Mail reputation containment in shared hosting

Two shared IPs blacklisted by Spamhaus and Barracuda after a compromised contact form turned one account into a spam relay. Contained, delisted and rate-limited within 18 hours.

5 September 2026  ·  2 min read

SECTOR

Shared hosting provider

SCALE

~400 domains, 3 servers

PLATFORM

cPanel + Exim

ENGAGEMENT

Incident response

18 h

To confirmed blacklist removal

400

Domains taken off the blast radius

3

Servers audited end to end

Environment

Blast radius of one compromised hosting accountOne compromised account relayed spam through the shared IP pool, which listed two IPs and caused delivery failures for roughly 400 domains across three servers. Containment restored delivery within 18 hours.How one account listed the whole IP pool1 compromised accountoutdated contact-formplugin, mail injectionrelaying spam via local MTAShared outbound IP poolIP A — listedIP B — listed~400 domains · 3 serversbounce-backs, delivery failuresSpamhaus + Barracuda listingContainmentsuspend account · disable plugin · purge queue · per-account outbound rate limits · delist with evidence18 h

Scroll the diagram sideways to see all of it →

One account’s outbound traffic listed IPs shared by every other site on the pool.

The problem

The symptom was pool-wide, not account-specific. The hosting provider saw a spike in bounce-backs and delivery failures across multiple customer domains. Two IPs from the shared pool had appeared on major blacklists, and customer complaints were escalating.

Investigation

One sender accounted for all of it. We audited outbound mail logs across all three servers and identified a single account sending high volumes through a compromised WordPress contact form plugin. That sending pattern was what triggered the Spamhaus and Barracuda listings. Every other account sharing those IPs was collateral damage.

One account’s outbound behaviour is every other account’s deliverability problem.

Root cause

An unauthenticated mail injection vulnerability. A customer was running an outdated WordPress plugin carrying a known flaw. The form was being exploited to relay spam through the local MTA using the server default IP.

At a glance

Challenge

Two shared IPs blacklisted; customer domains across the pool losing mail.

Approach

Audit outbound logs on all three servers, isolate the sender, contain before requesting delisting.

Result

Delisted in 18 hours. Per-account outbound rate limits now standard.

The fix

Contain first, then delist. We suspended the compromised account and disabled the vulnerable plugin, then cleaned the remaining spam out of the mail queue. Delisting requests went out with evidence of containment attached. To stop a repeat, we implemented per-account outbound rate limits and added the plugin path to the server malware scanner signatures.

Outcome

Blacklist removal confirmed within 18 hours. Delivery rates returned to normal across all affected customer domains, and the provider adopted outbound rate monitoring as a standard alert.

More case studies

Hidden DNS Dependency Outage

0 Rollbacks required

Live SAN Migration

60+ VMs migrated live

WordPress Performance Recovery

1.8 s Page load, down from 12 s

Shared mail reputation is a shared risk

One compromised account can put every domain on the IP at risk. We audit, contain and put the limits in place that stop it happening twice.