Skip to main content

How to fix spam abuse case?

For shared or reseller hosting packages

If you have received an abuse notification regarding spam or unsolicited email originating from your hosting account, this usually means that email associated with your account has been detected sending messages that appear to violate anti-spam policies.

There are several possible causes:

  • An email account has been compromised.

  • A website or PHP script has been compromised and is sending email.

  • A contact form or other website form is being abused.

  • A stolen cPanel, FTP, or website password is being used to send messages.

  • A vulnerable or outdated website application is being exploited.

  • A legitimate mailbox has been used to send spam after its password was compromised.

The first step is to identify where the messages are coming from.

1. Review the abuse notification

Start by carefully reviewing the abuse notification received from us.

Usually, in the evidence, Hostens provides details related to the spam. So please, investigate the evidence information because it helps to identify the issue.

The notification may contain information such as:

  • The affected domain

  • The sender email address

  • The recipient address

  • The date and time of the messages

  • The subject of the spam message

  • The number of messages detected

  • The originating IP address

  • Message headers or mail logs

Keep this information available while investigating the issue.

In particular, check whether the notification identifies a specific email address.

If a specific mailbox is mentioned, that mailbox should be investigated first.

2. Check your email accounts in cPanel

Log in to cPanel and open:

Email Accounts

Review all email accounts associated with your domain.

Look for:

  • Accounts you do not recognize

  • Old accounts that are no longer required

  • Accounts belonging to former employees or users

  • Unexpected forwarding addresses

  • Mailboxes that may have been compromised

Remove email accounts that are no longer needed.

3. Change the affected mailbox password

If the abuse notification identifies a specific mailbox, change its password immediately.

Use a strong, unique password that is not used for any other service.

Do not reuse:

  • Your cPanel password

  • Your website administrator password

  • An old email password

  • A password used on another website

If you suspect that multiple mailboxes may have been compromised, change the passwords for all affected accounts.

4. Check email forwarding settings

A compromised account may have forwarding rules configured by an attacker.

Check your email settings for unexpected forwarding addresses.

Also check for suspicious filters or autoresponders if your hosting environment provides these features.

5. Check for compromised website scripts

Spam does not necessarily originate from an email mailbox.

A compromised website can send large quantities of email through PHP or another server-side application.

This is particularly important if:

  • No email account appears to be compromised.

  • The spam sender is not a real mailbox on your domain.

  • The website contains contact forms or other email forms.

  • Your website recently had a malware infection.

  • The spam started after a website compromise.

If you recently received a malware abuse notification for the same hosting account, investigate the website carefully.

Use ImunifyAV to scan the hosting account for malware.

If infected files are detected, follow the malware cleanup procedure and remove or replace confirmed malicious files.

6. Check website contact forms

Publicly accessible forms can sometimes be abused to send spam.

Examples include:

  • Contact forms

  • Feedback forms

  • Registration forms

  • Password-reset forms

  • Comment forms

  • Newsletter subscription forms

  • Any form that sends an email to an address supplied by the visitor

For example, a vulnerable contact form may allow an attacker to submit:

Recipient: [email protected] Subject: Spam message Message: ...

If the website sends the email directly to the supplied address without appropriate restrictions, the form may be abused as a mail relay.

Your website developer should review all forms that send email.

7. Check your website for vulnerabilities

Make sure that your website software is fully updated.

For example, if you use WordPress, update:

  • WordPress

  • Plugins

  • Themes

Also remove plugins and themes that are no longer required.

If you use another CMS or web application, update it to a supported version and apply the latest security updates.

An outdated application may allow an attacker to upload a malicious script or otherwise gain access to the hosting account.

8. Review cPanel and FTP accounts

Spam can also be caused by compromised hosting credentials.

In cPanel, review:

FTP Accounts

Remove FTP accounts that are no longer required.

Also review access to the hosting account and website.

If you believe that your cPanel or FTP credentials may have been exposed, change those passwords as well.

If available, use SFTP instead of plain FTP and enable additional account security features such as two-factor authentication.

9. Check for suspicious cron jobs

A compromised website may create a scheduled task that repeatedly runs a spam-sending script.

In cPanel, check:

Cron Jobs

Review the configured cron jobs and look for entries that you do not recognize.

Pay particular attention to commands that:

  • Execute unfamiliar PHP scripts

  • Reference files outside the normal website structure

  • Run very frequently

  • Execute scripts from temporary or suspicious directories

Do not delete a cron job simply because it looks unfamiliar. Some applications legitimately use cron jobs.

If you are unsure, ask your website developer or hosting support team to review it.

10. Check the email sending activity

Your hosting provider may be able to determine how the messages were sent by reviewing mail logs.

Depending on the server configuration, the logs may help identify whether messages were sent through:

  • SMTP authentication

  • A PHP script

  • A website application

  • A compromised mailbox

  • Another local process

This information is particularly useful when it is not clear whether the problem is related to email credentials or the website itself.

If the hosting provider supplies an email delivery or mail tracking interface in cPanel, review the relevant entries there as well.

11. Secure the account

After identifying the likely source of the spam, secure the relevant accounts.

We recommend:

  • Changing affected email passwords

  • Changing the cPanel password if compromise is suspected

  • Changing FTP/SFTP passwords

  • Changing website administrator passwords

  • Updating the CMS and plugins

  • Removing unused applications and plugins

  • Removing unknown FTP accounts

  • Removing unknown email accounts

  • Reviewing suspicious cron jobs

  • Enabling two-factor authentication where available

Use unique passwords for each service.

12. Scan the account for malware

If the spam may be related to the website, run a malware scan using Imunify in cPanel.

Review all detected files carefully.

If confirmed malicious files are found, remove or replace them as appropriate.

Important: Do not delete website files simply because they have unusual names. Removing legitimate files can break the website.

If you are unsure about a detected file, provide the file path and Imunify detection information to your website developer or hosting support team.

13. Check whether the spam has stopped

After securing the account, monitor the mail activity.

If your hosting provider has temporarily suspended outgoing email because of the abuse case, they may need to verify that the problem has been resolved before restoring mail service.

If spam continues after changing a mailbox password, this may indicate that the mailbox was not the actual source.

For example, the website itself may still contain a malicious script.

14. Respond to the abuse notification

Once you have completed the cleanup, follow the instructions included in the abuse notification.

Please do not miss to inform in the abuse ticket otherwise, the service will be suspended.

Do not claim that the issue is resolved if spam is still being sent.

15. If you cannot identify the source

If you have completed the basic checks but cannot determine where the spam originated, contact your our abuse team in the ticket and provide:

  • The abuse case reference

  • The affected domain

  • The sender email address, if known

  • The date and time of the reported messages

  • The message subject, if available

  • Any relevant message headers

  • Information about the actions you have already taken

Important

Simply deleting sent emails from a mailbox does not resolve a spam abuse case.

The important part is identifying how the messages were sent and removing the cause of the unauthorized sending.

If the source is a compromised mailbox, secure the mailbox.

If the source is a compromised website, clean and secure the website.

If the source is a vulnerable contact form or application, fix the application.

If the source is compromised hosting credentials, secure the hosting account and related credentials.

Once the underlying cause has been addressed, continue monitoring the account to make sure the unauthorized email activity does not return.

Did this answer your question?