Troubleshooting Delivery Issues

How to suspend outgoing emails for all email accounts.

By the Domain India teamPublished 8 min read
Knowledge base article
Contents (8 sections)

When one hosting account on a mail server starts sending spam, the fastest way to protect the server's reputation is to stop that account's outgoing mail while leaving its incoming mail and website alone. This guide shows how to do that on a DirectAdmin or cPanel server you run yourself, using the tools the panels already provide, and what to do instead if you are on shared hosting.

Key takeaways

On a DirectAdmin server, add the DirectAdmin username to /etc/virtual/blacklist_usernames: current DirectAdmin Exim configurations then refuse authenticated SMTP and discard script mail from every mailbox of that user, with no restart. To block one mailbox only, add the full address to /etc/virtual/blacklist_smtp_usernames. On cPanel & WHM, use whmapi1 suspend_outgoing_email user=USERNAME. You need root on your own server; on shared hosting, ask support.

Shared hosting customers: this is for server administrators

Everything below needs root access to the mail server. On Domain India shared hosting the mail server is shared by every account and managed for you. If a mailbox of yours is sending spam, change its password at once and open a support ticket. On cPanel you can also pause sending for a single mailbox yourself (see section 5).

1. When to suspend outgoing mail

Suspending outgoing mail is an emergency brake, not a fix. Use it when:

  • a mailbox password has been guessed or phished and the account is sending spam;
  • a hacked script (often an old contact form or a WordPress plugin) is sending mail through PHP;
  • the server's IP address is heading for a blocklist and you need the flow stopped before you investigate.

Suspending sending keeps the website up and keeps incoming mail arriving, so the customer loses as little as possible while you clean up. Once the cause is fixed, lift the block.

2. DirectAdmin: block every mailbox of one user

Current DirectAdmin builds ship an Exim configuration that already checks three block lists in /etc/virtual/. You do not need to write your own ACL. We confirmed these lookups in the stock exim.conf of DirectAdmin 1.710 on 23 September 2026; on an older build, check first (see section 3).

FileWhat goes in itWhat it blocks
/etc/virtual/blacklist_usernamesDirectAdmin usernames, one per lineAuthenticated SMTP and PHP or script mail from every mailbox of that user
/etc/virtual/blacklist_smtp_usernamesFull email addresses, one per lineAuthenticated SMTP from that one mailbox
/etc/virtual/blacklist_script_usernamesDirectAdmin usernames, one per lineMail sent by that user's scripts (PHP mail) only

To stop all outgoing mail for the DirectAdmin user exampleuser:

  1. Log in as root over SSH.
    Use your server's own root or sudo access.
  2. Add the username.
    Run echo exampleuser >> /etc/virtual/blacklist_usernames. The file is created if it does not exist.
  3. Fix the ownership.
    Run chown mail:mail /etc/virtual/blacklist_usernames and chmod 644 /etc/virtual/blacklist_usernames, so Exim can read it.
  4. Test.
    Send a message from one of the user's mailboxes with a mail client. The server should drop the connection when the client tries to send, and the Exim main log (/var/log/exim/mainlog) should show User account exampleuser is blocked via BLACKLIST_USERNAMES.

Exim reads these files each time it checks a message, so no restart is needed. To lift the block, delete the username's line from the file.

To block one compromised mailbox instead of the whole account:

bash
echo '[email protected]' >> /etc/virtual/blacklist_smtp_usernames

That mailbox can still receive mail and log in to webmail to read it, but it can no longer send through SMTP.

3. Check your DirectAdmin build first

The lists work only if your exim.conf contains the lookups. Check with:

bash
grep -n -E 'BLACKLIST_(USERNAMES|SMTP_USERNAMES|SCRIPT_USERNAMES)' /etc/exim.conf

If the three names are defined and used in the ACLs, you are ready. If nothing comes back, your Exim configuration is out of date. Update it through CustomBuild (./build update followed by ./build exim_conf in /usr/local/directadmin/custombuild) rather than pasting rules into exim.conf by hand: CustomBuild regenerates that file, so manual edits are lost at the next update.

If you do need a custom rule, DirectAdmin's exim.conf includes optional files such as /etc/exim.acl_check_recipient.pre.conf and /etc/exim.acl_check_message.pre.conf. Rules placed there survive updates. See Custom Exim ACL for how to write and test them.

