to do that, more options and info can be found by looking up a DMARC syntax or DMARC guide online. SPF DNS host/name: _dmarc Value: v=DMARC1; p=none; ru
Share Your Experience
What's Your Exposure?
Know your risk exposure to this message with a Thorough Analysis. It returns a detailed report covering the complaint history, your data breach exposure, related scam entities, and risk signals tied to this email message. Check the box and enter your email address now.
NordVPN — Block threats and hide your IP from trackers
NordVPN encrypts your internet traffic and blocks malicious websites, ads, and trackers before they reach your device.