📧
Hosting

Email is a quietly dangerous attack channel — one of the most overlooked security risks in shared hosting environments. A single compromised email account can send tens of thousands of spam messages within hours, rapidly destroying the server's IP reputation. When the server's IP lands on global spam blacklists (DNSBL), every customer's email gets caught in spam folders simultaneously, regardless of how legitimate their messages are. The fallout extends beyond immediate delivery failure: Gmail, Outlook and Yahoo downgrade trust scores for the entire server, making future recovery costly and slow. cPGuard Email Security automatically detects these threats in real-time and prevents the cascade of problems before they damage your business.

Two-direction protection: inbound (filtering spam/phishing/malware sent to you) and outbound (detecting compromised accounts sending spam without the owner's knowledge). This bidirectional approach stops both external threats and internal account breaches.

How Incoming Mail Scanning Works

Each inbound email is processed through multiple security layers before it reaches the user's mailbox. This multi-stage approach ensures that no single attack method bypasses the system.

Malware Attachment Scanning

cPGuard examines every attachment, regardless of file type. The scanner detects not only executable malware (`.exe`, `.msi`) but also sophisticated threats embedded in documents: macro viruses in Word files, ransomware hidden in PDFs, and compressed archives containing trojans. Each attachment is cross-checked against multiple malware signature databases, ensuring even newly discovered threats can be caught. If a dangerous attachment is detected, the email is quarantined and the user is notified.

Phishing Link Detection

Phishing attacks work by tricking users into clicking links that lead to fake login pages or credential harvesters. cPGuard analyzes every URL in the email body and compares it against known phishing databases (like Google Safe Browsing). The scanner also checks for homograph attacks — URLs designed to look like legitimate banks or services but actually leading elsewhere — and flags suspicious link patterns such as shortened URLs pointing to untrustworthy domains.

Spam Content Analysis

Beyond attachments and links, cPGuard evaluates the message content itself using machine learning and pattern recognition. It looks for common spam characteristics: unsolicited promotional language, patterns associated with Nigerian prince scams, bulk mailing signatures, and other hallmarks of unwanted email. Content scoring helps distinguish between legitimate bulk mail and deceptive spam.

SRBL Filtering

SRBL (Spam Real-time Blocklist) is a database of IP addresses known to send spam. When an email arrives, cPGuard immediately checks the sender's server IP against SRBL. If the sending IP has a history of spam, the email can be rejected before it even enters the mail queue, saving server resources and preventing the spam from reaching end users.

Detecting Compromised Email Accounts

One of the most damaging scenarios in shared hosting is a customer's email account being hacked and used to send spam undetected. The account owner may not realize they've been compromised for hours or days, during which time thousands of spam messages flood out from their mailbox. By that time, the server's IP is already blacklisted and all legitimate email suffers.

Real-Time Outgoing Mail Monitoring

cPGuard continuously monitors the outgoing mail queue, tracking how many messages each account sends per hour. A typical account might send 10–50 messages per day. If an account suddenly begins sending 1,000 or 5,000 messages in a single hour — a pattern that would be impossible for legitimate business mail — cPGuard immediately flags it as suspicious behaviour.

Automatic Account Suspension

When compromise is detected, cPGuard can automatically suspend the affected email account, stopping the spam cascade instantly. The suspension prevents further damage to server IP reputation while the account owner investigates and resets their password. This automatic response is critical: even a 15-minute delay in stopping a compromised account can result in thousands of additional spam messages sent and significant IP reputation damage.

Alert and Investigation Support

The hosting provider (or account admin) receives an alert with detailed information: which account is compromised, how many messages it sent, how long the suspicious activity lasted, and what the mail queue contains. This data helps the support team quickly pinpoint the breach, communicate with the customer, and prevent re-compromise by requiring a password change.

DNSBL Monitoring — Protecting Your Server's IP Reputation

A server's IP reputation is a critical factor in email deliverability. Gmail, Outlook, Yahoo and other major mail providers check the sending server's IP against multiple DNSBL databases (Spamhaus, SORBS, Barracuda and others) to decide whether to accept, delay or reject incoming email.

What Happens When Your IP Gets Blacklisted

When a server IP is listed on a DNSBL, the consequences are immediate and severe. Gmail may accept the mail but place it directly in the spam folder without even delivering it to the inbox, effectively hiding legitimate messages from recipients. Outlook may reject connections outright, bouncing the email back to the sender. Some receivers may queue your mail for hours, delaying time-sensitive messages. Customers quickly start complaining that their email "doesn't work," even though the server is functioning correctly — the problem is purely reputation-based.

Proactive Monitoring and Early Alerts

cPGuard regularly checks the server's IP against major DNSBL lists and immediately alerts the admin if the IP appears on any list. This early warning allows you to investigate the cause (usually a compromised account sending spam) and fix it before customers are impacted. The earlier you catch the issue, the faster you can get delisted and restore full deliverability.

IP reputation takes weeks or months to recover once damaged. After an IP is delisted, many mail providers gradually restore trust over time rather than immediately accepting all mail again. Preventive monitoring and prompt action are far more cost-effective than trying to recover from a blacklisting incident.

SRBL Mail Server Filtering — Reducing Inbound Spam

While DNSBL protects your outgoing reputation, SRBL protects your incoming mail quality. SRBL (Spam Real-time Blocklist) contains IP addresses of mail servers worldwide that are known to send spam. When a message arrives from one of these servers, cPGuard can reject it before it ever enters your mail queue.

