Ironscales

Ironscales IRONSCALES is the leader in AI-powered email security protecting over 17,000 global organizations. IRONSCALES is headquartered in Atlanta, Georgia.

IRONSCALES is the leader in AI-powered email security protecting over 15,000 global organizations from advanced phishing threats. As the pioneer of adaptive AI, we detect and remediate attacks like business email compromise (BEC), account takeovers (ATO), and zero-days that other solutions miss. By combining the power of AI and continuous human insights, we safeguard inboxes, unburden IT teams, an

d turn employees into a vital part of cyber defense across enterprises and managed service providers. To learn more, visit
www.ironscales.com
or follow us on X

09/01/2026

A signature request came from the recipient's own address, sent to that same address. SPF failed, DKIM was absent, DMARC failed, and it still reached the inbox.

(Link to full teardown in comments)

08/31/2026

A conference invite passed SPF, DKIM, and DMARC clean - the attacker owned the domain outright, aged seven months. The scanner still called the brochure PDF malicious.

The same operator returned six weeks later for four more mailboxes at the same company. Adaptive AI scored it 90% and mitigated it.

(Link to full teardown in comments)

08/30/2026

A spoofed invoice notice failed SPF, had no DKIM, and failed DMARC against an enforced reject policy. Microsoft quarantined it - then it was resubmitted out of quarantine and delivered anyway.

No link, no attachment, just a reply address on a four-month-old domain.

(Link to full teardown in comments)

08/29/2026

A payment notice with no lookalike domain, no impersonated brand, no attachment and no authentication failure. The sender was a real business whose domain dates to the late 1990s and whose mailbox had been taken over, so the authentication passed honestly, and the only link led to a form on Google's own domain.

What gave it away was the message itself: a settled payment notice with no amount, and a body reference number that contradicts the subject line.

(Link to full teardown in comments)

08/28/2026

A document-share lure passed SPF, DKIM, and DMARC, because the sending domain was a dormant bystander relaying through Amazon SES. Its only link's first hop was a per-account tracking subdomain on hs-sales-engage[.]com, HubSpot's genuine redirect service, so the clean link verdict describes that first hop and nothing else.

A CSS hiding rule left outside any stylesheet then failed to hide the kit's own padding.

(Link to full teardown in comments)

08/27/2026

This message passed SPF, DKIM and DMARC cleanly because the claimed sending domain's own Microsoft 365 tenant accepted it from an unauthenticated host and re-signed it on the way out. One hop earlier it had failed all three, from an origin host with no reverse DNS.

Read the earliest hop, not the last one.

(Link to full teardown in comments)

08/26/2026

A reply inside a weeks-old billing thread authenticated perfectly, because it came from the vendor's own mailbox after that mailbox was taken over. One thing had changed: the link on the website line of the sender's signature.

The sender's own earlier reply, quoted a few inches below in the same email, still carried the original.

(Link to full teardown in comments)

08/25/2026

An attacker named a Microsoft Clarity project after a fabricated PayPal refund of $445.67 with a callback number, then used the product's own collaborator invite to send it to a government mailbox. Microsoft composed, signed, and delivered the message, so SPF, DKIM, DMARC under reject, four ARC seals, and composite authentication all passed correctly, and every link resolved to a real Microsoft address.

The person who received it reported it anyway.

(Link to full teardown in comments)

08/24/2026

An e-signature notice rendered as clean English, but every visible line was stored in the HTML backwards: the button label sits in the source as tnemucoD detelpmoC weiV and is un-reversed only by an inline unicode-bidi:bidi-override at render time. This is not the Unicode right-to-left mark trick, so there are no control characters for a normalizer to strip and no keyword list matches the stored form.

SPF and DKIM passed for an aged unrelated sending domain, no DMARC policy was in force, and the reversed button ran through two shared trackers to a press-and-hold bot-check page the platform link scanner marked malicious.

(Link to full teardown in comments)

Address

6 Concourse Pkwy NE
Sandy Springs, GA
30328

Alerts

Be the first to know and let us send you an email when Ironscales posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Ironscales:

Shortcuts

Share