Email spoofing is when someone sends mail with a forged From address, so it looks as if it came from your domain. On a shared mail server it damages the server's reputation and pushes everyone's mail towards spam. This guide covers both sides: what you can do on Domain India shared hosting, and how to block spoofing on a cPanel server you run yourself with root access to WHM.
On Domain India shared hosting the mail server is managed for you, so you don't edit Exim or WHM. Protect your own domain by switching on SPF and DKIM in cPanel's Email Deliverability and publishing a DMARC record, and send website mail from an address on your own domain. On your own cPanel server (for example a VPS), log in to WHM as root, turn on SMTP Restrictions, add Exim ACL rules that reject a From address the sender doesn't own, publish SPF, DKIM and DMARC for every domain, then test with SWAKS.
1. On Domain India shared hosting
You don't have WHM or root access on shared hosting, and you don't need it: the mail server's settings are managed by us for every account. What protects your domain from being spoofed elsewhere, and keeps your own mail out of spam, is authentication in DNS.
- Turn on SPF and DKIM.In cPanel, open Email Deliverability, find your domain and use Repair or Install the suggested record for SPF and DKIM.
- Publish a DMARC record.In Domains › Zone Editor, add a TXT record named
_dmarc. Start withv=DMARC1; p=none; rua=mailto:[email protected]to collect reports, then move top=quarantineonce your real mail passes. See SPF, DKIM and DMARC explained. - Send website mail from your own domain.Contact forms and scripts should send from an address on your domain, such as
[email protected], never from the visitor's address. On our cPanel servers, send with PHPmail()and the-foption; SMTP from PHP doesn't work there because the socket functions are disabled. See How to use PHPMailer for contact forms. - Report spoofed mail you receive.If someone is sending spam that pretends to come from your domain, or your account itself is sending spam, see Email account hacked or sending spam? and open a ticket with a sample message and its full headers.
2. On your own cPanel server: what to switch on
These steps need root access to WHM, so they apply to a VPS or dedicated server you manage. Take a backup of the Exim configuration first: in WHM, Exim Configuration Manager › Backup.
| Control | What it does | Where to set it |
|---|---|---|
| SMTP Restrictions | Only the mail server, root and mailman can connect to outside mail servers, so scripts can't bypass Exim | WHM › Security Center › SMTP Restrictions |
| Require TLS before AUTH | Passwords are never sent unencrypted | WHM › Exim Configuration Manager › Basic Editor › Security |
| Exim ACL rules | Reject mail whose From address the sender doesn't own (section 3) | WHM › Exim Configuration Manager › Advanced Editor |
| Hourly sending limit | Caps the damage from a hacked account or form | WHM › Tweak Settings › Mail (maximum hourly emails per domain) |
| SPF, DKIM and DMARC | Lets receiving servers detect forged mail from your domains | cPanel › Email Deliverability for SPF and DKIM; Zone Editor for DMARC |
3. Exim ACL rules that block spoofing
In WHM open Exim Configuration Manager › Advanced Editor.
- Define your remote domains.Under Add additional configuration setting, add:
- Block local scripts that send with a foreign From.In the
custom_begin_outgoing_notsmtp_checkallbox (in theacl_not_smtpsection), add the first rule below. It stops PHP and other local programs sending with a From domain that isn't hosted on the server. - Make authenticated senders use their own address.In the
custom_begin_outgoing_smtp_checkallbox (in theacl_smtp_datasection), add the second rule. It rejects mail where the From address doesn't match the mailbox that logged in. - Save.WHM checks the configuration, applies it and restarts Exim. Custom
custom_begin_*blocks are kept when cPanel updates Exim.
# Step 1: additional configuration setting
domainlist remote_domains = lsearch;/etc/remotedomains# Step 2: custom_begin_outgoing_notsmtp_checkall
deny
condition = ${if ! match_domain{${domain:${address:$h_From:}}}{+local_domains : +remote_domains}}
message = Sorry, you don't have permission to send email from this server with a From address on a domain it doesn't host.# Step 3: custom_begin_outgoing_smtp_checkall
deny
authenticated = *
condition = ${if or{ {!eqi{$authenticated_id}{$sender_address}} {!eqi{$authenticated_id}{${address:$h_From:}}} }}
message = Your From address ($sender_address, $h_From) must match the mailbox you logged in with ($authenticated_id).
acceptThe second rule is strict: a user who sends as an alias or a shared address from their own login is rejected too. Test it on a few accounts before you rely on it, and keep a copy of the working configuration.
4. Test that it works
Install SWAKS (dnf install -y swaks, from EPEL if needed, or apt install -y swaks), then run two tests from the server:
# 1. A normal message: should be delivered
swaks --server 127.0.0.1 --port 587 --tls \
--auth LOGIN --auth-user [email protected] --auth-password 'PASSWORD' \
--from [email protected] --to [email protected] \
--h-Subject "Delivery test"
# 2. A spoofed From: should be rejected by the ACL
swaks --server 127.0.0.1 --port 587 --tls \
--auth LOGIN --auth-user [email protected] --auth-password 'PASSWORD' \
--from [email protected] --to [email protected] \
--h-Subject "Spoofing test"Use a test mailbox, not a customer's password, and delete it afterwards. To trace a message in the log, use exigrep MESSAGE-ID /var/log/exim_mainlog.
5. Troubleshooting
| Symptom | Cause | Fix |
|---|---|---|
| "Your From address must match the mailbox you logged in with" | The mail app sends as a different address from its login | Set the app's From to the mailbox it logs in with, or create a login for the alias |
| A website's form mail is rejected | The script sends with the visitor's address as From | Send from an address on the hosted domain and put the visitor's address in Reply-To |
| Forwarded mail fails DMARC at the recipient | Forwarding changes the sending server | Expected for some forwards; the recipient's server decides, and SRS on the forwarding server helps |
| Everything is rejected after saving | A typing mistake in the ACL | Restore the backup in Exim Configuration Manager, then add the rules again |
6. Where Domain India fits
On Domain India shared hosting, the mail server, its limits and its abuse protection are managed for you; you set up SPF, DKIM and DMARC for your own domains from cPanel. If you want full control of Exim and WHM, a VPS gives you root access, and you manage the server yourself. See VPS plans compared.
Frequently asked questions
How do I stop email spoofing on Domain India shared hosting?
You can't change the mail server's settings on shared hosting, and you don't need to; they are managed for you. Protect your domain by turning on SPF and DKIM in cPanel's Email Deliverability and publishing a DMARC record, and send website mail from an address on your own domain.
Can I edit Exim or WHM settings on shared hosting?
No. WHM and the Exim configuration need root access, which only exists on a server you manage yourself, such as a VPS.
Someone is sending spam that looks like it came from my domain. What should I do?
Make sure SPF, DKIM and a DMARC record are published for your domain, so receiving servers can reject the forgeries. If your own account may be sending it, change your mailbox passwords and open a support ticket with a sample message and its full headers.
Why does my contact form mail get rejected or land in spam?
Usually the form sends with the visitor's address as From. Send from an address on your own domain, put the visitor's address in Reply-To, and on our cPanel servers send with PHP mail() and -f rather than SMTP.
How do I test spoofing protection on my own cPanel server?
Use SWAKS to send one normal message and one with a From address on another domain, both from an authenticated test mailbox. The first should be delivered and the second rejected by your Exim ACL.
Need help? On shared hosting, open a support ticket with the domain and a sample message with full headers. Support is by 24/7 live chat and tickets; there is no phone support.