Bobcares Logo
Search Call 1-800-383-5193 Emergency Contact
Bobcares Logo
Search Call 1-800-383-5193 Emergency Contact
Emergency Contact

cPanel email security – Most effective measures hand picked

by Visakh S | Sep 22, 2018 | cPanel, Server Administration | 0 comments

Spam! We all hate it.

And that is why people have invented a gazillion ways to fight it.

Anti-spam systems range from SPF & RFC checks to Sender verification & Mail queue cleaners.

Every hosting company provides almost all of these tools to fight spam through administration panels such as cPanel, Plesk, DirectAdmin, etc.

 

The downside of too much choice

It’s good to have a large arsenal of anti-spam tools.

But for an uninitiated web user, all these tools look the same.

It can lead users to overlook strong anti-spam measures, choose the weak ones instead, and cause their mail servers to get blacklisted.

 

Here at Bobcares.com, our Support Engineers help web hosts, digital marketers, and other cPanel users maintain server security as part of our Outsourced Tech Support Services.

Today we’ll list down the top 7 cPanel Email Security measures that has the most effect on blocking outgoing spam and IP blacklisting.

 

Quick primer – The mechanics of outgoing spam

Spammers use broadly two ways to send spam through a server:

  • Exploiting web application vulnerabilities : Spammers use unpatched vulnerabilities to upload spam scripts or bots. These scripts then follow external commands to send out spam mails.
  • Using stolen email logins : Attackers use phishing or brute force to obtain email ID login details. It is then used to send out spam through SMTP authentication.

So, to block spamming, the anti-spam measures must address these two exploit channels.

Now, let’s look at the details.

 

1. Restrict outgoing SMTP connections to Exim & Mailman

Spam scripts connect to port 25 of remote mail servers to send spam.

If left unchecked, this is an open playing field for malware to send spam anywhere they want.

That is why here at Bobcares, we enable SMTP connection restriction in the servers we support. It limits outgoing port 25 connections to only Exim server and Mailman mailing list.

This forces all web scripts to send mails via the Exim server, which allows us to keep track of how many mails were sent by each user.

 

2. Limit the number of mails allowed per hour

Let’s assume that despite all our precautions, a spam script did indeed manage to get into the server.

It’ll try to blast out thousands of mails an hour. If these mails land in spam detectors, the mail server IP will be blacklisted.

To prevent that, we set a limit on the number of mails that can go out per hour for any account.

We’ve found that most domains do not send more than 50 mails an hour. So we set the default mail limit as 50 for all cPanel accounts.

For users that need more than that, we increase it on a case-by-case basis.

This is made possible only by enabling the “SMTP restriction” as we explained above.

Together, these two measures prevents an IP blacklisting even if a spamming does happen.

 

3. Enable a Web application firewall

The majority of spam attacks utilize spam scripts or bots, which is uploaded through web application vulnerabilities.

In the cPanel servers we support, we prevent such malware uploads by using Web Application Firewalls such as mod_security or ComodoWAF.

We integrate it with malware scanning software like ClamAV + Sanesecurity, so that all attempts to upload a malware is promptly blocked.

 

4. Setup Malware scanning & quarantine based on file creation

A web application firewall can block malware uploaded through web applications.

But what about files uploaded through compromised FTP accounts?

To block any malware uploaded through other methods (eg. WebDisk), we use malware scanning based on file system change.

We use a Linux feature called “inotify” to start a malware scan whenever a new file is created in website directories.

The anti-malware tool will quarantine the spam script, thereby preventing any spam from being sent.

 

5. Scan outgoing mail

By implementing all measures till this point, we’ve covered pretty much all possibilities of spam sent through scripts.

That leaves spam sent through compromised email accounts.

Spammers steal mail passwords through compromised PCs, network sniffing, or through brute force attacks.

Then they use the these legitimate email login to send spam through the server.

To combat this issue, we setup outgoing mail scanning.

By default cPanel scans only incoming mails. Outgoing mail scanning will apply all anti-spam filters to authenticated outgoing mails as well.

This setting along with the mail rate limit will pretty much lockdown outgoing spam.

 

6. Setup Brute force detection

A favorite method for hackers to get login details is brute forcing.

Attack bots send hundreds of passwords a minute on email accounts, FTP accounts or web applications to break into the server.

Such a behavior stands out from the normal legitimate logins, and can be detected by a brute force detector like LFD or cpHulk.

We configure and tweak these brute force detectors so that legitimate users who forgot their passwords are not blocked, while actual attackers are banned.

 

7. Setup 24/7 monitoring and emergency response

Now, in ideal conditions, everything we’ve said till now should work, no spam would go out, and the IP shouldn’t be blacklisted.

But what if there’s a new kind of spam or malware that’ll evade the checks and get into the server? What if the blacklist spam traps increase their sensitivity?

That is why we provide 24/7 monitoring & emergency response for our customers.

Server experts manually verify each alert within 10 minutes, and if we detect a spam mail campaign, we quickly login to the server, clear out the spam, and block the affected account.