The Benefit of Early Filtering

If cPGuard detects that an inbound email comes from a known spam server and rejects it at the mail protocol level, it saves your server's resources: no disk I/O, no processing, no delivery attempt. This filtering also reduces the spam that your users see in their mailboxes, improving their experience. While end-users would eventually filter spam on their own, pre-filtering at the server level means spam never reaches them at all.

Customizable SRBL Lists

cPGuard can use multiple SRBL lists simultaneously. Different blacklist operators have different criteria and coverage, so using multiple lists gives broader protection. A mail server might be on Spamhaus but not SORBS, and vice versa — using both ensures better coverage.

Domain Reputation and Blacklist Prevention

Beyond the server's IP, cPGuard monitors the domain reputation of emails being sent from your server. Even if your server's IP has a good reputation, if a domain used to send mail from your server is flagged as a phishing or malware source, mail from that domain will be rejected or filtered by receiving mail servers.

Cross-Checking Against Google Safe Browsing

cPGuard checks domains against Google's Safe Browsing API, which tracks domains known to distribute phishing pages, malware and scam content. If a domain shows up as malicious, cPGuard alerts you to stop sending mail from that domain, protecting both your server IP and your customer's domain reputation.

Preventing Domain Reputation Blacklisting

Domains, like IPs, can be blacklisted. If your server is hosting a customer whose domain gets flagged for phishing (perhaps because their site was hacked and used to serve malware), that domain may be added to blacklists. If that customer then tries to use the same domain for email, their outgoing mail will be rejected or heavily filtered. cPGuard detects this issue and alerts you to remediate the underlying problem (cleaning up the hacked website) before it extends to email.

Practical Example: The Compromise Scenario

Let's walk through a real scenario to show how cPGuard prevents a major incident:

It's 2 PM. A customer's email password is compromised (stolen from a data breach on another site where the customer reused the same password). At 2:15 PM, the attacker's bot logs into the account and begins sending spam. Within 15 minutes, the account has sent 3,000 messages to random recipients. cPGuard detects the anomalous volume (normal: 5 messages/hour; current: 3,000 messages/15 minutes) and immediately sends an alert to the hosting provider and automatically suspends the account. By 2:30 PM, the spam stops.

Without cPGuard, the attacker would continue for hours. By 5 PM, the server IP has sent 100,000+ spam messages and is added to Spamhaus and three other major blacklists. Every customer on the server now experiences failed email delivery. Recovery takes 5–10 days even after the account is secured, during which the hosting provider loses customer trust and receives complaints. With cPGuard, the damage is contained to 3,000 messages, IP reputation stays clean, and the customer simply resets their password.

Integration with DirectAdmin Control Panel

On AsiaGB hosting with DirectAdmin, cPGuard is integrated directly into the admin interface. Hosting providers can view real-time mail statistics, quarantined messages, blacklist status and account alerts without leaving the DirectAdmin dashboard. Customers can also view quarantined email in their own account interface and release messages if a legitimate email was incorrectly flagged.

Setting Up cPGuard Alerts

To be effective, cPGuard must be configured to send alerts to the right people at the right time. Most hosting providers configure cPGuard to send notifications when: (1) an account exceeds a send threshold, (2) a phishing or malware attachment is detected, (3) the server IP appears on a new DNSBL, or (4) a domain reputation issue is flagged. Alerts can be sent to the admin email, support tickets, or SMS for critical issues.

Email Security Best Practices Beyond cPGuard

While cPGuard handles automated detection and prevention, it works best alongside manual security practices:

Frequently Asked Questions

What does cPGuard Email Security scan?

It scans incoming mail for malware and phishing, outgoing mail for spam signals or compromised account behaviour, and monitors the mail queue for anomalies. cPGuard uses multiple detection methods including malware signature analysis, phishing link detection against known databases, and behaviour-based pattern recognition.

If an email account is hacked and sending spam, can cPGuard catch it?

Yes — cPGuard monitors outgoing mail volume and patterns in real-time. If any account sends abnormally (e.g. thousands of recipients within minutes), it alerts and can automatically suspend that account before the spam damages the server's IP reputation.

What is SRBL?

Spam Real-time Blocklist — a database of IPs known to send spam. cPGuard uses SRBL to filter inbound mail servers with spam history before their mail enters the server's queue, reducing load and unwanted messages.

How is DNSBL different from SRBL?

DNSBL (DNS-based Blackhole List) is used to check whether your server's own IP is listed on global spam blacklists. SRBL filters inbound mail from other servers, catching spam from external sources.

If my server IP gets blacklisted, what should I do?

cPGuard alerts when your IP appears on a DNSBL. Find the cause first (usually a compromised account sending spam), stop it from the admin panel, then submit delisting requests to each blacklist that listed your IP.

Does cPGuard check domain reputation as well as IP reputation?

Yes — cPGuard monitors both IP and domain reputation by cross-checking against Google Safe Browsing and phishing databases. If a domain shows phishing or malware signals, you'll be alerted to take action before deliverability is affected.

AsiaGB Hosting Includes cPGuard Email Security on Every Plan

AsiaGB uses cPGuard to protect email on every server, automatically monitoring and alerting when email accounts show abnormal behaviour — on SSD from 500 THB/year. Your email security is built in, not added on.

See Hosting Plans

View all cheap Thailand web hosting plans →