Skip to main content

Disabling single cpanel email account

Comments

6 comments

  • vlee
    Do you use like ConfigServer Security & Firewall - csf? If not you should look into this because does help block possible issues like that. Just a possible fix.
    0
  • zaslayer
    Hi vlee, Thank you for the response. We do use csf. However in this case, I believe the spammer has managed to compromise the account and is in fact authenticating as that user thus csf blocking wont work in this case.
    0
  • vlee
    [quote="zaslayer, post: 1523742">Hi vlee, Thank you for the response. We do use csf. However in this case, I believe the spammer has managed to compromise the account and is in fact authenticating as that user thus csf blocking wont work in this case.
    Maybe this will work and you will need to backup the use email if using IMAP. Delete the user email account make sure that there is no possible scripts on their website that maybe linking use email and mail server information. Then recreate the user email account and use a very strong password and use like !, # $ in the password. Just more thoughts for you.
    0
  • quietFinn
    [quote="zaslayer, post: 1523742">Hi vlee, Thank you for the response. We do use csf. However in this case, I believe the spammer has managed to compromise the account and is in fact authenticating as that user thus csf blocking wont work in this case.
    I would change that cPanel account's password and every email account's passwords. If the emails are sent from outside of the server that would stop it.
    0
  • zaslayer
    That is unnecessarily drastic. Surely if I change the password, and immediately after, restart exim and/or dovecot, it should kill all authenticated sessions to the server and force any new sessions to authenticate again? Therefore the spammers should bot be able to authenticate any longer as they do not have the new password? Am I missing something here? We make use of the password generator that always generates very random strong passwords.
    0
  • cPanelMichael
    Hello :) In addition to changing the email passwords, you can also implement some of the options listed at: cPanel - Prevent Email Abuse Thank you.
    0

Please sign in to leave a comment.