YouMind
Iniciar sesión

DKIM Passed, But Not the Body: Analyzing Suspicious DoD Emails

@unccno
INGLÉS28 sept 2026
104K
7
0
0
1

TL;DR

This article analyzes suspicious Department of Defense emails that passed SPF, DKIM, and DMARC checks despite potential body manipulation. It distinguishes between confirmed technical facts and theoretical attack classes regarding header cloning and S/MIME mismatches.

Executive Summary

Two notices landed in a personal Gmail stored in DEERS. From address CACExpiration-DoNotReply@mail.mil. Real RAPIDS locator. Real mail.mil- gateway. May message: SPF, DKIM, and DMARC all PASS.

The question is not whether mail.mil- is fake. It is whether cloned or reused organizational headers can still carry those PASSes while the body the user reads is not the object the checks were meant to bind.

That is a method class drawn from summarized third-party reporting. It is not a finding that it ran on this Message-ID. This article does not describe how to build it.

What is confirmed: a real DMDC document-gap program; two notices to this mailbox; May left -uhil19pa53.eemsg.mail.mil at 214.24.21.199; Gmail banner from From ≠ S/MIME signer; no documents submitted; CAC still worked; a separate DMDC file-share exposure October 2025–16 July 2026.

What is not confirmed: a pre-sign body substitution, a cloned SIEM, or a join from this mailbox to the 18 September letter.

The mail

9 March 2026, 15:01. CACExpiration-DoNotReply@mail.mil → Gmail: the sender does not match the digital signature. Body: records “still indicate” two identity source documents missing. Visit RAPIDS “to upload.” Current CAC cannot be the identity document. 120 days. Links to the document list and -idco.dmdc.osd.mil/idco/-.

7 May 2026, 14:32 PDT. Same From. Same To. Subject: urgent 60-day reminder, documents by 6 July. Opened 23 May.

  • Message-ID <bb3067$d3elv8@UHIL19PA53.eemsg.mail.mil>
  • Host -uhil19pa53.eemsg.mail.mil / 214.24.21.199
  • ESMTPS to -mx.google.com-, TLS 1.3
  • SPF / DKIM / DMARC PASS. DKIM d=mail.mil-, selector EEMSG2021v1a. DMARC p=REJECT
  • S/MIME signer benefits.notifications@mail.mil. Issuer DOD SW CA-83. Valid 15 Oct 2025 – 15 Oct 2028
  • Gmail still flags the signature mismatch
  • Body: two documents missing. RAPIDS. 60 days and 180 days in one letter. “If you recently uploaded your documents, please disregard.”
  • Links: cac.mil- PDF with a ver= token, and IDCO

March + 120 days = 7 July. May + 60 days = 6 July. Documents were not given. CAC function was not lost.

The 10 October 2025 JKO mail from DoNotReply@jten.mil is a different campaign. It is not the missing notice implied by “still.”

Timeline

Overlap is not a join. Three lanes stay separate unless a record ties them.

Connor Lovgren 🇺🇸🥸🦊🤠☃️🐦‍⬛🐧 - inline image
Connor Lovgren 🇺🇸🥸🦊🤠☃️🐦‍⬛🐧 - inline image

The official program

DMDC told the services in January 2026 that DEERS records were missing current proof of identity. Phased email went to government and personal addresses in DEERS. By August: about 215,000 active and reserve out of compliance. Army: nearly 111,000 CACs reviewed, none revoked as of 2 September. Marines: about 21,500 still short in July.

3 September official: administrative record update. No evidence of fraud, forgery, or malicious activity. No indication the review enabled a data breach. Published 8 September — before the file-share letter was public. No department-wide deadline published.

MARADMIN 393/26: two original documents, in-person RAPIDS, picture ID that may not be a CAC. Official process is scan at a RAPIDS site. The March body said “upload.”

The program explains personal Gmail, a real IDCO link, and a threat that did not execute. It does not explain “upload,” the 60/180 collision, or the missing signed original.

The class

The summarized articles were about a specific seam: headers that still look like the real stream — From, Message-ID shape, sending host, DKIM d=, even a nearby organizational signature — while the body is the inserted object, and the receiving MTA still prints PASS.

Cheap rewrite after Gmail verifies is the version May rules out. DKIM passed. A change after that signature fails at Gmail.

The version that stays open: body text introduced at or before the signer, so the trusted path still authenticates. Or a gap between what Gmail verified and what the screen rendered. No .eml. No .p7s. Neither gap is tested.

PASS is not the same statement as “the paragraph about upload and July 6 is the paragraph DMDC intended.”

