The problem
A customer’s email password gets phished, and a botnet starts sending spam through your server using perfectly valid SMTP logins. Volume alerts alone catch it late, and by then thousands of phishing messages have your server’s signature on them — a fast lane onto every blacklist.
The solution
VpsMonitor.Pro’s compromised-account detector scans the mail log on a schedule and scores every authenticated sender on the signals that actually betray a stolen mailbox: sending from many different IPs at once (the decisive one — real users send from one or two places), randomised HELO names, phishing-style subjects, recipient-domain patterns and rate-limit hits.
Accounts crossing the alert score trigger an email/Telegram warning; accounts crossing the block score can — if you enable auto-block — have their foreign sending IPs blocked via CSF and their queued spam purged automatically. IPs from your own protected country are never auto-blocked, and the queue is only purged when an attacking IP was actually confirmed and blocked, so a legitimate sender can never lose mail.
The one thing the app deliberately does not automate is changing the mailbox password — that stays a conscious human action, and the alert tells you exactly which account needs it.
Frequently asked questions
What is the strongest sign a mailbox is compromised?
Simultaneous authenticated sending from many unrelated IP addresses. A real user sends from home, office and phone — a botnet sends from dozens of countries at once.
Will the detector block a customer who just sends a newsletter?
No single signal triggers blocking. High volume alone only contributes to the score; without multiple IPs or phishing patterns it stays an alert for review, not a block.
What should I do the moment I get the alert?
Change that mailbox password, check the mail queue, and let the app confirm the sending stopped. If auto-block was on, the sending IPs are already cut off.
Get a license · Download free — 7-day trial