Spam Filtering & Blacklists

How to Identify Outbound Spam on a cPanel Shared Hosting Server

By the Domain India teamPublished 9 min read
Knowledge base article
Contents (8 sections)

If spam is leaving a cPanel hosting account, it is almost always coming from one of three places: a mailbox whose password was stolen, a website form that bots are abusing, or a hacked website running a hidden mailer script. This guide shows how to tell which one it is from inside your own cPanel, what our support team checks in the server logs for you, and, in a clearly marked section at the end, how to trace spam yourself on a cPanel server you run as root.

Key takeaways

On Domain India shared hosting you cannot read the server's mail logs, because they cover every account on the server. Contain the problem first: change every mailbox password and put the suspect mailbox's outgoing mail on hold. Then check Sent folders, forwarders, contact forms and recently changed PHP files. Open a ticket with the dates and one sample message with full headers, and support will tell you whether a mailbox or a script sent the mail. The Exim commands in section 8 are only for a cPanel server where you have root.

The full investigation guide

This page is the quick version for cPanel. The complete customer checklist, including forged bounces and blocklists, is in how to investigate email spam and abuse problems.

1. Signs that spam is leaving your account

  • You receive an abuse complaint, or support tells you spam is coming from your account.
  • Your mail stops sending with an error about a limit. Every cPanel account on our servers can send 200 messages per hour per account, so hitting that on a normal day means something else is sending.
  • The Sent folder of a mailbox contains messages nobody in your business wrote.
  • Hundreds of bounces arrive for mail you never sent. This can also be forgery from someone else's server, which the full guide explains how to tell apart.

2. Where outbound spam comes from

A compromised mailbox
Someone has the password, from phishing, a reused password or an infected computer, and logs in to send as that user.
An abused contact form
A form with no CAPTCHA or honeypot lets bots send thousands of messages through your site.
A hacked website
A vulnerable WordPress plugin or theme lets an attacker upload a PHP mailer that sends directly from your account.

3. Contain it first

  1. Change every mailbox password.
    In cPanel, open Email › Email Accounts and give each mailbox a new, unique password, starting with any address that has unfamiliar sent mail.
  2. Hold outgoing mail on the suspect mailbox.
    In Email › Email Accounts, click Manage next to the mailbox and set sending to Suspend or Hold. Incoming mail keeps arriving.
  3. Change your cPanel and client area passwords
    and turn on two-factor authentication, so an attacker cannot simply create a new mailbox.
  4. Take a suspect form offline
    until it has spam protection.
  5. Tell support
    with a ticket, so we know you are working on it.

4. Check your mailboxes

Log in to webmail for each address. Spam sent by a logged-in mailbox often appears in its Sent folder; spam sent by a script does not. Also check the forwarders page in cPanel, mail filters and autoresponders for anything you did not set up, and update the new password on every phone and computer that uses the mailbox. Scan those computers for malware, because a keylogger would capture the new password too.

5. Check your website

  • Contact forms: every public form needs a CAPTCHA or honeypot, must send only to your own fixed address and must never put visitor input into mail headers. See how to use PHPMailer for contact forms.
  • WordPress: look for plugins you did not install, plugins with no updates for a long time, and administrator accounts you do not recognise.
  • Recently changed files: in the File Manager, sort by date and look for unfamiliar PHP files, especially in wp-content/uploads or with random names.

On our cPanel servers Imunify360 removes malicious code from infected files automatically, but it does not email you, and you cannot start a scan yourself. If you find signs of a hack, follow the security checklist for a hacked website. Domain India does not clean hacked websites as a free service.

6. What support checks for you

The mail logs are shared by the whole server, and cPanel's Track Delivery tool is not available on our servers. Support can search the logs and tell you whether the mail was sent by a logged-in mailbox (and which one) or by a script in your website (and which folder it ran from). Include in your ticket:

  • the domain and any mailbox you suspect;
  • the date and approximate time of the spam or complaint;
  • one bounce or spam sample with its full headers (in webmail, open the message and choose the option to view its source).

Open a ticket at /support/ticket or from the client area. Support is available on 24/7 live chat, and tickets get a first response within 15 minutes; the investigation itself can take longer.

