If you have received an abuse complaint, your outgoing mail has been blocked, or your inbox is suddenly full of bounce messages, something may be sending spam from your hosting account. This guide shows how to find the cause yourself, from inside your own control panel, mailboxes and website, and when to ask our support team to check the server logs for you.
Spam from a hosting account almost always comes from one of three places: a mailbox whose password was stolen, a website contact form that spammers are abusing, or a hacked WordPress site running a hidden mailer. Contain it first by changing every mailbox password and pausing sending on the suspect mailbox. Then check each mailbox for strange forwarders and filters, and check your website for unprotected forms, unknown plugins and recently changed files. Server mail logs are shared by every account, so you cannot read them yourself; open a ticket with the dates and a sample bounce, and support can tell you which mailbox or script sent the mail.
1. Signs that your account is sending spam
| What you notice | What it usually means |
|---|---|
| An abuse report or a message from support about spam from your account | Mail really is leaving through your hosting account |
| Mail stops sending with an error about a limit | Something is sending far more than usual and has hit the hourly or daily cap |
| Hundreds of bounce messages for mail you never wrote | Either your account is sending spam, or someone is forging your address from elsewhere (see section 5) |
| Your messages suddenly go to spam or are rejected | Your domain or the server's address may have been listed on a blocklist |
| Sent folder full of messages you do not recognise | A mailbox password has almost certainly been stolen |
Every hosting account has a sending limit, which caps the damage: 200 messages per hour per account on cPanel and 1,000 per day on DirectAdmin. Hitting it on a normal working day is a strong sign that something other than you is sending; see do you limit the amount of mail I can send.
2. The three usual sources
The steps below work through all three. Do the containment steps first, even before you know which one it is.
3. Contain it in the first few minutes
- Change every mailbox password.In your control panel's email accounts page, give each mailbox a new, unique password. Start with any address that has unfamiliar messages in its Sent folder.
- Pause sending on the suspect mailbox.On cPanel, open Email › Email Accounts, click Manage next to the mailbox, and set outgoing mail to Suspend or Hold. Incoming mail keeps arriving. On DirectAdmin and Webuzo, ask support to block sending for that mailbox.
- Change your control panel and client area passwords.If an attacker has those, they can simply create a new mailbox. Turn on two-factor authentication for your Domain India account; see how to enable two-factor authentication.
- Switch off the website formif you suspect it, until it is fixed. Replacing the contact page with a plain email address for a day is better than feeding a spam run.
- Tell support.Open a ticket so we know you are working on it; section 6 lists what to include.
4. Check your mailboxes
Log in to webmail for each address (see how to log in to webmail) and look for the traces an attacker leaves:
- Sent folder. Spam sent through a mail app or webmail often appears here. Spam sent by a script does not.
- Forwarders. An unknown forwarder copies your incoming mail to an outside address, a common way to spy on invoices and password resets. Check the forwarders page in your panel and remove anything you did not set up; see how to create and delete an email forwarder.
- Filters and autoresponders. A filter that deletes or redirects replies can hide the attack from you. An autoresponder you did not create can be used to send spam text.
- Identities in webmail. Check that the sender name and reply-to address have not been changed.
- Every device. Update the new password on each phone and computer. Scan any computer that used the mailbox for malware, because a keylogger would capture the new password too.
5. Check your website
If the mailboxes look clean, the website is the next suspect, especially if you run WordPress.
- Contact forms. Every public form needs spam protection, such as a CAPTCHA or a honeypot field. A form must never let the visitor choose the recipient address or put raw text into the email headers. For a safe PHP form on our servers, see how to use PHPMailer for contact forms.
- Plugins and users. In WordPress, look for plugins you did not install, plugins with no update in over a year, and administrator accounts you do not recognise.
- Recently changed files. In the File Manager, sort by date and look for PHP files you did not create, especially inside
wp-content/uploadsor with random names. See how to use the File Manager.
