If contacts are telling you they are receiving strange emails from your address, or your own emails suddenly start bouncing, your email account may have been compromised and used to send spam. This usually happens through a weak or reused password, and it can get your domain or server IP blacklisted if you do not act quickly.
Signs Your Email Account Has Been Compromised
- Contacts report receiving spam or phishing emails from your address that you did not send.
- Your Sent folder in webmail contains messages you never wrote.
- Legitimate emails you send start bouncing or landing in recipients' spam folders.
- You notice unfamiliar auto-forwarding rules sending your mail to an unknown address.
- Your hosting account suddenly shows a spike in outgoing mail volume.
Step 1: Change Your Email Password Immediately
This is the most important step, and it should come before anything else. Log in to your hosting control panel and change the password for the affected email account to something long and unique, not reused from another site.
In cPanel
- Go to Email then Email Accounts.
- Find the affected account and click Manage.
- Under Security, enter a new strong password and click Update Email Settings.
In DirectAdmin
- Go to Email Accounts.
- Select the account's Change Password option.
- Enter a new strong password and save.
Step 2: Remove Any Unauthorized Forwarders or Filters
Attackers sometimes add a forwarding rule so they keep receiving copies of your mail even after you change the password. Check for anything you did not set up yourself.
In cPanel
- Go to Email then Forwarders and delete any forwarding address you do not recognize.
- Go to Email then Filters and check for filters that silently forward or delete incoming mail.
In DirectAdmin
- Go to Email Accounts, open the account, and check its forwarder settings for unfamiliar addresses.
- Go to Filters and remove any rule you did not create.
Step 3: Check the Mail Queue for Outgoing Spam
If the account is actively sending spam, you will usually see a backlog of outgoing messages sitting in the mail queue.
In cPanel
Go to Email then Track Delivery to review recent outgoing mail and confirm whether spam is still being sent.
In DirectAdmin
Go to Email Queue to view, and if needed clear, pending outgoing messages.
If you cannot clear a large spam queue yourself, contact ZIPROF support. A backlog of outgoing spam can affect your whole hosting account's mail reputation if it is not cleared quickly.
Step 4: Check Whether a Website Form Is the Real Source
Sometimes what looks like a compromised email account is actually a contact form or script on your website being abused to send spam through your mail server. If you run WordPress or another CMS, scan it for malware and update all plugins and themes, since outdated or vulnerable software is a common entry point.
Step 5: Check If You Have Been Blacklisted
Once the account is secured, check whether the spam activity got your domain or server IP added to a spam blacklist. That can keep your legitimate emails from being delivered even after the underlying problem is fixed.
For more on this, see How to Check If Your Domain or Email IP Is Blacklisted.