Suped

Why are phishing emails being sent from verified and authenticated intuit.com servers?

Summary

Phishing emails appearing to originate from legitimate and authenticated domains like intuit.com can be highly confusing and deceptive. This phenomenon occurs not because the company's servers are compromised in a widespread sense, but typically because malicious actors exploit specific services or functionalities within these large platforms that allow for email sending (such as invoicing systems, notification services, or third-party integrations). These abuses leverage the trusted domain's established authentication, like SPF and DKIM, to bypass initial spam filters and appear credible to recipients.

What email marketers say

Email marketers often face challenges with phishing emails originating from seemingly legitimate domains, as these sophisticated scams can erode customer trust and bypass standard security measures. Their primary concern is protecting brand reputation and ensuring their legitimate communications reach the inbox without being flagged as suspicious due to association with such incidents.

Marketer view

Marketer from Email Geeks notes getting a sophisticated phishing email that appeared to originate from intuit.com, indicating confusion due to its apparent legitimacy.

11 Mar 2022 - Email Geeks

Marketer view

Marketer from Email Geeks expresses willingness to share the Email Message (EML) file for analysis, highlighting the unusual nature of the phishing attempt.

11 Mar 2022 - Email Geeks

What the experts say

Email deliverability experts highlight that phishing from legitimate domains like Intuit.com often stems from the abuse of their own sending infrastructure. This can occur through compromised accounts, exploitation of open forms, or vulnerabilities in specific services. While email authentication protocols like SPF, DKIM, and DMARC are crucial, they validate the sending server's identity, not necessarily the content or the sender's intent. This gap allows sophisticated phishing to slip through, presenting a significant challenge for email providers and recipients alike.

Expert view

Expert from Email Geeks explains that phishing emails from Intuit's servers are common because bad actors abuse Intuit's products designed for small businesses to send phishing attempts, making it a recurring challenge.

11 Mar 2022 - Email Geeks

Expert view

Expert from Email Geeks states that countering this type of abuse is challenging without blocking all Intuit traffic, which is not feasible due to the vast amount of legitimate emails sent.

11 Mar 2022 - Email Geeks

What the documentation says

Official documentation and cybersecurity advisories consistently warn about the sophisticated nature of phishing attacks, particularly those that mimic legitimate organizations. These resources emphasize that while technical authentication protocols are essential, they are not foolproof against every type of abuse. They highlight common tactics used by scammers and provide clear guidelines for users and organizations on how to identify, report, and prevent falling victim to these pervasive threats.

Technical article

Documentation from FTC Consumer Advice explains that scammers use email or text messages to trick users into giving them personal and financial information, emphasizing common tactics of social engineering.

15 Mar 2023 - FTC Consumer Advice

Technical article

Documentation from security.intuit.com outlines that customers should forward suspicious emails to security@intuit.com for investigation, emphasizing the importance of reporting abuse directly to the source.

20 Feb 2024 - security.intuit.com

8 resources

Start improving your email deliverability today

Get started