My site is sending emails I didn't write
Customers report receiving a promotional message or a suspicious follow-up from your domain, or your host flags an unusual sending volume: your CMS's email function is being used without your knowledge.
Signs of a hijacked mail function
- A customer forwards you a promotional or phishing email that appears to come from your contact or order address
- Your host warns you about a daily sending quota being exceeded, while your usual volume of order confirmations hasn't changed
- Password reset or order confirmation emails stop arriving, because your domain has been blacklisted by mail providers over the spam sent alongside them
- The CMS's mail log (where one exists) shows hundreds of messages over a short period, to addresses you don't recognise as customers
- "Unknown address" bounce replies flood a mailbox you rarely check
Why the native mail function becomes a target
PrestaShop, like most e-commerce CMSs, has a built-in email function used constantly for order confirmations, password resets, and tracking notifications. It relies on the server configuration (often the native PHP mail() function or an SMTP server set up in the back office) and on the reputation of the site's domain name.
That reputation is exactly what makes the function worth hijacking. An established e-commerce domain with a history of legitimate sending passes spam filters more easily than a brand-new domain created for the purpose. Depending on the specific flaw involved, a poorly validated form on the public-facing site can be enough to inject extra recipients or content into an email sent by the CMS, without requiring any admin access at all: that's the general mechanism behind a good share of abuse of this kind, independent of the technical detail specific to each case.
In other cases, a compromised admin account is used directly, either through the CMS's own email templates or through a bulk-sending extension (newsletter, marketing) installed for a legitimate purpose, to distribute content with nothing to do with your business.
Either way, the common thread is the same: it isn't your personal mailbox that's compromised, it's the server sending on your behalf. Changing your mail password changes nothing.
How to confirm where the sending is coming from
-
Check the server's mail logs
Most hosts keep an outgoing mail log (often named exim_mainlog or similar) showing sender, recipient and time for every send, independent of anything the CMS logs itself.
-
Compare against actual order volume
A clear gap between the number of orders placed and the number of outgoing emails over the same period confirms an extra sending source exists.
-
Review the site's public forms
Any form that triggers an email (contact, quote request, customer review) is worth checking first, especially if it was added by a third-party extension.
-
Check the domain's reputation
Free IP and domain reputation checkers show whether your domain has already been flagged as a spam source by mail providers.
Related pages
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.