Every one of these countries is a place someone tried to send us mail while pretending to be a domain that does not exist. We reject them at the door, before a single message is accepted. This map refreshes hourly.
Counting blocked messages is a vanity metric. What protects you is whether the right mail is stopped, not how big a number we can print. The colours show relative activity only.
Most of this traffic rents space on ordinary cloud providers. The provider is not the attacker, so naming them would be misleading. We show the country and nothing more.
A fake domain is invented and owned by nobody, so there is no record to fix. A spoofed domain is the company's exact domain β not a look-alike β sent without permission. That distinction matters: a look-alike belongs to the attacker and DMARC cannot touch it, while exact-domain spoofing is precisely what a DMARC policy stops.
Attackers pick domains that are cheap to impersonate. A correct DMARC policy makes yours worthless to them. Check yours in a few seconds β it's free.
Check my domainCountry outlines: Natural Earth (public domain). LastSpam does not publish which networks or address ranges it blocks.