Back to The Local Vocal
The Local VocalMedium
Email
Medium risk PhishingEncountered ViaEMAIL 15 July 2026
RegionOtagoNew Zealand

AliExpress Impersonation Emails Are Reaching Your Inbox With Fake Summer Discount Offers

Threat actors are spoofing AliExpress via phishing emails featuring fraudulent summer discount lures to harvest user credentials or financial data.

Emails of this nature are designed to lure your staff into clicking links embedded within promotional content, with the likely objective of harvesting credentials, delivering malware, or redirecting recipients to fraudulent storefronts. The financial and reputational harm to your organisation can be significant β€” particularly where staff interact with the content on work devices or enter personal and payment details into spoofed landing pages. Even a single click on an unverified link can provide an initial foothold for a broader compromise.

This campaign was identified after a spike in NZ inboxes, with the same message appearing across multiple local organisations within a narrow window. The emails present as promotional communications from AliExpress, advertising a summer sale with a 60% discount offer. The concentrated delivery timeframe suggests an automated bulk-sending operation rather than a targeted or manually curated campaign.

The deception lies in the mismatch between the claimed sender identity and the actual sending infrastructure. While the display name references AliExpress, the sending domain β€” shoppingbestof.shop β€” has no affiliation with the legitimate AliExpress platform. Critically, the message fails all standard email authentication checks: SPF returned no result, DKIM failed, DMARC returned no result, and composite authentication failed entirely. A legitimate communication from a major e-commerce platform would pass these checks without exception.

Of note is the unsubscribe mechanism embedded in the HTML body, which invites recipients to "click here to remove your self from our emails list" β€” a construction that is grammatically irregular and inconsistent with professional marketing communications. Rather than providing a genuine opt-out, such links are frequently used to confirm active email addresses to threat actors, or to redirect recipients through additional malicious infrastructure. The campaign's use of seasonal framing β€” referencing summer deals β€” is also contextually inverted for New Zealand's July winter, suggesting the content was repurposed from a Northern Hemisphere template with no localisation applied.

Email authorisation
SPF
pass
DKIM
pass
DMARC
pass
COMPAUTH
pass
Domain authentication
Sender / From domain
damrinet.com
Domain age
2280 days old
Email Sample
Email Sample screenshot
Domain Reputation
Abuse score
15/ 100Low
ISP (Internet Service Provider)
Regional Host
Function:Function Unknown
Reputation:Reputation Unknown
Recommended Action

Practical steps you or your IT provider can take to reduce the risk from this kind of threat.

  • Verify the sender's email address carefully before clicking any links β€” legitimate AliExpress emails will always come from an official @aliexpress.com domain, never from suspicious domains like shoppingbestof.shop
  • Avoid clicking any links or downloading attachments from this email, as they may lead to credential-harvesting sites or install malware on your device
  • Report the phishing email to CERT NZ at CERT NZ via their website at cert.govt.nz or by forwarding the email to report@phishing.cert.govt.nz and forward it to your IT or security team so they can block the domain across your organisation
  • Educate your staff to be sceptical of unsolicited promotional emails offering extreme discounts, particularly those using emoji-heavy subject lines designed to bypass spam filters
  • Enable multi-factor authentication (MFA) on all business accounts and password managers so that even if credentials are compromised, unauthorised access is prevented
AliExpress logo
Is it real?
Got an email from AliExpress?

See what a genuine AliExpress message looks like, the real sender domain, the real link destination, and where to report a fake.

Check the real thing