IP Reputation , Email Spamming and Mass Mailing

azadhussnain

Well-Known Member
May 28, 2020
63
0
6
India
cPanel Access Level
Root Administrator
Hello , my server provider sent me a mail that there are a lot of spamming happening from my IP address and if you not solve that in some time then your IP can be blocked by DataCenter.
I am at risk please anyone help me.

I also seen there are a lot of emails being sent from my server IP. I check senderscore.org and there my IP reputation is Just 1
I got a list of 65 domains which are seen sending emails from my IP but none of them exists in my server but they are sending emails from my IP. How is it possible ? Anyone can help me?
 
Last edited by a moderator:

ZenHostingTravis

Well-Known Member
PartnerNOC
May 22, 2020
273
92
28
Australia
cPanel Access Level
Root Administrator
Hi @azadhussain,

When you set up the server, you should limit the amount of email that can be sent by the server and each account.

It's not too late to restrict the amount of email that can be sent by your server.

It's possible that a site has been hacked and used to relay spam. Do you use Imunify? If not, can you run a maldet scan on your server?

Check the mail queue to see what accounts the spam is being sent from.
 

azadhussnain

Well-Known Member
May 28, 2020
63
0
6
India
cPanel Access Level
Root Administrator
I added limit.
But I think there are many domains that are sending emails from my IP via PHP Mailer.
Most of them are hosted on GoDaddy.
I seen in senderscore.org, there are many domains which are seen sending emails from IP but none of them exists in my server.
But I seen they are sending emails from my IP.
How they can do this?
Can we stop it?
From this anyone can send emails from any IP and down any IP reputation.
Is there any way to stop it?
 

andrew.n

Well-Known Member
Jun 9, 2020
965
358
63
EU
cPanel Access Level
Root Administrator
How many emails do you send out? You can check the number of emails currently in mail queue if you login to WHM under "Mail Queue" option. If you see many stuck emails then probably either some of the accounts are compromised or you have contact forms without captcha. If your hosting provider told you this then they should also forwarded you proof like an example email...from the headers you will be see (X-sender or X-forwarder) how it's being sent out.
 

cPJustinD

Administrator
Staff member
Jan 12, 2021
286
52
103
Houston
cPanel Access Level
Root Administrator
Hey there! In order to remedy the issue, you will first need to fully identify the source of the spam emails. We've published the following articles that outline how to identify the source of spam emails on the server:


Once you have identified the source, you can then work with your system administrator to take the appropriate actions to rectify the issue. Then, if you are on any blacklists, you may then request to be delisted. More on this can be found here: