An email flood is what happens when one stolen mailbox password or one abused contact form starts pushing thousands of spam messages through a mail server in a few hours. The sender's queue fills, Gmail and Outlook start delaying or refusing mail from that server, and legitimate mail for everyone on it slows down. This guide covers both sides: what to do if it is your hosting account sending, and, in a clearly marked section, how an administrator traces and stops a flood on their own server.
Most floods start with a compromised mailbox (someone logs in with a stolen password and sends through the server) or a website script. On Domain India shared hosting, change every mailbox password, suspend outgoing mail on the suspect mailbox, and open a ticket: support can read the server logs you can't. On your own cPanel or DirectAdmin server, find the sender in the Exim log (A= for a mailbox login, cwd= for a script), stop that sender, remove only its queued messages, then fix the cause and let the IP's reputation recover.
1. What a flood looks like
| Sign | What it usually means |
|---|---|
| Bounces saying your domain "exceeded the max emails per hour" | Your account hit its sending limit, often because something other than you is sending |
| A Sent folder full of messages you don't recognise | A mailbox password has been stolen |
| Hundreds of bounces for mail you never wrote | Spam is going out from your account, or someone is forging your address elsewhere |
| Mail to Gmail delayed with 421 4.7.x errors | Gmail has lowered its trust in the sending server |
| A message from support about spam from your account | The server logs show mail leaving through your account |
2. If it is your Domain India hosting account
Sending limits cap the damage on shared hosting: 200 messages per hour per account on cPanel and 1,000 per day on DirectAdmin. Hitting them on a normal day is a strong sign of a problem.
- Change every mailbox password.Start with any address whose Sent folder shows messages you didn't write. Use a unique password for each mailbox.
- Suspend outgoing mail on the suspect mailbox.On cPanel, open Email › Email Accounts, click Manage next to the address and set sending to Suspend or Hold. Incoming mail keeps arriving. On DirectAdmin and Webuzo, ask support to block sending for that mailbox.
- Change your control panel and client area passwordsand turn on two-factor authentication. An attacker with panel access can simply create a new mailbox.
- Switch off an unprotected contact formuntil it has a CAPTCHA or honeypot and a fixed recipient address.
- Open a ticket.Include your domain, the suspect mailbox, the approximate time and one bounce with full headers. Shared hosting mail logs cover every account on the server, so only support can read them and tell you whether a mailbox login or a script sent the mail.
The full clean-up checklist, including forwarders, filters and hacked-website checks, is in how to investigate email spam abuse. Domain India does not clean hacked websites as a free service; see the security checklist for a hacked website.
Messages that a receiving server defers stay in the queue and are retried; on our cPanel and DirectAdmin servers retries continue for up to 4 days before the message bounces. Once the spam stops, delays to Gmail usually ease as the server sends clean mail again. See fixing Google greylisting.
3. Own server only: find the source
Sections 3 to 5 are for administrators with root access to their own cPanel & WHM or DirectAdmin server, such as a VPS. They do not apply to Domain India shared hosting. The main Exim log is /var/log/exim_mainlog on cPanel and /var/log/exim/mainlog on DirectAdmin; the examples use the cPanel path.
First, measure the queue and see who is in it:
exim -bpc # messages in the queue
exim -bp | exiqsumm | sort -rn | head -20 # queued mail per recipient domain
exim -bp | awk '/^ *[0-9]+[mhd]/{print $4}' | sort | uniq -c | sort -rn | head
# queued mail per sender addressThen find how the mail was injected. A mailbox login shows as A= followed by the authenticator and the address; mail sent by a script run by a local account shows a cwd= folder:
# Top authenticated senders (stolen mailbox passwords)
grep -oE 'A=[a-z_]*(login|plain):[^ ]+' /var/log/exim_mainlog | sort | uniq -c | sort -rn | head
# Top script folders (PHP mailers, abused forms)
grep -oE 'cwd=[^ ]+' /var/log/exim_mainlog | sort | uniq -c | sort -rn | headOn cPanel, WHM › Email › View Sent Summary gives the same picture per account without the command line. Once you have the account, look at the subjects it sent (T="..." in the log) to confirm it is spam and not a legitimate newsletter.
