Email and IP blacklisting, and how it affects other accounts

Blacklists are lists of email addresses, domains and server IP addresses known to have sent spam. Mail providers check them and reject or junk anything that matches. Getting listed is easy and getting removed is slow, so it is worth understanding how it happens.

What causes it

  • A compromised mailbox. Weak or reused passwords are the single most common cause. Once someone has the password they use the account to send spam, often thousands of messages before anyone notices.
  • A hacked website. An outdated plugin or theme lets an attacker upload a script that sends mail directly from the server.
  • Malware on a local computer that has your mail password saved.
  • Bulk mail sent without consent, including buying or importing a list of addresses.

Why it affects more than just you

This is the part that surprises people. On shared hosting, many customers send mail from the same server IP address. If one account is compromised and sends spam, it is that shared IP that gets blacklisted.

The result is that other customers on the same server can have their mail rejected because of a problem they did not cause. This is why we act quickly, and sometimes without warning, when we detect an account sending spam.

What happens to the account

When we detect spam originating from an account we will normally suspend outgoing mail, or the account itself, to stop the sending immediately. Where a customer has more than one service with us, other linked services on the same account may also be suspended until the cause has been found and fixed, because the same compromised password or the same vulnerable software is often present on all of them.

We will always tell you what we found and what needs to be done.

Getting removed from a blacklist

Delisting is not instant and it cannot be rushed. The cause has to be fixed first, because requesting removal while spam is still being sent gets the listing reapplied and makes the next delisting slower. Some blacklists remove entries automatically after a quiet period, others require a request and a review.

Expect reduced deliverability for a period even after removal. Reputation recovers gradually, not immediately.

What you can do

  • Use a long, unique password on every mailbox, and never reuse it elsewhere
  • Keep websites, plugins and themes updated - see our WordPress security article
  • Scan the computers and phones that have your mail password saved
  • Never send to a purchased or imported list
  • Tell us as soon as you suspect something, rather than waiting to see if it settles

If your mail is being rejected and you are not sure why, open a ticket with the exact bounce message you received. The bounce usually names the blacklist involved, which tells us where to start.

  • 0 Users Found This Useful
Was this answer helpful?

Related Articles

Which hosting plan is right for you

We offer shared hosting from mini to maxi, so you can start small and move up as you grow.Basic -...

Create an email account in cPanel

To add a mailbox such as info@yourdomain.co.za:Log in to cPanel from your client areaUnder Email,...

Set up your email on a phone or desktop

The quickest way to get the correct settings is from cPanel itself:Log in to cPanel and open...

Backing up your website

We take server level backups for disaster recovery, but you should keep your own copy of anything...