Do not copy the old block_users recipe

An older version of this article suggested a custom ACL in the DATA stage that checked /etc/virtual/${sender_address_domain}/passwd/${local_part}. At that stage $local_part is not the sender's mailbox, so the rule does not reliably match, and the edit lived in exim.conf, where the next rebuild removed it. Use the built-in lists above instead.

4. cPanel & WHM: suspend outgoing mail for an account

cPanel has this built in, both in WHM and in its API. As root:

bash
# Stop all outgoing mail for the cPanel account "exampleuser"
whmapi1 suspend_outgoing_email user=exampleuser

# Allow it again
whmapi1 unsuspend_outgoing_email user=exampleuser

This covers every mailbox and every script under that account. Incoming mail and the website carry on as normal. Messages that were already in the queue are not removed, so after suspending, review the queue and delete the spam. See Managing the Exim mail queue.

cPanel rebuilds its own exim.conf, so never edit that file directly for this purpose.

5. cPanel: pause sending for one mailbox

On cPanel, an account owner can restrict a single mailbox without root access. In cPanel, open Email Accounts, click Manage next to the mailbox, and look for the outgoing email restriction. It offers:

  • Allow: the mailbox sends normally.
  • Suspend: outgoing mail from the mailbox is refused.
  • Hold: outgoing mail is kept in the queue instead of being delivered, so you can inspect it before it goes anywhere.

This is available to Domain India cPanel customers on shared hosting. On DirectAdmin and Webuzo shared hosting, ask support to block a single mailbox for you.

6. After the block: find and fix the cause

A suspension only buys time. Before you lift it:

Change the password
Set a new, long password on the compromised mailbox, and on the control panel login if it may be known.
Find the source
Check the mail log for the sending mailbox or the script path. Script mail usually shows the account's home directory in the log line.
Clean the scripts
Update or remove the vulnerable plugin or form. Add a CAPTCHA to public contact forms.
Clear the queue
Delete the queued spam so it is not delivered once you unblock the account.

For investigation methods, see How to identify outbound spam on a cPanel server and How to investigate email spam abuse problems. If the website itself was hacked, follow the security checklist for a hacked website.

7. Sending limits on Domain India shared hosting

On shared hosting, every account also has a sending limit, which caps the damage a compromised mailbox can do. On our cPanel servers the limit is 200 messages per hour per account; on DirectAdmin it is 1,000 per day. The details are in Do you limit the amount of mail I can send per hour?

8. Running your own mail server on Domain India

A Domain India VPS is self-managed with full root access, so you control Exim, its block lists and its logs. VPS plans do not include cPanel; the VPS page lists the panels offered at checkout. Prices on the card are live and exclude 18% GST.

VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details
How do I stop all outgoing email for one DirectAdmin user?

As root, add the DirectAdmin username to /etc/virtual/blacklist_usernames, one per line, with owner mail:mail. Current DirectAdmin Exim configurations then refuse authenticated SMTP and discard script mail from every mailbox of that user. No Exim restart is needed.

How do I block just one email account on DirectAdmin?

Add the full email address to /etc/virtual/blacklist_smtp_usernames. That mailbox can still receive mail but can no longer send through SMTP.

How do I suspend outgoing email for a cPanel account?

As root, run whmapi1 suspend_outgoing_email user=USERNAME. Run whmapi1 unsuspend_outgoing_email user=USERNAME to allow sending again. Incoming mail and the website are not affected.

Does suspending outgoing mail stop incoming mail?

No. Incoming mail keeps arriving and the website stays online. Only sending is blocked.

Do I need to restart Exim after editing the DirectAdmin block lists?

No. Exim reads the block list files each time it checks a message, so changes take effect straight away.

I am on Domain India shared hosting. Can I suspend outgoing mail myself?

On cPanel you can suspend or hold sending for a single mailbox under Email Accounts, Manage. Server-wide rules need root access, so for anything else, change the mailbox password and open a support ticket.

Spam coming from a mailbox on your shared hosting account? Change its password and open a support ticket. Running your own mail server? Compare VPS plans, or let Business Email handle mail for you.

Run your own mail server on a VPS

Full root access on KVM virtualisation, so you control Exim, its block lists and its logs.

See VPS plans

Ready when you are

Get Business Email from ₹60/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Suspend Outgoing Email for an Account: DirectAdmin & cPanel