Site AI AuditInternet Solutionsilt

Compromised Email Account Sending Spam: What to Do Right Now

11. oktoober 20268 min lugemistE-kirjade kohalejõudmine
Compromised Email Account Sending Spam: What to Do Right Now

Short answer: If one of your mailboxes is sending spam or phishing, assume the account is compromised and act at once: reset the password, sign out all sessions, remove forwarding rules, filters and app passwords the attacker may have added, and turn on two-factor authentication. Then check whether your domain or mail server has landed on blocklists, warn the people who received the messages and look for the way the attacker got in. SPF, DKIM and DMARC do not stop this, because the messages really are sent from your account.

How to tell that an account is compromised

A compromised mailbox is different from spoofing. With spoofing, someone outside fakes your address and their messages fail authentication. With a compromised account, the attacker logs in as you and sends through your real mail server, so the messages pass SPF, DKIM and DMARC and look completely genuine. Typical signs:

Bounces alone are not proof. If they arrive for messages you did not send and the headers show other servers, it may be spoofing or backscatter instead; our article on backscatter explains the difference. If the Sent folder or the sign-in log shows activity, treat it as a compromise.

First hour: lock the attacker out

  1. Change the password from a device you trust, to a new, long password not used anywhere else.
  2. Sign out all sessions. Most providers have an option to sign out everywhere or revoke sessions. A password change alone does not always end existing sessions.
  3. Remove app passwords and connected apps you do not recognise. Attackers often create them because they keep working after a password reset.
  4. Check forwarding and inbox rules. Delete forwards to unknown addresses and rules that hide, move or delete messages. Attackers use them to read your mail secretly and to hide replies from victims.
  5. Check recovery options, such as the backup phone number and email address, and signatures and auto-replies that may have been changed.
  6. Turn on two-factor authentication for the account, preferably with an authenticator app or security key.

In a company, an administrator can do most of this centrally and also suspend outgoing mail for the account while the cleanup takes place. If several accounts show signs of compromise, act on all of them at once and reset the administrator account too.

Find out how the attacker got in

If you do not close the entry point, the attacker comes back. The usual causes:

Run a malware scan on the devices that use the account, and ask the account owner whether they recently entered their password anywhere unusual. The sign-in log usually shows the first suspicious login, which helps you match it to a phishing message.

Contain the damage

Warn recipients. Send a short, plain message to the people who received the spam or phishing: what happened, that they should not open links or attachments from those messages, and that payment details have not changed. This matters most when the attacker sent fake invoices; our guide to invoice fraud by email explains the typical pattern.

Check other accounts. If the mailbox was used to reset passwords for other services, such as banking, the domain registrar, hosting or social media, check those accounts and change their passwords as well.

Data protection. If the attacker could read emails containing personal data of customers or staff, check your obligations under data protection law. In the EU, some breaches must be reported to the authority within 72 hours.

When the sender is not a person’s mailbox

Sometimes the spam does not come from anyone’s mailbox at all, but from another part of your setup that uses the same mail server or domain. Check these before you conclude that the cleanup is finished:

The mail server’s logs, or your provider’s message trace, show which account or system authenticated for each outgoing message. That is the quickest way to find the real source.

Repair your sending reputation

A burst of spam damages the reputation of your domain and, if you run your own mail server, its IP address. Mailbox providers may now send your normal mail to spam or reject it.

Prevent the next compromise

Strong domain authentication is still important, even though it does not stop a compromised account. A strict DMARC policy prevents outsiders from impersonating your domain, so attackers are pushed towards the much harder route of stealing a real account, as explained in our guide to stopping email spoofing.

How Site AI Audit helps

Site AI Audit checks the DNS side of your email: whether SPF exists, is unique, does not allow every server with +all and stays within ten DNS lookups; whether a DMARC record exists, which policy it uses and whether it collects reports; whether DKIM keys are published at common selectors; and whether MX records are in place. It cannot see sign-ins to your mailboxes and does not check blocklists, so use your provider’s security tools and a blocklist lookup for that. You can check your domain for free, and the pricing page lists plans with daily email checks.

Related reading

The bottom line

A hacked mailbox sends spam that looks perfectly legitimate, because it is sent from your real account. Lock the attacker out in the first hour by resetting the password, ending sessions, removing rules, forwards and app passwords and turning on two-factor authentication. Then find the entry point, warn recipients, check other accounts that use the mailbox for recovery, clear blocklists and send carefully until your reputation recovers.

KKK

Is changing the password enough?

No. Also sign out all sessions, remove unknown app passwords and connected apps, delete suspicious forwarding and inbox rules and turn on two-factor authentication.

Why did SPF, DKIM and DMARC not stop the spam?

Because the attacker sent through your real account and server, so the messages passed authentication. These records stop outsiders from faking your domain, not stolen logins.

How do I know if my domain is on a blocklist?

Look up your mail server’s IP address and your domain with a blocklist checking tool, and check bounce messages, which often name the list that rejected your mail.

Should I tell the people who received the spam?

Yes, briefly. Tell them not to open links or attachments from those messages and confirm that your payment details have not changed.

How long does reputation take to recover?

After a short incident that is fixed quickly, usually days to a few weeks. Blocklist removal can be faster once you request it and the spam has stopped.

#Email Deliverability#Email Security#Sender Reputation
Kontrollige oma veebisaiti — tasuta.Mida veebisaidil parandada — ja millest alustada.
Alusta tasuta

Veel blogist

Kõik artiklid →
Internet Solutions

Veel meie meeskonnalt

Loonud Internet Solutions. Proovige ka meie teisi tooteid — iga üks säästab aega omal moel.

internet-solutions.net ↗