If you have received an abuse notification regarding spam or unsolicited email originating from your hosting account, this usually means that email associated with your account has been detected sending messages that appear to violate anti-spam policies.
There are several possible causes:
An email account has been compromised.
A website or PHP script has been compromised and is sending email.
A contact form or other website form is being abused.
A stolen cPanel, FTP, or website password is being used to send messages.
A vulnerable or outdated website application is being exploited.
A legitimate mailbox has been used to send spam after its password was compromised.
The first step is to identify where the messages are coming from.
1. Review the abuse notification
Start by carefully reviewing the abuse notification received from us.
Usually, in the evidence, Hostens provides details related to the spam. So please, investigate the evidence information because it helps to identify the issue.
The notification may contain information such as:
The affected domain
The sender email address
The recipient address
The date and time of the messages
The subject of the spam message
The number of messages detected
The originating IP address
Message headers or mail logs
Keep this information available while investigating the issue.
In particular, check whether the notification identifies a specific email address.
If a specific mailbox is mentioned, that mailbox should be investigated first.
2. Check your email accounts in cPanel
Log in to cPanel and open:
Email Accounts
Review all email accounts associated with your domain.
Look for:
Accounts you do not recognize
Old accounts that are no longer required
Accounts belonging to former employees or users
Unexpected forwarding addresses
Mailboxes that may have been compromised
Remove email accounts that are no longer needed.
3. Change the affected mailbox password
If the abuse notification identifies a specific mailbox, change its password immediately.
Use a strong, unique password that is not used for any other service.
Do not reuse:
Your cPanel password
Your website administrator password
An old email password
A password used on another website
If you suspect that multiple mailboxes may have been compromised, change the passwords for all affected accounts.
4. Check email forwarding settings
A compromised account may have forwarding rules configured by an attacker.
Check your email settings for unexpected forwarding addresses.
Also check for suspicious filters or autoresponders if your hosting environment provides these features.
5. Check for compromised website scripts
Spam does not necessarily originate from an email mailbox.
A compromised website can send large quantities of email through PHP or another server-side application.
This is particularly important if:
No email account appears to be compromised.
The spam sender is not a real mailbox on your domain.
The website contains contact forms or other email forms.
Your website recently had a malware infection.
The spam started after a website compromise.
If you recently received a malware abuse notification for the same hosting account, investigate the website carefully.
Use ImunifyAV to scan the hosting account for malware.
If infected files are detected, follow the malware cleanup procedure and remove or replace confirmed malicious files.
6. Check website contact forms
Publicly accessible forms can sometimes be abused to send spam.
Examples include:
Contact forms
Feedback forms
Registration forms
Password-reset forms
Comment forms
Newsletter subscription forms
Any form that sends an email to an address supplied by the visitor
For example, a vulnerable contact form may allow an attacker to submit:
Recipient: [email protected] Subject: Spam message Message: ...
If the website sends the email directly to the supplied address without appropriate restrictions, the form may be abused as a mail relay.
Your website developer should review all forms that send email.
7. Check your website for vulnerabilities
Make sure that your website software is fully updated.
For example, if you use WordPress, update:
WordPress
Plugins
Themes
Also remove plugins and themes that are no longer required.
If you use another CMS or web application, update it to a supported version and apply the latest security updates.
An outdated application may allow an attacker to upload a malicious script or otherwise gain access to the hosting account.
8. Review cPanel and FTP accounts
Spam can also be caused by compromised hosting credentials.
In cPanel, review:
FTP Accounts
Remove FTP accounts that are no longer required.
Also review access to the hosting account and website.
If you believe that your cPanel or FTP credentials may have been exposed, change those passwords as well.
If available, use SFTP instead of plain FTP and enable additional account security features such as two-factor authentication.
9. Check for suspicious cron jobs
A compromised website may create a scheduled task that repeatedly runs a spam-sending script.
In cPanel, check:
Cron Jobs
Review the configured cron jobs and look for entries that you do not recognize.
Pay particular attention to commands that:
Execute unfamiliar PHP scripts
Reference files outside the normal website structure
Run very frequently
Execute scripts from temporary or suspicious directories
Do not delete a cron job simply because it looks unfamiliar. Some applications legitimately use cron jobs.
If you are unsure, ask your website developer or hosting support team to review it.
10. Check the email sending activity
Your hosting provider may be able to determine how the messages were sent by reviewing mail logs.
Depending on the server configuration, the logs may help identify whether messages were sent through:
SMTP authentication
A PHP script
A website application
A compromised mailbox
Another local process
This information is particularly useful when it is not clear whether the problem is related to email credentials or the website itself.
If the hosting provider supplies an email delivery or mail tracking interface in cPanel, review the relevant entries there as well.
11. Secure the account
After identifying the likely source of the spam, secure the relevant accounts.
We recommend:
Changing affected email passwords
Changing the cPanel password if compromise is suspected
Changing FTP/SFTP passwords
Changing website administrator passwords
Updating the CMS and plugins
Removing unused applications and plugins
Removing unknown FTP accounts
Removing unknown email accounts
Reviewing suspicious cron jobs
Enabling two-factor authentication where available
Use unique passwords for each service.
12. Scan the account for malware
If the spam may be related to the website, run a malware scan using Imunify in cPanel.
Review all detected files carefully.
If confirmed malicious files are found, remove or replace them as appropriate.
Important: Do not delete website files simply because they have unusual names. Removing legitimate files can break the website.
If you are unsure about a detected file, provide the file path and Imunify detection information to your website developer or hosting support team.
13. Check whether the spam has stopped
After securing the account, monitor the mail activity.
If your hosting provider has temporarily suspended outgoing email because of the abuse case, they may need to verify that the problem has been resolved before restoring mail service.
If spam continues after changing a mailbox password, this may indicate that the mailbox was not the actual source.
For example, the website itself may still contain a malicious script.
14. Respond to the abuse notification
Once you have completed the cleanup, follow the instructions included in the abuse notification.
Please do not miss to inform in the abuse ticket otherwise, the service will be suspended.
Do not claim that the issue is resolved if spam is still being sent.
15. If you cannot identify the source
If you have completed the basic checks but cannot determine where the spam originated, contact your our abuse team in the ticket and provide:
The abuse case reference
The affected domain
The sender email address, if known
The date and time of the reported messages
The message subject, if available
Any relevant message headers
Information about the actions you have already taken
Important
Simply deleting sent emails from a mailbox does not resolve a spam abuse case.
The important part is identifying how the messages were sent and removing the cause of the unauthorized sending.
If the source is a compromised mailbox, secure the mailbox.
If the source is a compromised website, clean and secure the website.
If the source is a vulnerable contact form or application, fix the application.
If the source is compromised hosting credentials, secure the hosting account and related credentials.
Once the underlying cause has been addressed, continue monitoring the account to make sure the unauthorized email activity does not return.
