Back to The Local Vocal
The Local VocalMedium
PhishingAliExpress
Email
Medium risk PhishingEncountered ViaEMAIL 15 July 2026
RegionOtagoNew Zealand

A Suspicious Retail Promotion Is Reaching NZ Inboxes With No Authentication

Threat actors are spoofing a retail brand via unauthenticated emails targeting NZ users to harvest credentials or personal data through fraudulent promotional lures.

Receiving unsolicited promotional emails from unverified senders carries real risk for your organisation. Clicking links within these messages can expose your staff to credential harvesting pages, malware downloads, or the silent installation of tracking software. Even an unsubscribe action — if directed through a malicious link — can confirm your address as active, increasing the volume of future attacks and potentially leading to more targeted follow-up campaigns.

This campaign was identified after a spike in NZ inboxes receiving messages promoting deep seasonal discounts, sent from a domain with no established sending history. The messages arrived across multiple local organisations within a short window, suggesting an automated bulk-sending operation rather than a targeted or manually managed campaign.

The email presents itself as a legitimate retail promotion, complete with the kind of subject line and discount framing typical of recognised e-commerce brands. However, the sending domain — shoppingbestof.shop — bears no relationship to any established retailer, and the message body is notably sparse, containing little more than an unsubscribe prompt. This combination of retail-style urgency with near-empty content is a common hallmark of campaigns designed to test deliverability or harvest engagement signals.

What makes this campaign technically notable is the complete absence of email authentication across all checked mechanisms — SPF, DKIM, DMARC, and composite authentication all returned failing or absent verdicts. This means the sender made no attempt to legitimise the message through standard controls, which reputable retailers invariably implement. The use of a freshly registered or low-reputation .shop domain, paired with a fire emoji in the subject line to simulate seasonal excitement, points to an actor prioritising volume and evasion over sophistication.

Email authorisation
SPF
none
DKIM
fail
DMARC
none
COMPAUTH
fail
Sender Domain Intelligence

The domain the message claims to be from. Fresh registrations and known-bad reputations are the strongest technical tells of a spoofed sender.

Sender domainshoppingbestof.shop
Age104 daysYoung domain
Registered18/03/2026
Email Sample
Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Verify the sender's email domain carefully before clicking any links — "shoppingbestof.shop" is not associated with any legitimate NZ retailer, and unsolicited discount offers from unknown domains should be treated as suspicious.
  • Hover over any links in the email before clicking to reveal the actual destination URL, and avoid proceeding if the address looks unfamiliar, misspelt, or redirects through an unknown domain.
  • Report the phishing email to CERT NZ (cert.govt.nz) and forward it to your IT team or managed service provider so they can block the domain across your organisation's mail filters.
  • Educate your staff to be sceptical of unsolicited promotional emails offering unusually large discounts, particularly those using urgency tactics like flame emojis or limited-time language, which are common social engineering techniques.
  • Blacklist the domain "shoppingbestof.shop" in your organisation's email security gateway or spam filter to prevent further messages from this sender reaching your team's inboxes.
AliExpress logo
Is it real?
Got an email from AliExpress?

See what a genuine AliExpress message looks like, the real sender domain, the real link destination, and where to report a fake.

Check the real thing