A hosting server sends mail for hundreds of users, and any one of them can be phished, reuse a leaked password, or run a WordPress plugin with a mail-injection bug. MailBaby’s value on such a server is that it notices the resulting spam run within minutes and stops it before your account’s reputation is spent. The cost is that the affected sender address is blocked until you demonstrate the problem is fixed. This guide describes how to spot a block, how to clean up, and how to get the address delisted through the portal.
Table of Contents
Short answer: MailBaby scores every message per sender address and blocks an address whose rSPAM rate, bounce rate, complaints or sending pattern cross its thresholds, returning a 5xx that names the address; the block shows in your Exim or Postfix log and on the portal’s block management page. Change the mailbox password or fix the script, kick active sessions, purge that sender’s messages from the queue, and only then use the portal’s delist action with a short note describing the remediation. Delisting before the queue is purged gets the address re-blocked within minutes.
How detection works
Every message is scored by the content filter and the score is logged against the sender address. MailBaby also tracks the rate of rSPAM rejections, the bounce rate, complaint feedback from mailbox providers and sudden changes in sending pattern for each address. When an address crosses the threshold, the relay stops accepting mail from it and returns a 5xx response that names the address and refers to a block or compromise. Mail from other addresses on the same account continues, which is why per-address blocking is better for a shared server than an IP-level blocklist.
The block is visible in three places: the SMTP rejection text in your Exim or Postfix log, the MailBaby log in the InterServer portal, and the block management page in the same portal, which lists every currently blocked address on the account.
Recognise it in the log
On cPanel or DirectAdmin:
grep 'relay.mailbaby.net' /var/log/exim_mainlog | grep -iE 'block|compromis|rspam' | tail -20
On Postfix:
grep 'relay.mailbaby.net' /var/log/mail.log | grep 'status=bounced' | tail -20
Then find out how much left the server before the block. cPanel’s Exim log records the authenticated user or script path in the A= and X-AuthUser fields; exigrep is the quickest way to count:
exigrep 'compromised@example.com' /var/log/exim_mainlog | grep -c '<='
Several hundred messages in an hour from a mailbox that normally sends five is the confirmation you need.
Stop the source
Do this before touching the relay, or the delisting request will fail as soon as the next batch arrives.
For a mailbox, change the password immediately and terminate active sessions:
uapi --user=USER Email passwd_pop email=compromised domain=example.com password='NEW_STRONG_PASSWORD'
doveadm kick compromised@example.com
For a script, the X-Source and X-Source-Args headers that cPanel adds identify the file. Take the site offline or fix the injection, then scan the account. The full search procedure is in the outgoing spam guide. On DirectAdmin, /var/log/exim/mainlog records the script path when mail_partial logging is enabled in the DirectAdmin PHP mail wrapper.
Purge what is still queued, because Exim will keep retrying it:
exim -bp | grep -B1 'compromised@example.com' | grep -oE '^[0-9A-Za-z-]{16,}' | xargs -r exim -Mrm
Review the queue report script output to confirm no other address is affected. A single compromise often exposes a second, and MailBaby scores the whole account’s behaviour.
Delisting through the portal
Once the source is closed, log in to the InterServer portal and open the MailBaby block management page. Each blocked address has a delist action. Use it only after cleanup; a second block on the same address shortly after a delist is treated as a repeat offence and attracts a longer hold. Where the portal asks for a note, state plainly what happened and what was changed: password reset, plugin patched, queue purged. That note is read by a person when the automated delist is refused.
If the block covers a domain rather than a single address, or the account as a whole has been paused, the portal directs you to open a ticket. Include the server hostname, the affected addresses, the Exim log excerpt showing the volume, and the timestamps of your remediation steps. InterServer keeps 60 days of logs, so they can see the same data you can.
Prevent the next one
The measures that reduce compromise frequency on a hosting server are well known and cheap:
- Enforce strong mailbox passwords and enable WHM » Security Center » Password Strength Configuration with a minimum of 65.
- Cap per-domain hourly sending far below MailBaby’s limit so a compromise produces a small burst rather than a flood; see the outbound limits guide.
- Turn on cPHulk or its DirectAdmin equivalent to stop credential stuffing against SMTP AUTH.
- Prevent the
nobodyuser from sending mail, forcing scripts to authenticate or use the account’s own sender. - Run a regular security audit to catch outdated plugins and unexpected cron jobs.
Verify
After delisting, send a test message from the affected address and confirm in the portal log that it was accepted with a normal score, and in the Exim log that the delivery shows => rather than **. Watch that address for the following 24 hours; the block management page should stay empty. The common pitfall is delisting before purging the queue: Exim retries the queued spam within minutes, the address is re-blocked, and the second delist request is refused.
MailBaby compromised account at a glance

Official documentation: RFC 5321 (SMTP), Linux man pages.
Related guides: MailBaby SPF and domain verification: the spf-c include vs the _mailbaby TXT record · Locking down WHM: 2FA, cPHulk, Host Access Control and scoped API tokens · Certificate not renewing on DirectAdmin: reading the Provisioning History page and lego output.
Frequently asked questions
Does a MailBaby block on one address stop mail for my whole server?
No. Blocks are applied per sender address, so other mailboxes and domains on the same account keep sending. Only a repeated or account-wide pattern leads to a domain block or an account pause, and the portal directs you to open a ticket in that case.
How long does it take to get a sender address delisted from MailBaby?
The portal’s delist action takes effect almost immediately for a first offence once the source is fixed. A second block on the same address shortly afterwards is treated as a repeat and attracts a longer hold, and refused automated delists are reviewed by a person, so include a clear remediation note.
How do I find which script or mailbox sent the spam through MailBaby?
On cPanel, use exigrep on /var/log/exim_mainlog for the blocked address and read the A=, X-AuthUser, X-Source and X-Source-Args fields, which identify the authenticated user or the PHP file. On DirectAdmin, /var/log/exim/mainlog records the script path when the PHP mail wrapper’s logging is enabled.