Fix the cause, not just the symptom

A new password does not remove a mailer script, and a fixed form does not undo a stolen password. If you only fix one of them, the spam comes back and your account may be limited again.

7. After the clean-up

  1. Ask support to lift any sending block once the cause is fixed.
  2. Check that SPF and DKIM are valid in cPanel under Email › Email Deliverability, and publish a DMARC policy. DKIM is on by default for new cPanel accounts.
  3. If your mail is still rejected, check your domain on a public blocklist checker and follow each list's removal process; see email blacklist removal.
  4. Look at your Sent folders and plugin list again a week later.

8. Own server only: tracing spam with Exim as root

This section applies only to a cPanel server you manage yourself with root access. None of these commands can be run on Domain India shared hosting. Domain India VPS plans do not include cPanel, so it applies to a cPanel server you licence and run elsewhere.

Which accounts are sending through PHP scripts. cPanel's Exim logs the working directory of the script that sent each message:

bash
grep 'cwd=/home/' /var/log/exim_mainlog \
  | grep -o 'cwd=/home/[^ ]*' | sort | uniq -c | sort -nr | head

A high count under /home/USER/public_html/..., especially inside wp-content/uploads or a plugin folder, points to the account and the folder of the mailer.

Which mailboxes are sending after logging in. Authenticated SMTP appears as A=dovecot_login: followed by the mailbox:

bash
grep -o 'A=dovecot_login:[^ ]*' /var/log/exim_mainlog \
  | sort | uniq -c | sort -nr | head

One mailbox with a sudden high count, often logging in from many countries, is a stolen password.

Trace one message.

bash
exigrep MESSAGE_ID /var/log/exim_mainlog   # every log line for that message
exim -Mvh MESSAGE_ID                        # headers, while it is still queued
exim -bpc                                   # how many messages are queued

Contain it. Stop one account's outgoing mail without touching its website or inbox with whmapi1 suspend_outgoing_email user=USERNAME (and unsuspend_outgoing_email afterwards). Remove queued bounces with exiqgrep -i -f '<>' | xargs -r exim -Mrm, but read what is in the queue before deleting anything else. Then reset the stolen passwords or remove the mailer, update the site, and keep WHM's Prevent "nobody" from sending mail and a sensible per-domain hourly limit in place. Our guides on mail log analysis and suspending outgoing email for an account go further.

How do I find out which email account is sending spam on cPanel shared hosting?

Check the Sent folder of each mailbox in webmail, and look at the headers of a sample. Spam sent by a script leaves nothing in any Sent folder. The server mail logs are not available to customers on shared hosting, so open a ticket with the dates and a sample with full headers and support will tell you which mailbox or script sent it.

What should I do first if my hosting account is sending spam?

Change the password of every mailbox, put outgoing mail on the suspect mailbox on hold (in cPanel, Email Accounts, Manage, then Suspend or Hold), change your cPanel and client area passwords, and open a support ticket.

How many emails can my cPanel account send?

Domain India cPanel hosting accounts can send 200 messages per hour per account. Spam uses up that limit quickly, so reaching it on a normal day is a warning sign.

Can I run exigrep or read exim_mainlog on shared hosting?

No. Those tools and logs need root access and cover every account on the server. They are for a cPanel server you manage yourself. On shared hosting, support searches the logs for you.

Will Domain India clean my hacked website?

Hacked-site clean-up is not a free service. Imunify360 on our cPanel servers removes known malicious code from infected files automatically, and support can tell you what the logs show, but fixing the vulnerable plugin, form or password is the site owner's job.

Can spam from my account get my mail blocked?

Yes. Spam can put your domain or the server's address on a blocklist and can lead to your account's outgoing mail being limited until the cause is fixed. Fix the source first, then check blocklists and ask support to lift any block.

Ready to track down the problem? Change your mailbox passwords now, work through the checks above, and open a support ticket with the dates and a sample message so we can check the server side for you.

Think your account is sending spam?

Send us your domain, the dates and a sample message with full headers, and we will check the server logs for you.

Open a support ticket

Ready when you are

Get Business Email from ₹60/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Find Outbound Spam on cPanel Shared Hosting