Two shared IPs blacklisted by Spamhaus and Barracuda after a compromised contact form turned one account into a spam relay. Contained, delisted and rate-limited within 18 hours.
5 September 2026 · 2 min read
SECTOR
Shared hosting provider
SCALE
~400 domains, 3 servers
PLATFORM
cPanel + Exim
ENGAGEMENT
Incident response
To confirmed blacklist removal
Domains taken off the blast radius
Servers audited end to end
Scroll the diagram sideways to see all of it →
One account’s outbound traffic listed IPs shared by every other site on the pool.
The symptom was pool-wide, not account-specific. The hosting provider saw a spike in bounce-backs and delivery failures across multiple customer domains. Two IPs from the shared pool had appeared on major blacklists, and customer complaints were escalating.
One sender accounted for all of it. We audited outbound mail logs across all three servers and identified a single account sending high volumes through a compromised WordPress contact form plugin. That sending pattern was what triggered the Spamhaus and Barracuda listings. Every other account sharing those IPs was collateral damage.
One account’s outbound behaviour is every other account’s deliverability problem.
An unauthenticated mail injection vulnerability. A customer was running an outdated WordPress plugin carrying a known flaw. The form was being exploited to relay spam through the local MTA using the server default IP.
Two shared IPs blacklisted; customer domains across the pool losing mail.
Audit outbound logs on all three servers, isolate the sender, contain before requesting delisting.
Delisted in 18 hours. Per-account outbound rate limits now standard.
Contain first, then delist. We suspended the compromised account and disabled the vulnerable plugin, then cleaned the remaining spam out of the mail queue. Delisting requests went out with evidence of containment attached. To stop a repeat, we implemented per-account outbound rate limits and added the plugin path to the server malware scanner signatures.
Blacklist removal confirmed within 18 hours. Delivery rates returned to normal across all affected customer domains, and the provider adopted outbound rate monitoring as a standard alert.
One compromised account can put every domain on the IP at risk. We audit, contain and put the limits in place that stop it happening twice.