{"id":148875,"date":"2018-10-29T20:54:00","date_gmt":"2018-10-29T19:54:00","guid":{"rendered":"http:\/\/www.lotsofways.de\/?p=148875"},"modified":"2018-10-29T20:54:00","modified_gmt":"2018-10-29T19:54:00","slug":"if-wordpress-suddenly-sends-spam-this-can-be-the-simple-cause","status":"publish","type":"post","link":"https:\/\/www.lotsofways.de\/en\/if-wordpress-suddenly-sends-spam-this-can-be-the-simple-cause\/","title":{"rendered":"If WordPress suddenly sends spam, this can be the simple cause"},"content":{"rendered":"[et_pb_section bb_built=&#8221;1&#8243; fullwidth=&#8221;on&#8221; specialty=&#8221;off&#8221; next_background_color=&#8221;#000000&#8243;][et_pb_fullwidth_image _builder_version=&#8221;3.12.2&#8243; src=&#8221;https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/spam.jpg&#8221; alt=&#8221;Crumpled advertising mail in a mailbox&#8221; title_text=&#8221;Crumpled advertising mail in a mailbox&#8221; \/][\/et_pb_section][et_pb_section bb_built=&#8221;1&#8243; prev_background_color=&#8221;#000000&#8243;][et_pb_row][et_pb_column type=&#8221;1_2&#8243;][et_pb_post_title _builder_version=&#8221;3.4.1&#8243; date_format=&#8221;d.m.Y&#8221; categories=&#8221;off&#8221; comments=&#8221;off&#8221; featured_image=&#8221;off&#8221; \/][et_pb_text _builder_version=&#8221;3.12.2&#8243;]\n<p>WordPress and other content management systems must be able to send e-mails. However, this also entails dangers. A practical example shows: Even without a hack, a WordPress installation can easily become a spam catapult and damage the reputation of the IP addresses and domains involved.<\/p>\n<h2>Sending spam through WordPress: That happened<\/h2>\n<p>The web server on which the WordPress installation in question is located is well secured and not infected by malware. All sites and applications on the server send e-mails via the Amazon SES service, which acts as a smart host or SMTP gateway. Suddenly, it caught the eye: The proportion of bounces (undeliverable e-mails) and complaints (users or providers report spam) in relation to all e-mails sent increased significantly.<\/p>\n<p>This problem had to be analyzed and solved. By default, Amazon SES does not provide any information about which e-mails from which domain lead to bounces and complaints. Only an overview is available to the owner of the SES account. Total number of messages, rejects, bounces and complaints are displayed on the timeline:<\/p>\n<div id=\"attachment_148817\" style=\"width: 866px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-148817\" src=\"https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Rejects-Bounces-Complaints.jpg\" alt=\"Amazon SES Rejects, Bounces, Complaints\" width=\"856\" height=\"214\" class=\"size-full wp-image-148816\" data-wp-pid=\"148816\" nopin=\"nopin\" srcset=\"https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Rejects-Bounces-Complaints.jpg 856w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Rejects-Bounces-Complaints-300x75.jpg 300w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Rejects-Bounces-Complaints-768x192.jpg 768w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Rejects-Bounces-Complaints-610x153.jpg 610w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Rejects-Bounces-Complaints-510x128.jpg 510w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Rejects-Bounces-Complaints-800x200.jpg 800w\" sizes=\"(max-width: 856px) 100vw, 856px\" \/><p id=\"caption-attachment-148817\" class=\"wp-caption-text\">Amazon SES Rejects, Bounces, Complaints<\/p><\/div>\n<p>In order to identify the cause of the problem, the account holder has to subscribe to notifications per domain. He configures a so-called SNS Topic for this purpose.<\/p>\n<div id=\"attachment_148822\" style=\"width: 1124px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-148822\" src=\"https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Notifications.jpg\" alt=\"Amazon SES Notification Topics\" width=\"1114\" height=\"362\" class=\"size-full wp-image-148821\" data-wp-pid=\"148821\" nopin=\"nopin\" srcset=\"https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Notifications.jpg 1114w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Notifications-300x97.jpg 300w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Notifications-768x250.jpg 768w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Notifications-1024x333.jpg 1024w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Notifications-610x198.jpg 610w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Notifications-1080x351.jpg 1080w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Notifications-510x166.jpg 510w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Notifications-800x260.jpg 800w\" sizes=\"(max-width: 1114px) 100vw, 1114px\" \/><p id=\"caption-attachment-148822\" class=\"wp-caption-text\">Amazon SES Notification Topics<\/p><\/div>\n<p>Result: Rejects, bounces or complaints are reported to the owner in the desired way, for example by e-mail in JSON format.