On our cPanel servers, Imunify360 removes malicious code from infected files automatically, but it does not email you and you cannot start a scan yourself. If you find signs of a hack, follow the security checklist for a hacked website. Domain India does not clean hacked websites as a free service.
Anyone can put your address in the From line of a spam message sent from their own server. The bounces then come to you, although nothing left your account. Open one bounce, view the original message's headers, and read the Received lines: if the message never passed through your hosting server, it was forged elsewhere. The long-term fix for forgery is a DMARC record; see setting up DMARC.
6. What support can check for you
The mail logs on shared hosting belong to the whole server, so customers cannot read them, and our cPanel servers do not offer cPanel's Track Delivery tool. Our support team can search the logs and tell you whether mail was sent by a logged-in mailbox or by a script, and which one. To make that quick, include in your ticket:
- the domain and the mailbox you suspect, if any;
- the date and approximate time of the spam or the complaint;
- one bounce message or spam sample, with its full headers. In most webmail, open the message and choose the option to view the source or headers, then copy all of it.
Open a ticket at /support/ticket, or from the client area. Support is available on 24/7 live chat, and tickets get a first response within 15 minutes; how long the investigation takes depends on what we find.
7. After the clean-up
- Make sure the cause is fixed.A new password without removing a mailer script, or a fixed form without changing a stolen password, means the spam starts again.
- Ask support to lift any blockon your account or mailbox once you have fixed the cause.
- Check blocklists.If your mail is still rejected, search your domain on a public blocklist checker and follow each list's removal process.
- Tighten your domain.Make sure SPF and DKIM are correct (in cPanel, Email › Email Deliverability), then publish a DMARC policy.
- Keep watching.Look at the Sent folders and your website's plugin list again after a week.
8. Running your own server?
This guide is for Domain India shared hosting. If you run your own mail server on a VPS, you have root access and can read the logs directly: see mastering mail log analysis and how to suspend outgoing email for an account.
9. Where Domain India fits
Email included with cPanel, DirectAdmin and Webuzo hosting runs on the same server as your website, so a hacked website can affect your mail. If you want mail that is independent of the website, Domain India Business Email runs on a separate platform, with two-factor authentication and DKIM signing on every message:
- Priced per mailbox - start with one
- Email at your own domain ([email protected])
- Add and remove mailboxes yourself
- Webmail with calendar, contacts and tasks
The price on the card is a live Domain India list price and excludes 18% GST. To compare the two, read Business Email vs the email included with your hosting.
How do I find out which email account is sending spam?
Check the Sent folder of each mailbox in webmail, and look at the headers of a bounce or spam sample. Spam sent by a script usually leaves no trace in any Sent folder. On shared hosting, open a support ticket with the dates and a sample with full headers, and support can check the server logs and tell you which mailbox or script sent it.
Can I see the server mail logs on my shared hosting account?
No. The mail logs on shared hosting cover every account on the server, so they are not available to customers. Support can search them for you.
What should I do first if my email account is sending spam?
Change the password of every mailbox, then pause outgoing mail on the suspect mailbox (on cPanel, Email Accounts › Manage › Suspend or Hold). Change your control panel and client area passwords too, and open a support ticket.
Why am I getting bounces for emails I never sent?
Either your account is sending spam, or someone is forging your address on their own server. Read the Received lines in the headers of the returned message: if it never passed through your hosting server, it was forged elsewhere. A DMARC record helps stop forgery.
Will Domain India clean my hacked website for me?
Hacked-site clean-up is not a free service. Our cPanel servers remove known malicious code from infected files automatically, and support can tell you what the server logs show, but finding and fixing the vulnerable plugin, form or password is the site owner's job.
Ready to track down the problem? Change your mailbox passwords now, work through the checks above, and open a support ticket with the dates and a sample message so we can check the server side for you.
Send us your domain, the dates and a sample message with full headers, and we will check the server logs for you.
Open a support ticket