4. Own server only: contain it
- Stop the sender, not the whole server.On cPanel,
whmapi1 suspend_outgoing_email user=USERNAMEstops one account's outgoing mail. On DirectAdmin, add the username to/etc/virtual/blacklist_usernames, or one address to/etc/virtual/blacklist_smtp_usernames. Details are in how to suspend outgoing email for an account. - Reset the stolen password, or disable the script: rename or remove the mailer file found in the
cwd=folder, then find how it got there. - Remove only that sender's queued mail. `exiqgrep -i -f 'sales@example\.com'xargs -r exim -Mrm
. Check the count first withexiqgrep -c -f`. - Let the rest of the queue retry normally.Don't force a full queue run against a provider that is rate-limiting you.
Blocking outbound port 25 for the whole server stops every customer's legitimate mail, and exiqgrep -i | xargs exim -Mrm with no filter deletes invoices and password resets waiting for a retry, without telling their senders. Stop the one sender and remove only its messages. The queue commands are explained in managing the Exim mail queue.
5. Own server only: prevent the next one
- Per-domain limits. In WHM, Tweak Settings has a maximum number of emails per domain per hour and a limit on the share of failed or deferred messages a domain may send; set both so a single account can't flood the server.
- Protect forms. Every public form needs a CAPTCHA or honeypot, server-side validation, and a recipient address fixed in code.
- Protect logins. Enforce strong mailbox passwords, keep brute-force protection on, and offer two-factor authentication on the control panel.
- Watch reputation. Register your sending domains in Google Postmaster Tools, and check the queue size daily with a simple cron alert on
exim -bpc. - Keep identity consistent. SPF, DKIM and DMARC for every domain, and a PTR record that matches the server's hostname.
6. Where Domain India fits
On Domain India shared hosting, the server, its logs and its IP reputation are managed for you, and the sending limits above stop one account from flooding the server. You stay responsible for your passwords, forms and website code. If you want mail that is independent of your website, Business Email runs on a separate platform; compare it in Business Email vs hosting email. Domain India VPS plans are self-managed, so on a VPS the steps in sections 3 to 5 are yours to carry out.
- Priced per mailbox - start with one
- Email at your own domain ([email protected])
- Add and remove mailboxes yourself
- Webmail with calendar, contacts and tasks
Prices on the cards exclude 18% GST.
How do I know if my email account is being used to send spam?
Look for a Sent folder full of messages you did not write, bounces for mail you never sent, or bounces saying your account exceeded its sending limit. On shared hosting, support can check the server logs and tell you which mailbox or script sent the mail.
What should I do first if my mailbox is sending spam?
Change the password of every mailbox, suspend outgoing mail on the suspect address (on cPanel, Email Accounts, Manage, then Suspend or Hold), change your control panel password and open a support ticket.
How many emails can a Domain India shared hosting account send?
200 messages per hour per account on cPanel and 1,000 per day on DirectAdmin. Each recipient counts as one message.
How do I find which cPanel account is flooding my own server?
As root, use WHM, Email, View Sent Summary, or search /var/log/exim_mainlog for A= entries (mailbox logins) and cwd= entries (scripts) and count them per sender.
How do I delete spam from the Exim queue without losing real mail?
Filter by the spammer's sender address: exiqgrep -i -f with the address, piped to xargs -r exim -Mrm. Never delete the whole queue, which also removes legitimate mail waiting for a retry.
Will Gmail stop delaying my mail after a flood?
Usually yes, once the spam has stopped and the server sends clean, authenticated mail again for some days. There is no form to request it; the recovery comes from clean traffic.
Ready to stop a flood? On shared hosting, change your mailbox passwords now and open a support ticket with a sample bounce. Live chat is available 24/7, and tickets get a first response within 15 minutes.
Send us your domain, the suspect mailbox, the time and a sample message with full headers, and we will check the server logs for you.
Open a support ticket