<\/p>\n<div id=\"attachment_148819\" style=\"width: 717px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-148819\" src=\"https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Complaint-Notification.jpg\" alt=\"Amazon-SES-Complaint-Notification\" width=\"707\" height=\"109\" class=\"size-full wp-image-148818\" data-wp-pid=\"148818\" nopin=\"nopin\" srcset=\"https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Complaint-Notification.jpg 707w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Complaint-Notification-300x46.jpg 300w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Complaint-Notification-610x94.jpg 610w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/Amazon-SES-Complaint-Notification-510x79.jpg 510w\" sizes=\"(max-width: 707px) 100vw, 707px\" \/><p id=\"caption-attachment-148819\" class=\"wp-caption-text\">Amazon-SES-Complaint-Notification<\/p><\/div>\n<p>Clear advantage: As the owner of the Amazon SES account, we now know which domains are responsible for the increased spam volume. In the next step, the analysis continues. Is the amount of spam generated by the hosting customer directly in the e-mail client or on the workstation that sends it via SMTP? Or is the WordPress installation on the web server to blame, for example, because it was hacked?<\/p>\n[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;1_2&#8243;][et_pb_text _builder_version=&#8221;3.12.2&#8243;] [card title=\"Spam Slingshot Contact Form\" text=\"text-darken-3 grey\" title_color=\"blue\"]\nMake sure that hackers cannot send e-mails in your name to uninvolved third parties. This abuse of WordPress and others <a href=\"https:\/\/de.m.wikipedia.org\/wiki\/Content-Management-System\" target=\"_blank\" rel=\"noopener\">CMS<\/a> as a spam catapult becomes possible if a contact form that is not sufficiently protected against spam entries sends automatic acknowledgements of receipt to the sender address entered in the form.<br \/>\n[\/card]\n[card title=\"Impending Danger\" text=\"text-darken-3 grey\" title_color=\"blue\"]\nWhen it comes to email deliverability, the reputation of the sender IP and sender domain are relevant. If spam messages are repeatedly complained about among your senders, you damage your reputation and risk that the deliverability of your legitimate messages decreases.<br \/>\n[\/card][card title=\"How can I further Reduce Spam?\" text=\"text-darken-3 grey\" title_color=\"blue\"]\nConfigure your email domain strictly by using <a href=\"https:\/\/de.m.wikipedia.org\/wiki\/Sender_Policy_Framework\" target=\"_blank\" rel=\"noopener\">SPF<\/a>, <a href=\"https:\/\/de.m.wikipedia.org\/wiki\/DomainKeys\" target=\"_blank\" rel=\"noopener\">DKIM<\/a> and <a href=\"https:\/\/de.m.wikipedia.org\/wiki\/DMARC\" target=\"_blank\" rel=\"noopener\">DMARC<\/a> and make your DMARC policy more restrictive step by step. In this way, you effectively prevent third parties from successfully sending spam on your behalf in other scenarios not addressed in this article. Messages are then rejected directly by the receiving server if they are not legitimate, without interaction with the recipient and thus a spam complaint. However, the integration of a strict DMARC policy requires experience and close monitoring. If it is too strict or incorrect, e-mails will be lost.[\/card]\n[card title=\"Help needed?\" text=\"text-darken-3 grey\" title_color=\"blue\"]\nEvery month we send a large number of legitimate emails to customers with a strong reputation focus and are happy to help with email deliverability and sender reputation. Please do not hesitate to contact us!<br \/>\n[link text=\"blue\" to=\"\/contact\/\"]Contact[\/link]\n[\/card] [\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row][et_pb_column type=&#8221;2_3&#8243;][et_pb_text _builder_version=&#8221;3.12.2&#8243;]\n<h2>Analysis of the e-mails sent by WordPress<\/h2>\n<h3>The plugin &#8220;WP Mail Logging&#8221; does a good job in root cause analysis on the WordPress level.<\/h3>\n<p>It performs the simple task of logging all e-mails sent by a WordPress installation in tabular form. After WP Mail Logging has been installed and activated, a functional test is recommended, for example by triggering a password reset mail. If everything fits, we now have a functioning control system. It is supposed to tell us whether malicious software sends e-mails from our WordPress installation. A parallel malware scan is recommended, for example with WordFence or the Sucuri scanner. Sucuri also offers a nice <a href=\"https:\/\/wp.cool\/wordpress-site-infected-how-to-clean-a-wordpress-hack\/\" target=\"_blank\" rel=\"noopener\">guide to clean infected WordPress websites<\/a>.