No. Passing SPF and DKIM only shows that a domain authorized or signed the message, not that the sender is who they claim to be. Microsoft's Q2 2026 report, published July 23, describes a business email compromise campaign that passed both checks from a DKIM-configured Slovak domain. Check the real address, and verify requests by phone.
Key takeaways
- Microsoft says a June 1, 2026 business email compromise (BEC) campaign reached more than 67,000 users across more than 42,000 organizations in under three hours.
- The messages came from a DKIM-configured Slovak domain through Amazon SES, so Microsoft says they passed SPF and achieved DKIM alignment.
- Generic openers such as "Are you at your desk?" made up 87–92% of BEC first-contact emails each month in the quarter.
- DMARC on your domain protects against forgery of that exact domain. It doesn't stop mail from other domains, lookalikes or hijacked mailboxes.
- Process covers what authentication can't: check the real address and Reply-To, and confirm payment changes by phone.
What did Microsoft's Q2 2026 report find?
On July 23, 2026, Microsoft published its email threat landscape report for April to June 2026. According to Microsoft:
- It detected approximately 7.6 billion email-based phishing threats in the quarter, with monthly volume easing from 2.7 billion in April to 2.4 billion in June.
- BEC hit nearly 9 million attacks in April, up 121% from March, then fell to 3.4 million in May and settled at 3.9 million in June, both consistent with the usual monthly baseline.
- Generic outreach messages (like "Are you at your desk?") accounted for 87–92% of initial contact emails each month, while explicit requests for specific financial transactions or documents were just 3–8%.
How did the June 1 campaign work?
Among the notable campaigns in the report, Microsoft describes one BEC operation in detail. Over a send window of under three hours (14:08 to 16:52 UTC) on June 1, 2026, one actor reached more than 67,000 users across more than 42,000 organizations, almost all in the United States.
- Two lures. First, messages impersonating sales executives asked for aging report data and customer contact details. Then a payroll diversion lure impersonated the CEO or President to redirect salary payments to attacker-controlled bank accounts.
- Fully scripted. Python-generated messages went out through the Amazon Simple Email Service (SES) API, with spoofed executive display names inserted per message.
- Role mailboxes, not people. The actor addressed generic mailboxes such as "ar", "accountsreceivable", "hr" and "payroll", and used a 1×1 tracking pixel to see who opened the email.
- Authenticated. Microsoft says the messages "were sent from a DomainKeys Identified Mail (DKIM)-configured Slovak domain (ecajovna[.]sk) through SES, so they passed Sender Policy Framework (SPF) and achieved DKIM alignment."
- No links, no attachments. Both lures asked for a reply, and replies went to attacker-controlled mailboxes that mimicked legitimate providers: ilyff[.]com, j-gmails[.]com and x2mails[.]com.
If an email passes SPF and DKIM, is it legit?
Not necessarily. Each check answers one narrow question:
| Check | A pass proves | A pass does not prove |
|---|---|---|
| SPF | The sending server is authorized by the domain in the hidden envelope sender address | That the visible From address uses the same domain, or that the sender is honest |
| DKIM | The message was signed by the domain in the signature and wasn't altered in transit | That the signing domain belongs to anyone you know |
| DMARC | SPF or DKIM passed for a domain that aligns with the visible From domain | That the display name is real, or that the domain belongs to the company it imitates |
| Display name | Nothing. It's free text anyone can type. | — |
Alignment is the key idea. Microsoft's DMARC documentation explains that DMARC checks whether the domain that passed SPF or DKIM matches the domain in the From address, and a message passes if either aligned check passes. The June 1 messages achieved DKIM alignment, so as far as email authentication is concerned, they genuinely came from the domain in their From address. The fraud was in everything else: an executive's name as the display name, and a familiar-looking Reply-To domain.
Microsoft's operations guide puts it precisely: when all checks pass, "the recipient can trust the sender domain properly authenticated this message." The domain, not the person.
Where does DMARC on your domain help?
It's built to stop criminals from forging your exact domain. With p=reject, you ask receiving systems to reject mail that fails DMARC while claiming to be from you; Microsoft 365, for example, rejects it during delivery when its Honor DMARC record policy setting is on. It does nothing about domains you don't control, which is what the June 1 campaign used.
