Spam Filtering & Blacklists

Stop Email Spoofing: Shared Hosting and Your Own cPanel Server

By the Domain India teamPublished 7 min read
Knowledge base article
Contents (7 sections)

Email spoofing is when someone sends mail with a forged From address, so it looks as if it came from your domain. On a shared mail server it damages the server's reputation and pushes everyone's mail towards spam. This guide covers both sides: what you can do on Domain India shared hosting, and how to block spoofing on a cPanel server you run yourself with root access to WHM.

Key takeaways

On Domain India shared hosting the mail server is managed for you, so you don't edit Exim or WHM. Protect your own domain by switching on SPF and DKIM in cPanel's Email Deliverability and publishing a DMARC record, and send website mail from an address on your own domain. On your own cPanel server (for example a VPS), log in to WHM as root, turn on SMTP Restrictions, add Exim ACL rules that reject a From address the sender doesn't own, publish SPF, DKIM and DMARC for every domain, then test with SWAKS.

1. On Domain India shared hosting

You don't have WHM or root access on shared hosting, and you don't need it: the mail server's settings are managed by us for every account. What protects your domain from being spoofed elsewhere, and keeps your own mail out of spam, is authentication in DNS.

  1. Turn on SPF and DKIM.
    In cPanel, open Email Deliverability, find your domain and use Repair or Install the suggested record for SPF and DKIM.
  2. Publish a DMARC record.
    In Domains › Zone Editor, add a TXT record named _dmarc. Start with v=DMARC1; p=none; rua=mailto:[email protected] to collect reports, then move to p=quarantine once your real mail passes. See SPF, DKIM and DMARC explained.
  3. Send website mail from your own domain.
    Contact forms and scripts should send from an address on your domain, such as [email protected], never from the visitor's address. On our cPanel servers, send with PHP mail() and the -f option; SMTP from PHP doesn't work there because the socket functions are disabled. See How to use PHPMailer for contact forms.
  4. Report spoofed mail you receive.
    If someone is sending spam that pretends to come from your domain, or your account itself is sending spam, see Email account hacked or sending spam? and open a ticket with a sample message and its full headers.

2. On your own cPanel server: what to switch on

These steps need root access to WHM, so they apply to a VPS or dedicated server you manage. Take a backup of the Exim configuration first: in WHM, Exim Configuration Manager › Backup.

ControlWhat it doesWhere to set it
SMTP RestrictionsOnly the mail server, root and mailman can connect to outside mail servers, so scripts can't bypass EximWHM › Security Center › SMTP Restrictions
Require TLS before AUTHPasswords are never sent unencryptedWHM › Exim Configuration Manager › Basic Editor › Security
Exim ACL rulesReject mail whose From address the sender doesn't own (section 3)WHM › Exim Configuration Manager › Advanced Editor
Hourly sending limitCaps the damage from a hacked account or formWHM › Tweak Settings › Mail (maximum hourly emails per domain)
SPF, DKIM and DMARCLets receiving servers detect forged mail from your domainscPanel › Email Deliverability for SPF and DKIM; Zone Editor for DMARC

3. Exim ACL rules that block spoofing

In WHM open Exim Configuration Manager › Advanced Editor.

  1. Define your remote domains.
    Under Add additional configuration setting, add:
  2. Block local scripts that send with a foreign From.
    In the custom_begin_outgoing_notsmtp_checkall box (in the acl_not_smtp section), add the first rule below. It stops PHP and other local programs sending with a From domain that isn't hosted on the server.
  3. Make authenticated senders use their own address.
    In the custom_begin_outgoing_smtp_checkall box (in the acl_smtp_data section), add the second rule. It rejects mail where the From address doesn't match the mailbox that logged in.
  4. Save.
    WHM checks the configuration, applies it and restarts Exim. Custom custom_begin_* blocks are kept when cPanel updates Exim.
apache
# Step 1: additional configuration setting
domainlist remote_domains = lsearch;/etc/remotedomains
apache
# Step 2: custom_begin_outgoing_notsmtp_checkall
deny
  condition = ${if ! match_domain{${domain:${address:$h_From:}}}{+local_domains : +remote_domains}}
  message   = Sorry, you don't have permission to send email from this server with a From address on a domain it doesn't host.
apache
# Step 3: custom_begin_outgoing_smtp_checkall
deny
  authenticated = *
  condition = ${if or{ {!eqi{$authenticated_id}{$sender_address}} {!eqi{$authenticated_id}{${address:$h_From:}}} }}
  message   = Your From address ($sender_address, $h_From) must match the mailbox you logged in with ($authenticated_id).
accept

