How to Check if Your Server is Sending Spam

·

How to Check if Your Server is Sending Spam

If you run mail for other people, as an ISP, hosting provider, university, SaaS platform or enterprise, your servers can send spam without you knowing. One compromised account, an infected device or a hijacked web form is enough.

The damage adds up fast. Your IP addresses get blocklisted, legitimate mail bounces, and attackers who got in through the mail platform can move further into your network.

This guide shows you how to check whether your server is sending spam and what to put in place to prevent it from happening again.

Check your mail server logs first, then look at blocklists

1. Monitor your outbound mail logs

The two clearest signs that your server is sending spam are a rise in bounces, also called NDRs (non-delivery reports), and growing outbound queues. Both happen when other servers start rejecting or deferring your mail because your IP address or domain has been blocklisted.

Where to look depends on your platform. On Linux mail servers such as Postfix or Exim, check the mail log under /var/log/ (for example mail.log or maillog). On Microsoft Exchange, use message tracking and the queue viewer. Look for:

  • Rising NDR rates, especially rejections that mention a blocklist.
  • Growing outbound queues caused by delivery deferrals. Exchange, for example, can raise an alert when remote queues grow too long.
  • Single accounts sending unusual volumes, or sending to large numbers of unknown recipients.
  • Sending at unusual times, such as a burst of mail from one account in the middle of the night.

If you see these signs, pause outbound mail from the affected accounts or IP addresses straight away. Then find and fix the cause, so other servers stop rejecting your mail and your delivery rates recover.

2. Check spam blocklists

Next, check whether your IP addresses or domains are listed.

  • Use a multi-list checker such as MXToolbox or MultiRBL to see which blocklists include you.
  • Check the lookup pages of the major lists directly, including the Abusix Lookup & Delist service. Our guide explains what each Abusix list means and how to get delisted.
  • Look at the pattern. Some lists, such as UCEPROTECT, can block whole IP ranges or entire networks, regardless of who else uses them. If only these lists include you, the problem is probably the reputation of your network neighborhood, built up over time. If major lists such as Abusix or Spamhaus list your specific IP address, assume a compromised account, an infected machine, or a misconfiguration such as an open relay.
  • Ignore SORBS results. The SORBS blocklist was shut down in June 2024 and no longer contains any data. If your own servers still query SORBS, remove it from your configuration.

3. Find the cause

Once you know spam is leaving your server, find out where it comes from. These are the most common causes, and how to fix each one:

Cause

How it shows up

How to fix it

Compromised user account

One authenticated account sends high volumes, often to many unknown recipients

Reset the password, end active sessions, enable two-factor authentication, and notify the user

Infected device

Spam comes from a customer or office IP address, sometimes directly to other mail servers

Block the connection, tell the user, and ask them to run a malware scan and update firmware

Vulnerable website or web form

Mail is sent by the web server user (for example through PHP mail) rather than a mailbox

Patch or disable the script, add bot protection to forms, and limit what web applications can send

Open relay

Your server accepts and forwards mail for domains it does not host

Restrict relaying to authenticated users and your own networks, then test from outside your network

Spoofing of your domain

Bounces and complaints arrive for mail your server never sent

Publish SPF, DKIM and DMARC (see below)

 

4. Put these mail security practices in place

The three steps above are the fastest way to get back on track. The practices below stop the problem from coming back. If you provide mail as a service, whether as an ISP, hosting provider, business email provider, or email marketing platform, it is essential.

Block spam before it leaves your network, and reset passwords for blocked accounts

Filter outgoing mail just as you filter incoming mail, with its own set of rules. Here’s how inbound and outbound protection differ. With outbound filtering in place, you can:

  • Block connections to your mail server from users on infected machines.
  • Block messages containing known spam domains or zero-reputation domains, which are commonly used for phishing.
  • Block short URLs and online storage URLs that have been linked to spam. Block the specific URLs, not the whole shortener or storage domain.

For every user you block, reset their password straight away and tell them why. If the problem was the IP address they connected from, let them know their router or computer is compromised. Most users will thank you: nobody wants their account used for spam.

Keep an eye on your password reset logs too. Accounts that need repeated resets are easy to spot there, whether they belong to users with an ongoing problem or to bad actors.

Manage your postmaster address

Every mail domain must have a working postmaster@ address, as required by RFC 5321. Microsoft explains how to configure it in Exchange.

Watch for NDRs arriving at postmaster@ for messages your users never sent, or for recipients who don’t exist. This is a sign that someone is misusing your domain. If a returned message came from one of your users, reset their password and let them know, in case their account is compromised.

If you are a hosting provider, ISP, or university, Abusix Ops (formerly known as AbuseHQ and Guardian Ops) can process these reports for you automatically.

Authenticate your mail and stop spoofing

Without SPF, DKIM, and DMARC records, anyone can send mail that claims to come from your domain. That lets criminals impersonate your executives and staff, and it can get your domain blocklisted for spam you never sent. Read our guide to SPF, DKIM, DMARC and BIMI here.

Check that all three records are published and correct, and sign all outgoing mail with DKIM. Then add these tags to your DMARC record so you receive reports when something fails (defined in RFC 7489):

  • rua=mailto:[email protected] tells receivers where to send aggregate reports, usually daily. Hosting providers, ISPs and universities can point this at their abuse@ address.
  • ruf=mailto:[email protected] tells receivers where to send failure reports on individual messages.
  • fo=1 asks for a failure report whenever SPF or DKIM fails, rather than only when both fail.

If you find another network’s server sending mail as your domain, report it to that network’s abuse contact and ask for it to be taken down.

Sign up for feedback loops and act on high complaint rates

Feedback loops (FBLs) are not just for email marketers. Anyone running a mail server benefits from knowing when recipients mark their mail as spam. Learn how feedback loops work here.

Subscribe your mail servers to FBLs and track complaints per user. Users with a high ratio of complaints to emails sent are either compromised or sending mail people don’t want. Reset their passwords, notify them, and follow your acceptable use policy.

In summary

If you have a delivery problem right now:

  1. Check your outbound mail logs for bounces, growing queues and unusual sending.
  2. Check the blocklists, and read the pattern of who lists you.
  3. Find the cause, and fix it before you request any delisting.

To prevent it happening again:

  • Filter outbound mail and reset passwords for blocked accounts.
  • Monitor your postmaster address.
  • Publish SPF, DKIM and DMARC, and read the DMARC reports.
  • Sign up for feedback loops and track complaints per user.

How Abusix can help

If you run a shared mail service as an ISP, hosting provider, SaaS, or social platform, Abusix Mail (formerly known as Guardian Mail) and Abusix Ops make inbound mail, outbound mail, and network abuse far easier to manage. Abusix Mail provides real-time blocklists to filter in both directions, and Abusix Ops automates the handling of abuse reports.

Explore Abusix Mail here and explore Abusix Ops here.

Read More

·

In the fight against cyber threats, securing unused mail domains is crucial. By pointing your parked or unused mail domains...

·

Cyber threat intelligence processing requires a suite of specialized tools, each serving a unique purpose in the defense strategy. Below...

·

Botnet-assisted Distributed Denial of Service (DDoS) attacks are one of the most common forms of network abuse. In October 2016,...