<\/p>\n<div id=\"attachment_148824\" style=\"width: 1106px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-148824\" src=\"https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/WP-Mail-Logging-Overview.jpg\" alt=\"WP Mail Logging Overview\" width=\"1096\" height=\"348\" class=\"size-full wp-image-148823\" data-wp-pid=\"148823\" nopin=\"nopin\" srcset=\"https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/WP-Mail-Logging-Overview.jpg 1096w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/WP-Mail-Logging-Overview-300x95.jpg 300w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/WP-Mail-Logging-Overview-768x244.jpg 768w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/WP-Mail-Logging-Overview-1024x325.jpg 1024w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/WP-Mail-Logging-Overview-610x194.jpg 610w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/WP-Mail-Logging-Overview-1080x343.jpg 1080w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/WP-Mail-Logging-Overview-510x162.jpg 510w, https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/WP-Mail-Logging-Overview-800x254.jpg 800w\" sizes=\"(max-width: 1096px) 100vw, 1096px\" \/><p id=\"caption-attachment-148824\" class=\"wp-caption-text\">WP-Mail-Logging-Overview<\/p><\/div>\n<p>The next step is to wait and see &#8211; as long as the admin does not find an acute infection of the WordPress website, which would also explain the unwanted sending of e-mails.<\/p>\n<p>In our current case, the analysis actually led to a result: the contact form was to blame. The website operator had insufficiently protected his form from spam entries and had also configured an automatic acknowledgement of receipt. Spammers could thus enter any sender addresses in the contact form. The automatic acknowledgement of receipt was sent to the contact form via WordPress, web server and Amazon SES as gateway.<\/p>\n[\/et_pb_text][et_pb_image _builder_version=&#8221;3.12.2&#8243; src=&#8221;https:\/\/www.lotsofways.de\/wp-content\/uploads\/2018\/09\/WP-Mail-Logging-Details.jpg&#8221; alt=&#8221;Analyze WordPress spam with WP Mail Logging: Detail view of an abused e-mail&#8221; title_text=&#8221;Analyze WordPress spam with WP Mail Logging: Detail view of an abused e-mail&#8221; \/][\/et_pb_column][et_pb_column type=&#8221;1_3&#8243;][et_pb_text _builder_version=&#8221;3.12.2&#8243;] [card title=\"WP Mail Logging\" text=\"text-darken-3 grey\" title_color=\"blue\"]\nThe plugin WP Mail Logging by Christian Z\u00f6ller can be downloaded free of charge from the WordPress Repository. It logs e-mails sent by WordPress. This allows you to analyze the causes of unwanted emails sent by WordPress. Installation and configuration are a matter of a few seconds. We used the plugin reliably and quickly achieved the desired result.<br \/>\n[\/card]\n<script type=\"application\/ld+json\">\n{\n  \"@context\": \"http:\/\/schema.org\/\",\n  \"@type\": \"Review\",\n  \"itemReviewed: {\n    \"@type\": \"Thing\",\n    \"name\": \"WP Mail Logging (WordPress Plugin)\"\n  },\n  \"author\": {\n    \"@type\": \"Person\",\n    \"name\": \"Bernhard Jodeleit\"\n  },\n  \"datePublished\": \"2018-09-05\",\n  \"reviewRating: {\n    \"@type\": \"Rating\",\n    \"description\": \"The plugin by Christian Z\u00f6ller can be downloaded for free from the WordPress Repository. It logs e-mails sent by WordPress. In this way, the causes of unwanted emails sent by WordPress can be analyzed. Installation and configuration are a matter of a few seconds. We used the plugin reliably and quickly achieved the desired result\",\n    \"ratingValue\": \"5\"\n  }\n}\n<\/script> [\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]\n","protected":false},"excerpt":{"rendered":"<p>A misconfigured contact form can become a spam catapult and damage your email reputation. A real-world case with hints on how to analyze and fix the problem.<\/p>\n","protected":false},"author":1,"featured_media":148814,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[537,606],"tags":[630,632],"class_list":["post-148875","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business-webhosting-en","category-new","tag-e-mail","tag-email"],"_links":{"self":[{"href":"https:\/\/www.lotsofways.de\/en\/wp-json\/wp\/v2\/posts\/148875","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lotsofways.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lotsofways.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lotsofways.de\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lotsofways.de\/en\/wp-json\/wp\/v2\/comments?post=148875"}],"version-history":[{"count":0,"href":"https:\/\/www.lotsofways.de\/en\/wp-json\/wp\/v2\/posts\/148875\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lotsofways.de\/en\/wp-json\/wp\/v2\/media\/148814"}],"wp:attachment":[{"href":"https:\/\/www.lotsofways.de\/en\/wp-json\/wp\/v2\/media?parent=148875"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lotsofways.de\/en\/wp-json\/wp\/v2\/categories?post=148875"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lotsofways.de\/en\/wp-json\/wp\/v2\/tags?post=148875"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}