Adjacent reporting in the same stack, not this seam:

  • Empty envelope / ReliaQuest via SC Media, 4 September. Visible From versus a blank SMTP envelope on Microsoft 365 Direct Send. May was EEMSG to Google, not tenant Direct Send.
  • Unicode Tags-block characters / Microsoft via BleepingComputer, 3–6 September. Visible word versus detector token. A screenshot will not show extra code points. No raw MIME here.

SaaS telemetry stays in its own lane. 20 July page: redirect copy, track URL on -email.usfhp.net-, fingerprint script. Real USFHP brand. Ordinary marketing measurement. Also a place an identity-adjacent click can be counted. -email.usfhp.net- is not the EEMSG host. 25 September public note named the overlap with CAC mail, USFHP/HubSpot, and Nexus reporting, and said overlap is not a join.

23 May and Pulse

Morning, from 192.168.1.73 through 192.168.1.254:

Connor Lovgren 🇺🇸🥸🦊🤠☃️🐦‍⬛🐧 - inline image

Afternoon:

Connor Lovgren 🇺🇸🥸🦊🤠☃️🐦‍⬛🐧 - inline image

QSecPulse:

Connor Lovgren 🇺🇸🥸🦊🤠☃️🐦‍⬛🐧 - inline image

Hosts, 25-26 Sep:

Connor Lovgren 🇺🇸🥸🦊🤠☃️🐦‍⬛🐧 - inline image

26 September outside the six host runs: -lidstrom01.int.dmdc.osd.mil- and -velocity.int.dmdc.osd.mil- still NXDOMAIN, SOA -dns1.nipr.mil-. From this network -www.cac.mil- gained CNAME -user-att-104-176-48-0.e80948.dscb.akamaiedge.net- and A 23.62.46.164 / 23.62.46.182. PDF HTTP 403, content-length 455, no Location, ref 18.b62d3e17.1790428672.8bb3de93.

Firefox profile z2wnofk9 on 3 April 2026 at 11:56 opened -myaccess.dmdc.osd.mil- and -pki.dmdc.osd.mil- on a CAC login whose return path continues to TriWest. Profile pfebf5xa has no visit row for these six hosts.

WHOIS profile shared by every 214. address in this file:

Connor Lovgren 🇺🇸🥸🦊🤠☃️🐦‍⬛🐧 - inline image

.mil domain WHOIS on every host: This TLD has no whois server.

ip-api places every 214. query in Columbus, Ohio. Tokenless ipinfo places every 214. query in Rose Hill, Virginia (38.7887,-77.1128, postal 24281). Same allocation. Not two sites.

-uhil19pa53.eemsg.mail.mil-

Connor Lovgren 🇺🇸🥸🦊🤠☃️🐦‍⬛🐧 - inline image

ip-api: Columbus, AS345, reverse -uhil19pa53.eemsg.mail.mil. ipinfo: Rose Hill, same hostname.

OSINT 11 hits. Not this hostname as a public site. Adjacent names only: -webmail.apps.mil, MilitaryCAC OWA list, CIO memo on EEMSG and commercial certs, -myaccess.microsoft.us DoD tenants, -connect.disa.mil, -portal.apps.mil, ArmyNG note on EEMSG DLP, -miap.csd.disa.mil. Handles dodapps1, dodlogs1 are search noise.

-www.cac.mil-

Connor Lovgren 🇺🇸🥸🦊🤠☃️🐦‍⬛🐧 - inline image

WHOIS: NET-23-192-0-0-1 / 23.192.0.0/11 AKAMAI, 145 Broadway, Cambridge MA 02142. Abuse abuse@akamai.com. Tech ip-admin@akamai.com.

HTTP/1.1 and HTTP/2 both 403 AkamaiGHost, content-length: 363, HSTS max-age=31536000. No Location.

TLS both edges, 25 September:

Connor Lovgren 🇺🇸🥸🦊🤠☃️🐦‍⬛🐧 - inline image

SAN includes -www.cac.mil on a Pentagon/DMA/Guard set: -www.pentagon.mil, -www.defense.mil, -www.dod.mil, -www.nationalguard.mil, -www.cybercom.mil, -www.dfas.mil, -www.dia.mil, -www.dla.mil, -www.nro.mil, -www.nro.gov, and the rest of that LE batch.

Wayback CDX on the hostname runs from 2006 -(-cac.mil:80/ 200) through 2012 snapshots.

idco.dmdc.osd.mil-

Connor Lovgren 🇺🇸🥸🦊🤠☃️🐦‍⬛🐧 - inline image

HTTP snippet 25 September (cookies stripped):

Connor Lovgren 🇺🇸🥸🦊🤠☃️🐦‍⬛🐧 - inline image

TLS:

Connor Lovgren 🇺🇸🥸🦊🤠☃️🐦‍⬛🐧 - inline image

Wayback on /: 403 in 2021–2025, then 302 from April 2025 onward. Error-doc GIFs archived 2020. Live IDCO paths (/idco/, ?rapids-appointments, /idco/myprofile-info), -dwp.dmdc.osd.mil ID cards, myaccess login stub, milConnect search, Bragg ID-card page.

