DrivenHost

Blog / security monday

Spam Sent From Your Email? Here's What to Do

What a compromised hosting mailbox looks like from the server side, and the order to work through locking it down, cleaning it up and keeping it shut.

A compromised mailbox rarely announces itself. The first sign is usually indirect. A client mentions your reply never arrived, or a message you sent last week bounces back from a domain that accepted your mail fine in August. Behind that, the account has been pushing out thousands of messages a day under your own domain name. We see this often enough on shared servers that it is worth walking through, so for this week's Security Monday: what a takeover looks like from our side, and the order to work through it.

What it looks like from the server

From the server side a compromised mailbox is obvious in a way it never is from your inbox. The mail logs show successful SMTP authentications for one of your addresses, often from IPs in several countries inside the same hour, and the queue fills with near-identical messages to strangers.

The sending is authenticated, so SPF and DKIM pass. That is the part owners find hardest to accept. Your DNS records are correct, your domain is signing its mail properly, and that is precisely why the spam gets delivered. It really is coming from your account.

Usually outbound limits and queue alerting catch it, and the mailbox gets suspended before the volume damages your domain's reputation. Sometimes a recipient complaint reaches us first. Either way, we can stop the sending, but we cannot work out how the password got out. That part needs you.

Lock the account before you clean anything

Change the mailbox password first, in cPanel, to something new and unrelated to the old one. Not Summer2026 where it used to be Summer2025. Attackers who land a working credential often come back weeks later to try the obvious successors.

Then look for the things a password change on its own will not undo:

  • Forwarders you did not create. A quiet forward to an outside address is the standard way to keep reading your mail after you have locked the door.
  • Filters that move or delete messages. Rules that bin bounce notifications are common, because they keep you unaware that anything is wrong.
  • Autoresponders, which get abused as a cheap relay because nobody ever checks them.

Those all live under the email section of cPanel, per address. Check the compromised account, then every other mailbox on the domain while you are in there, and remove anything you cannot account for.

Work out where the password actually went

Four paths cover almost everything we see.

Someone typed the password into a convincing fake webmail login. Those pages are good now, and they arrive as a "mailbox full" or "verify your account" warning. We went through the patterns in the phishing attempts aimed at site owners.

The same password was used on another service that later leaked it. Credential lists get replayed against mail servers constantly, because mail accepts a login attempt from anywhere in the world.

A device had malware on it, usually a Windows machine with a saved mail client password.

Or the mailbox is still configured on hardware nobody controls any more: a phone that got sold, a laptop that left with a contractor, a tablet in a drawer at a former office. Mail clients store that password in easy reach, and nothing expires it.

Pick whichever of those four you cannot rule out, and deal with it. Rotating the password without finding the leak is how the same account gets compromised twice in a month.

The mailbox is usually not the only thing exposed

This is the step people skip. If that password was also your cPanel password, your WordPress admin login, or your account at the domain registrar, then the mailbox was the cheap part of the break-in. Change those too, with a different password for each, and read through the user lists while you are at it. An extra administrator account in WordPress is easy to miss and will never show up in your inbox. Our notes on who still has access to your site cover that review.

Remember too that control of your mailbox means control of most password resets you own, for as long as the attacker held the account.

Making the next one harder

A few habits do most of the work. Give every mailbox its own password, kept in a password manager rather than in your head, and never reuse the cPanel password for mail. Delete addresses nobody reads, because an unwatched mailbox is the one that sends spam for three days before anyone notices. Give departing staff a forwarder instead of leaving their account live with a password three people know. If your team works from a shared inbox, each person should still have their own business email address, so one leak does not hand over the shared account. Turn on two-factor authentication for cPanel while the subject is in front of you.

None of it shows up as a measurable improvement anywhere. It just means the next credential list replayed against the server finds nothing useful.

If you are seeing bounces you cannot explain, or you suspect an address on your account has been taken over, open a ticket with support and ask us to check the outbound mail logs for your domain. We can usually tell you quickly whether mail is going out that you did not send, and from which address.

security mondayemailaccount security

← All posts

No sales team. No scripts.

Tell us what you're running.
We'll tell you what it needs.

Migrations are free, quotes are written, and the engineer who replies is on the team that will run your server.