MB Bluejuice
Security

Your website is sending spam: when the server becomes a relay

Emails stop reaching customers and your IP lands on blacklists. The usual causes and what to do first.

· updated 2026-10-07

The first sign is usually not technical: customers stop receiving order confirmations and your messages land in spam folders.

Three possible causes

  1. Malicious code on the site. An uploaded PHP script sends mail directly through the server function, bypassing WordPress.
  2. A compromised mailbox. The password was stolen and mail is sent over SMTP with your credentials — in this case the website is clean.
  3. An unprotected contact form. A form without bot protection is used to relay messages to third parties.

How to tell them apart

Look at the mail queue on the server. If the sender is the website system user, the problem is in the site. If it is a specific mailbox, the problem is in the account. Message headers show which process and directory the mail left from.

First steps

  • Pause the mail queue so sending stops.
  • Save several messages with full headers — evidence and a trail.
  • Change the passwords of every mailbox.
  • Check forwarding and filter rules — attackers often leave a copy going to themselves.
  • Once the cause is removed, request delisting from the blacklists.

SPF, DKIM and DMARC records plus form protection without reCAPTCHA prevent most of this. Both are part of our technical maintenance.

Next

Related articles

Need help with your website?

We will review your situation and tell you what to do first.