Start by checking for signs of real account access
Look for unknown messages in Sent, unfamiliar forwarding rules, password-change notices, unexpected login alerts or a BadMailFrom restriction. If any appear, treat the mailbox as compromised immediately.
Forged sender
What email spoofing means
A sender can place another address in a message's visible From field, much like writing somebody else's return address on an envelope. Delivery failures and replies may then come back to you even though the message never passed through your mailbox or UKC server.
- The message is absent from your Sent folder and other devices.
- There are no unknown rules, aliases or forwards on the account.
- The full headers show an unrelated sending server.
- No unusual login or outgoing-mail activity is visible.
These signs make spoofing more likely, but a missing Sent copy alone is not conclusive because malicious software may send without saving one.
Account compromise
Signs the mailbox may have been accessed
- Unknown messages, deletions, folders, rules or forwarding destinations.
- Your password unexpectedly stops working or login details change.
- Recipients receive messages that were authenticated by your UKC mailbox.
- Outgoing-mail protection reports suspicious or excessive sending.
Immediate response
Secure the mailbox if compromise is possible
- Change the mailbox password in Plesk to a new, unique password.
- Update the password only on authorised phones, computers and websites.
- Remove unknown mail rules, forwarding addresses, aliases and connected applications.
- Scan devices for malware and update website software that sends through the account.
- Warn affected contacts not to open unexpected links or attachments.
Domain protection
SPF, DKIM and DMARC help recipients reject forgeries
These DNS-based controls tell receiving providers which systems may send for your domain, add a verifiable signature and specify how authentication failures should be handled. They reduce successful impersonation but cannot stop somebody from typing your address into a forged From field.
Before changing mail-related DNS, confirm every legitimate sender such as UKC hosting, a newsletter platform, accounting software or a website form so valid messages are not rejected.
Need help deciding between spoofing and compromise?
Attach the suspicious message as an email file or provide its complete headers, plus the date, time and what you observed in Sent, rules and login activity. Screenshots of the visible From address alone are not enough. Never send the mailbox password.
Ask the Email team