Formula Inbox

US Staffing Firm (Government Sector) · US Staffing Firm (Government Sector)

Their DNS Was Compromised. 28,000 Fake Pages and a Gmail Ban Were the Symptoms.

100% → 0%Delivery error rate
ClearedGmail 550-5.7.1 block
28,000Fake pages removed
Within daysRecovery time

Client Snapshot

A U.S.-based staffing firm that serves government clients and runs operations across the United States and Japan. The business depends on email for job communications, client coordination, and correspondence with government contacts. When it lost the ability to reach Gmail, revenue-critical communication stopped. The founder came to us after weeks of trying to diagnose the problem himself.

The Situation

Every message the company sent to Gmail was bouncing with a hard 550-5.7.1 "unsolicited mail" rejection. Nothing was getting through. The founder had already moved the company's email over to Zoho, assuming the problem lived with the old mail host, and the block did not budge.

Our audit found the real cause, and it was much larger than a bad SPF record. The company's entire web and DNS environment had been compromised. An attacker was running a Japanese SEO spam injection on the site: roughly 28,000 fake product pages cloned from a major Japanese retailer, cloaked so they showed a blank page to the owner and thousands of spam pages to Google's crawler. The injected pages carried phishing pop-ups built to steal visitors' Google account credentials. Most damaging for deliverability, the attacker was also sending fraudulent email through the domain and its subdomains at volume.

Gmail was not flagging the company's outreach. It was blocking a domain that had been turned into a spam and phishing operation. The delivery error rate sat at 100%.

What We Did

The strategic call was to treat the 550-5.7.1 block as a symptom rather than the disease. Re-checking authentication records and declaring victory would have missed the live compromise underneath. So we traced the rejection back to its source, confirmed the attack, and led with containment.

We restricted SPF to the one authorized sender, refreshed DKIM, and moved DMARC to a strict reject policy. We stripped out every unauthorized sending source and fraudulent DNS record, took the poisoned website offline, and rebuilt DNS on Cloudflare with a registrar lock to prevent further tampering. The DMARC monitoring we stood up during this phase caught the attacker still pushing mail through the legacy host, so we shut that path down as well. With control re-established, we went to Google directly, documented the recovery, and requested delisting to stop the rejections while the longer reputation-repair work ran in parallel.

The Results

The engagement began in mid-March 2026, and the delivery error rate reached zero within days.

  • Delivery error rate fell from 100% (March 18–20, 2026) to 0% by March 22, confirmed in Google's own delivery reporting.
  • The Gmail 550-5.7.1 block cleared. Test sends reached Gmail inboxes instead of bouncing.
  • Attacker-driven fraudulent sending stopped. DMARC-fail traffic that had peaked at more than 5,300 messages in a single week, including one unauthorized source pushing 6,200 messages at 0% SPF alignment, dropped away once containment held.
  • Roughly 28,000 injected spam pages and 32 fraudulent sitemaps were removed, and the compromised site was taken down.
  • Email flow with the company's U.S. government contacts was restored.

Discovering that our entire DNS and website were compromised was a nightmare scenario, and your emergency response literally saved our business and reputation. Seeing our emails landing to our government contacts again is a massive relief.

Founder, US Staffing Firm

Talk to an Expert

Tell us about your sending setup and what is going wrong. We will map the right mix of audit, infrastructure, and ongoing support, and give you a scoped quote on the first call.

Talk to an Expert