# MailBaby Compromised Account Detection: 2026 Delisting Without Problems

Source: https://srvscripts.com/guides/mailbaby-compromised-account-delisting/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

A hosting server sends mail for hundreds of users, and any one of them can be phished, reuse a leaked password, or run a WordPress plugin with a mail-injection bug. MailBaby’s value on such a server is that it notices the resulting spam run within minutes and stops it before your account’s reputation is spent. The cost is that the affected sender address is blocked until you demonstrate the problem is fixed. This guide describes how to spot a block, how to clean up, and how to get the address delisted through the portal.

In short: MailBaby scores every message per sender address and blocks an address whose rSPAM rate, bounce rate, complaints or sending pattern cross its thresholds, returning a 5xx that names the address; the block shows in your Exim or Postfix log…

**Short answer:** MailBaby scores every message per sender address and blocks an address whose rSPAM rate, bounce rate, complaints or sending pattern cross its thresholds, returning a 5xx that names the address; the block shows in your Exim or Postfix log and on the portal’s block management page. Change the mailbox password or fix the script, kick active sessions, purge that sender’s messages from the queue, and only then use the portal’s delist action with a short note describing the remediation. Delisting before the queue is purged gets the address re-blocked within minutes.

## How detection works

Every message is scored by the content filter and the score is logged against the sender address. MailBaby also tracks the rate of rSPAM rejections, the bounce rate, complaint feedback from mailbox providers and sudden changes in sending pattern for each address. When an address crosses the threshold, the relay stops accepting mail from it and returns a 5xx response that names the address and refers to a block or compromise. Mail from other addresses on the same account continues, which is why per-address blocking is better for a shared server than an IP-level blocklist.

The block is visible in three places: the SMTP rejection text in your Exim or Postfix log, the MailBaby log in the InterServer portal, and the block management page in the same portal, which lists every currently blocked address on the account.

## Recognise it in the log

On cPanel or DirectAdmin:

```
grep 'relay.mailbaby.net' /var/log/exim_mainlog | grep -iE 'block|compromis|rspam' | tail -20
```

On Postfix:

```
grep 'relay.mailbaby.net' /var/log/mail.log | grep 'status=bounced' | tail -20
```

Then find out how much left the server before the block. cPanel’s Exim log records the authenticated user or script path in the `A=` and `X-AuthUser` fields; `exigrep` is the quickest way to count:

```
exigrep 'compromised@example.com' /var/log/exim_mainlog | grep -c '