-d117002.dmdc.osd.mil-

Connor Lovgren 🇺🇸🥸🦊🤠☃️🐦‍⬛🐧 - inline image

-myaccess.dmdc.osd.mil-

Connor Lovgren 🇺🇸🥸🦊🤠☃️🐦‍⬛🐧 - inline image

Redirect chain 26 September (cookies stripped):

Connor Lovgren 🇺🇸🥸🦊🤠☃️🐦‍⬛🐧 - inline image

Same Seaside DigiCert as IDCO. Wayback CDX call returned Internet Archive “Temporarily Offline” HTML, not a snapshot list. Archive plus webcompat issues on -myaccess.dmdc.osd.mil and a Stratum Auth DS Logon ticket.

Firefox z2wnofk9 3 April 2026 11:56:

Connor Lovgren 🇺🇸🥸🦊🤠☃️🐦‍⬛🐧 - inline image

Separate session. Not the notices.

-pki.dmdc.osd.mil-

Connor Lovgren 🇺🇸🥸🦊🤠☃️🐦‍⬛🐧 - inline image

Firefox same 3 April chain: /identitymanagement/app/login?action=cacLogin and /identitymanagement/app/authentication.

SaaS-adjacent, not the mail host

-email.usfhp.net is the 20 July track host. It is not in the six-host -qs-recon.sh run. Local page: redirect copy, track URL, fingerprint script. HubSpot-class measurement on a real USFHP brand. No shared IP with 214.24.21.199 or 214.16.194.0/24 in this file.

Gmail wrappers on 23 May resolved to 142.251.154.119 and 142.251.157.119 (gws). That is the mailbox front, not DMDC.

Recon confirms the fronts the mail pointed at. It does not confirm a pre-sign edit. No shared IP between the EEMSG prefix and the DMDC app prefix.

What landed later

File-share letter dated 18 September. Hole found 16 July. Unencrypted PII accessed October 2025 through 16 July 2026. SSN plus at least one other identifier. No indication of misuse. One year of IDX. “About four million” is two unnamed people, not the letter. FY2024 “60 million records” is DMDC holdings, not a victim count. The letter does not describe mail altered in transit.

IDScan notice 4 September. Customer cloud accounts. Names and government ID numbers. Marketplace headcount is not in the notice. No published join to this From address.

Ledger

Confirmed

  • Real DMDC email program to personal addresses in DEERS, January 2026.
  • Two notices, 9 March and 7 May. Same From. Same IDCO pointer. Gmail signature-mismatch banner.
  • May left a DoD EEMSG host that still resolves. Transport auth passed. S/MIME signer is a different -mail.mil mailbox than From. That is enough for the Gmail banner without a forged domain.
  • No documents uploaded. CAC not pulled.
  • File-share exposure, October 2025–16 July 2026.
  • USFHP page 20 July: track URL and fingerprint script.

Class only

  • Cloned or reused organizational headers with PASS results and a substituted body.
  • “Upload” and dual clocks in official-looking copy.
  • USFHP/HubSpot click measurement.

Open

  • The notice before 9 March.
  • The signed bytes of either CAC message.
  • Any log that the body changed before -mail.mil signed it.
  • A hop inside DMDC before the gateway.

The cleanup was real. The channel was trusted. PASS on May means the cheap post-sign rewrite is out. The files do not finish the claim that the body was introduced before the signer.

What moves that sentence: the May original including the S/MIME part, a second recipient’s copy, the implied earlier notice, or a gateway log that names this Message-ID. Until one of those exists, the class stays in the vocabulary column and the notices stay in the evidence column.

Guardar con un clic

Lee artículos virales en profundidad con IA en YouMind

Guarda la fuente, haz preguntas concretas, resume el argumento y convierte un artículo viral en notas reutilizables en un único espacio de trabajo con IA.

Explora YouMind
Para creadores

Convierte tu Markdown en un artículo de 𝕏 impecable

Cuando publicas tus propios textos largos, dar formato en 𝕏 a imágenes, tablas y bloques de código es un fastidio. YouMind convierte un borrador completo en Markdown en un artículo de 𝕏 impecable y listo para publicar.

Prueba Markdown a 𝕏

Más patrones por descifrar

Artículos virales recientes

Explorar más artículos virales