{"success":true,"data":{"id":"sender-ip-residential-claim-corporate","label":"Residential-IP sender claiming corporate auth posture","description":"The connecting IPv4 sender address is OUTSIDE the known datacenter/hosting-provider prefix list (DigitalOcean, Linode, Hetzner, OVH, Vultr) — i.e., it looks like a residential ISP or compromised endpoint — while the sender domain claims a corporate authentication posture (Authentication-Results references both spf= and dkim= mechanisms). This shape indicates either a hijacked residential endpoint sending phishing through a home connection, or a distributed proxy network using compromised consumer routers. Free-webmail senders (gmail, outlook, yahoo, icloud) and BRAND_TRUST_MAP brands are skipped because they legitimately span outside the small static datacenter prefix list.","tier":"danger","category":"sender","isThin":false}}