What about lookalikes and stolen mailboxes?
Microsoft says the reply-to mailboxes, on domains like j-gmails[.]com, mimicked legitimate providers. Stolen logins are another route: on July 20, Germany's Federal Criminal Police Office (BKA) announced that German investigators, working with US authorities, had taken more than 200 servers offline behind Kratos, a phishing-as-a-service kit that built fake Microsoft sign-in pages. The BKA believes more than 1,800 criminal customers bought the kit and ran around 15,000 phishing campaigns a month with it. Mail sent from a mailbox taken over this way can pass SPF, DKIM and DMARC, because it really does come from that organization's mail system. Our guide to Microsoft's move to passkeys covers the sign-in side.
What should you do now?
- Enforce DMARC on your own domain. Check your records with our free SPF, DKIM and DMARC scanner. Microsoft recommends moving gradually from
p=nonetop=quarantinetop=rejectwhile you monitor reports. If SPF itself is new to you, start with what an SPF record does. - Read the address, not the name. Train staff to check the actual sender address and Reply-To before answering any request involving money, data or payroll. A vague "Are you at your desk?" from an executive's name on an outside address is a reason to reply through a known channel instead.
- Lock down role mailboxes. Payroll, HR and receivables inboxes were targeted on June 1. Never change direct deposit or bank details because of an email; confirm by calling a number already on file, and require a second approver.
- Use impersonation protection if you have it. Business Premium and, since July 1, Office 365 E3 and Microsoft 365 E3 include Defender for Office 365 Plan 1. Add your executives to impersonation protection in the Standard or Strict preset policy.
- Harden sign-ins. Microsoft's report recommends passwordless methods such as Windows Hello, FIDO keys or Microsoft Authenticator, and phishing-resistant MFA for privileged accounts.
Frequently asked questions
Can a phishing email pass DMARC?
Yes. DMARC checks that a message passed SPF or DKIM for a domain that aligns with the From address. Criminals sending from a domain they control and have set up correctly can pass. Microsoft's Q2 2026 report describes BEC mail that passed SPF and achieved DKIM alignment; it doesn't say whether the Slovak domain was registered by the attackers or compromised. DMARC authenticates the domain, not whoever controls it.
Would DMARC on my domain have stopped the June 1 campaign?
Not directly. According to Microsoft, the messages were sent from a DKIM-configured Slovak domain with spoofed executive display names, rather than forging recipients' own domains. DMARC on your domain targets mail that forges your exact domain. The controls that fit this campaign are display-name and Reply-To checks, impersonation filtering and payment verification.
What does "Are you at your desk?" mean in a scam email?
It's a rapport-builder. Microsoft found that generic openers like this made up 87–92% of BEC first-contact emails each month in Q2 2026, and says BEC operators overwhelmingly favor building conversation before making a fraudulent request. Reply, and the fraudulent request typically follows.
Need help getting your domain to DMARC enforcement? Call (818) 574-8240.
Sources
- Microsoft Security Blog — Email threat landscape: Q2 2026 trends and insights (July 23, 2026)
- BKA — Schlag gegen eine der weltweit gefährlichsten Phishing-Gruppierungen (Kratos) (July 20, 2026)
- The Register — Kratos phishing-as-a-service kit loses its battle with international law enforcement (July 21, 2026)
- Help Net Security — Police dismantle Kratos phishing platform behind 15,000 monthly campaigns (July 22, 2026)
- Microsoft Learn — Set up DMARC to validate the From address domain for cloud senders (reference documentation, undated)
- Microsoft Learn — Security Operations guide for email authentication in Microsoft 365 (reference documentation, undated)
- Microsoft Learn — Email authentication in cloud organizations (reference documentation, undated)
- Microsoft Learn — Microsoft Defender for Office 365 service description (service documentation, undated)
- Microsoft Learn — Preset security policies in cloud organizations (reference documentation, undated)
Editor's note: This article was researched and written with AI assistance. Every factual claim was checked against the sources listed above; see our fact-check process for details.
Related Topics
Ready to Secure Your Email?
Check your domain's email security status with our free scanner, or get professional help setting up DMARC, SPF, and DKIM.