We then work with the website owner to fix the vulnerable web application or reset the logins to any compromised user accounts.

 

Conclusion

Software vendors have built up a dazzling array of anti-spam tools to fight spam. Ironically, it’s this wide range of options that confuse the users and makes them overlook strong measures, adopt weak solutions, and make their server vulnerable to spamming. Today, we’ve had a fresh look at cPanel email security, where we’ve listed the top 7 effective measures our Support Engineers have used in web hosting servers.

 

Related posts:

    1. WHM IP address missing? Here’s how to fix it
    2. cPanel Nginx support – The why, what and how
    3. How to fix “MySQL conflicts with file from package” error in cPanel
    4. The domain already exists in the Apache configuration : Causes and Fix

Submit a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • A 15-Minute Self-Hosted RAG Stack Tutorial: From Zero to Production
  • Designing Data Pipelines That Prevent Outages Across Global Systems
  • Deployment Automation: Deploy With Efficiency and Consistency
  • What Is Proactive Monitoring? A Complete Guide
  • AI Use Cases: How Artificial Intelligence Is Used Across Industries

Categories

  • Advanced Vulnerability
  • AI Services
  • AI Support
  • AIOps
  • Amazon Web Services (AWS)
  • Apache
  • API Integration
  • Application Development
  • Azure
  • Cloud Cost Optimization
  • Cloud Management
  • Cloud-Native Application
  • Cloudflare
  • cPanel
  • cPanel migration
  • Cyberpanel
  • DDoS
  • Development Service
  • DevOps
  • DevOps Consulting
  • DevSecOps
  • Digital Transformation
  • DigitalOcean
  • DirectAdmin
  • Docker
  • Drupal
  • Ecommerce
  • Filezilla
  • FTP
  • Google cloud platform
  • HAProxy
  • Headless CMS Integration
  • Hosting Support
  • IIS
  • Infrastructure Management & Optimization
  • Kubernetes
  • KVM
  • Laravel
  • Latest
  • Linode
  • Litespeed
  • LXC/LXD
  • Magento
  • Mobile App Development
  • MongoDB
  • Moodle
  • MySQL
  • NFS
  • Nginx
  • OnApp
  • Outsourced Support
  • OVH
  • ovirt
  • pfsense
  • Plesk
  • PostgreSQL
  • PowerDNS
  • Product Engineering
  • Proxmox
  • RedHat
  • Redis
  • Sendmail
  • Server Administration
  • Server Management
  • Software Development
  • SQLServer
  • Technical Support
  • UI/UX
  • Virtualizor
  • VMware
  • VPN
  • Vulnerability Scanning
  • Vultr
  • Web Development
  • Windows
  • WordPress
  • WordPress Hosting
  • WordPressHA

Subscribe to our newsletter

Footer newsletter

Email sales@bobcares.com | Phone 1-800-383-5193

Product Engineering

  • MVP Build
  • MVP to Scale
  • Product Maintenance

Digital Transformation

  • Process Digitization & Automation
  • Systems Integration & Workflow Orchestration
  • Data Enablement & Decision Support
  • Application & Platform Modernization
  • Transformation Execution & Delivery Enablement

AI Services

  • AI Readiness & Use-Case Discovery
  • AI Integration & Application Enablement
  • Intelligent Automation & AI Workflows

Infrastructure Management

  • Always-On Infrastructure Management
  • Proactive Monitoring & Incident Prevention
  • Cloud Cost Control & Optimization (FinOps)
  • Outsourced IT & End-User Support
  • Managed Infrastructure Execution Support

DevOps & Automation Services

  • CI/CD & Release Automation
  • Infrastructure as Code & Platform Standardization
  • Reliability Engineering & Observability
  • DevSecOps Enablement
Product Engineering +
Web Development MVP to Scale Builds Microservices Architecture Agile & Dev Team Augmentation Mobile Apps Ecommerce UI/UX Design QA & Test Automation
Digital Transformation +
Legacy Modernization Workflow Automation Data-Driven Dashboards CRM / ERP Integration Business Process Re-engineering
AI Services +
AI & Machine Learning AIOps Intelligent Automation Business Intelligence & Analytics AI Installation & Compute
Infrastructure Management +
Cloud Setup Cloud Migration Managed Cloud Services Server & Hosting Cost Optimization Performance Optimization Outsourced Support
DevOps & Automation Services +
CI/CD Setup Kubernetes & Docker Infrastructure as Code Cloud-Native Migration DevSecOps
Cybersecurity & Compliance Services +
Security Hardening VAPT Incident Response Backup & DR

© 2026 Bobcares. All Rights Reserved.

  • Careers
  • |
  • Cookie Policy
  • |
  • GDPR
  • |
  • Privacy Policy
  • |
  • Terms and Service
  • LinkedIn
  • YouTube
  • Instagram
  • Facebook

Preview of the new Bobcares experience
NEW UPDATE
See What’s New
at Bobcares

Discover a faster, clearer view of our services and expertise.


Explore the New Experience
Arrow Right