The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Best Practices to stop outbound spam

Discussion in 'E-mail Discussions' started by Arkaic, Feb 22, 2016.

  1. Arkaic

    Arkaic Member

    Joined:
    Jun 23, 2015
    Messages:
    22
    Likes Received:
    3
    Trophy Points:
    3
    Location:
    United Kingdom
    cPanel Access Level:
    Root Administrator
    Hey there,

    Over the past few weeks I've caught multiple Wordpress installs on my server being the cause of sending out spam, outdated/vulnerable plugins etc.

    The sender emails are all fake i.e.

    firstname.surname@domain.com

    What are the best practices, for a server administrator (other than telling users to keep wordpress updated and secure), for preventing these emails from being sent?

    Is there a method to prevent outbound emails from email accounts that don't exist on the server?


    -SMTP_Block enabled.
    -Prevent “nobody” from sending mail
    -Max hourly emails per domain 120

    Anything else to consider? (I've probably forgotten a few other settings I've changed to combat this!)

    Furthermore, is there a particular command or method to find the exact file being used to send out spam?
    I'm aware of the following which is very useful, however, is rather difficult if there are many php files in the directory and the spam script is conspicuously named.
    grep cwd /var/log/exim_mainlog | awk '/public_html/ {print $3}' | sort | uniq -c

    Thanks :)
     
    #1 Arkaic, Feb 22, 2016
    Last edited: Feb 22, 2016
  2. 24x7server

    24x7server Well-Known Member

    Joined:
    Apr 17, 2013
    Messages:
    1,146
    Likes Received:
    34
    Trophy Points:
    48
    Location:
    India
    cPanel Access Level:
    Root Administrator
  3. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    30,787
    Likes Received:
    665
    Trophy Points:
    113
    cPanel Access Level:
    Root Administrator
    Hello :)

    The document referenced in the previous response is a good place to start. As far as the command, you could try searching the files in those directories for strings related to email. For instance:

    Code:
    grep mail /home/$user/public_html/script/*
    Thank you.
     
Loading...

Share This Page