The second rule is strict: a user who sends as an alias or a shared address from their own login is rejected too. Test it on a few accounts before you rely on it, and keep a copy of the working configuration.

4. Test that it works

Install SWAKS (dnf install -y swaks, from EPEL if needed, or apt install -y swaks), then run two tests from the server:

bash
# 1. A normal message: should be delivered
swaks --server 127.0.0.1 --port 587 --tls \
  --auth LOGIN --auth-user [email protected] --auth-password 'PASSWORD' \
  --from [email protected] --to [email protected] \
  --h-Subject "Delivery test"

# 2. A spoofed From: should be rejected by the ACL
swaks --server 127.0.0.1 --port 587 --tls \
  --auth LOGIN --auth-user [email protected] --auth-password 'PASSWORD' \
  --from [email protected] --to [email protected] \
  --h-Subject "Spoofing test"

Use a test mailbox, not a customer's password, and delete it afterwards. To trace a message in the log, use exigrep MESSAGE-ID /var/log/exim_mainlog.

5. Troubleshooting

SymptomCauseFix
"Your From address must match the mailbox you logged in with"The mail app sends as a different address from its loginSet the app's From to the mailbox it logs in with, or create a login for the alias
A website's form mail is rejectedThe script sends with the visitor's address as FromSend from an address on the hosted domain and put the visitor's address in Reply-To
Forwarded mail fails DMARC at the recipientForwarding changes the sending serverExpected for some forwards; the recipient's server decides, and SRS on the forwarding server helps
Everything is rejected after savingA typing mistake in the ACLRestore the backup in Exim Configuration Manager, then add the rules again

6. Where Domain India fits

On Domain India shared hosting, the mail server, its limits and its abuse protection are managed for you; you set up SPF, DKIM and DMARC for your own domains from cPanel. If you want full control of Exim and WHM, a VPS gives you root access, and you manage the server yourself. See VPS plans compared.

Frequently asked questions

How do I stop email spoofing on Domain India shared hosting?

You can't change the mail server's settings on shared hosting, and you don't need to; they are managed for you. Protect your domain by turning on SPF and DKIM in cPanel's Email Deliverability and publishing a DMARC record, and send website mail from an address on your own domain.

Can I edit Exim or WHM settings on shared hosting?

No. WHM and the Exim configuration need root access, which only exists on a server you manage yourself, such as a VPS.

Someone is sending spam that looks like it came from my domain. What should I do?

Make sure SPF, DKIM and a DMARC record are published for your domain, so receiving servers can reject the forgeries. If your own account may be sending it, change your mailbox passwords and open a support ticket with a sample message and its full headers.

Why does my contact form mail get rejected or land in spam?

Usually the form sends with the visitor's address as From. Send from an address on your own domain, put the visitor's address in Reply-To, and on our cPanel servers send with PHP mail() and -f rather than SMTP.

How do I test spoofing protection on my own cPanel server?

Use SWAKS to send one normal message and one with a From address on another domain, both from an authenticated test mailbox. The first should be delivered and the second rejected by your Exim ACL.

Need help? On shared hosting, open a support ticket with the domain and a sample message with full headers. Support is by 24/7 live chat and tickets; there is no phone support.

Ready when you are

Get Business Email from ₹60/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app