The short answer
A website that sends spam on its own has almost certainly been compromised. Attackers plant a malicious script that quietly uses your site's PHP mail function to blast spam, which is why the messages come from your domain without you touching them. This is a hack, not a glitch, and it needs cleanup fast before your domain gets blacklisted.
Key takeaways
- Spam sent from your site means an attacker is using your server, not that your email account was guessed.
- The usual method is a malicious PHP script that abuses the site's built-in mail function to send in bulk.
- The real damage is reputation: your domain and server IP get blacklisted, so even your legitimate email stops arriving.
- Outdated plugins, themes, or an unprotected contact form are the common entry points.
- Cleanup means finding and removing the injected code, closing the hole, and requesting removal from blacklists.
Let's be direct: if your website is sending spam emails you never wrote, it's been hacked. This isn't a setting you misconfigured or a bug in your form. Someone got in and planted code that uses your site to send junk mail, and it needs to come out. Here's what's actually going on and what to do about it.
| Cause | How common | The tell |
|---|---|---|
| Injected malicious PHP mailer script | Very common | Bounce-back messages you didn't send. Host warns of high outbound mail volume. |
| Vulnerable or hijacked contact form | Common | Spam relayed through a form with no spam protection or a mail-header exploit. |
| Compromised email account or password | Less common | Spam sent through your actual mailbox after a leaked or guessed password. |
| Outdated plugin or theme with a known hole | Common (the entry point) | Attacker used a known vulnerability to upload the mailer in the first place. |
What's actually happening on your server
Most sites run on PHP, and PHP has a built-in mail function. That function is what legitimately sends your contact form notifications and password resets. When an attacker gets a file onto your server, they drop in a small script that calls that same function in a loop, sending thousands of spam messages that all appear to come from your domain.
You didn't do anything, and you often can't see it, because the script hides in a folder you never open. The first sign is usually a flood of bounce-back messages for emails you never sent, or a note from your hosting company saying your account is sending too much mail.
Confirm it's your site, then stop the bleeding
Ask your host to check your outbound mail logs. A spike of outgoing messages you didn't send confirms the site is the source. While you sort out the cleanup, ask them to pause outbound mail from your account or take the site offline temporarily. That stops the spam immediately and protects your reputation while you work.
Find and remove the injected code
Cleanup means locating the malicious files and deleting them, then hunting for any others the attacker left as a backdoor. On WordPress, a reputable security plugin can scan for known malware, and comparing your files against clean copies of WordPress core, your theme, and your plugins reveals anything that doesn't belong. Recently modified files in odd locations are a common giveaway.
This is fiddly, and if you miss a single backdoor the spam comes right back a week later. If you have a clean backup from before the compromise, restoring it and then immediately patching the hole is often faster and safer than picking through files by hand. Our overview of how to tell if your website has been hacked covers the other signs worth checking while you're in there.
Close the door so it doesn't happen again
Removing the script isn't the end. The attacker got in somehow, and if you don't close that path they'll be back. Update WordPress core, every plugin, and your theme to current versions, since an outdated one is the usual entry point. Change all admin and hosting passwords. Add spam protection to your contact forms. Then ask the major blacklist services to re-review your domain now that the source is gone.
How we handle this for clients
When a client's site starts spewing spam, we take it offline, find and remove the injected code and any backdoors, patch whatever let the attacker in, and work through delisting the domain. Then we keep it from recurring. Our maintenance plans start at $99 a month and keep plugins and core patched, which closes the exact holes these mailers exploit.
We're a Seattle-area studio in Mill Creek, Washington, and we handle cleanups for clients across the Puget Sound and remotely nationwide. If your site is sending mail you didn't write, call us at (425) 314-1415 and we'll help you shut it down.
Related services
More website answers
Every question in this series, from Website Problems, Solved.
Symptoms & emergencies19
- Why Is My Website Down? How to Find Out and Fix It
- Why Does My Website Say "Account Suspended"?
- Error Establishing a Database Connection: What It Means
- Why Is My Contact Form Not Sending Emails?
- White Screen of Death on WordPress: What to Do Now
- Why Is My Website Showing "Not Secure" in Chrome?
- Squarespace Site Not Showing Up on Google? Here's Why
- Why Did Google Remove My Website From Search Results?
- Why Did My Website Traffic Suddenly Drop? Top Causes
- Why Is My Website Sending Spam Emails? What It Means (you are here)
- Why Is My Website Slow on Mobile but Fast on Desktop?
- Why Does My Website Look Broken on My Phone?
- Why Do My Website Images Look Blurry or Broken?
- How to Tell If Your Website Has Been Hacked: 9 Signs
- "This Site May Be Hacked": How to Remove Google's Warning
- "Deceptive Site Ahead" Warning: How to Fix It Fast
- How to Make Your Website Load Faster
- Why Isn't My Business Showing Up on Google?
- 10 Signs Your Business Website Needs a Redesign
What happens if...9
- What Happens If You Don't Update WordPress Plugins?
- What Happens If Your SSL Certificate Expires?
- What Happens If Your Domain Name Expires? A Timeline
- What Happens If Your Web Host Goes Out of Business?
- What Happens If You Stop Paying Your Web Developer?
- Can an Old Website Hurt Your Google Ranking?
- Is an Outdated Website a Liability for Your Business?
- Why Are My Business Emails Going to Spam?
- What Happens If You Don't Maintain Your Website?
Cost & pricing7
- How Much Does It Cost to Fix a Hacked WordPress Site?
- Why Is Website Maintenance So Expensive? A Breakdown
- Hourly Rate vs. Monthly Retainer for Website Updates
- How Much Do Freelancers Charge for Website Maintenance?
- How Much Does WordPress Maintenance Cost Per Month?
- How Much Does Squarespace Maintenance Cost?
- How Much Does Website Maintenance Cost?
Plans & hiring10
- Do I Need a Website Maintenance Plan? An Honest Answer
- Maintenance Plan vs. Pay As You Go: Which Actually Wins
- One-Time Website Fix vs. Ongoing Care: Which Do You Need
- Does a Simple Website Need a Maintenance Plan?
- 12 Questions to Ask a Website Maintenance Company
- Freelancer vs. Agency for Website Maintenance
- What to Look For in a Website Maintenance Contract
- Is Your Website Maintenance Plan a Scam? How to Tell
- Website Maintenance Checklist for Non-Technical Owners
- What Does Website Maintenance Include? (And Why It Matters)
Ownership & switching9
- What Is My Website Built With? How to Check in Seconds
- How to Find Out Who Hosts and Manages Your Website
- Your Web Developer Disappeared: What to Do Now
- How to Switch Web Hosting Without Losing Your Email
- How to Fire Your Web Developer (Without Losing Your Site)
- Can You Maintain Your Own Website Without Coding?
- How Often Should You Update Your Website Content?
- How to Back Up a WordPress Site Yourself (Two Ways)
- Do You Really Own Your Website? How to Check Before You Hire
Platform-specific7
- Do Squarespace Sites Need Maintenance? The Honest Answer
- Do Wix Websites Need Maintenance? What Owners Should Know
- Shopify Maintenance: What Store Owners Actually Need
- WordPress Maintenance Checklist for Non-Developers
- WordPress vs. Squarespace: Which Is Easier to Maintain?
- GoDaddy Website Builder vs. WordPress for Small Business
- How to Keep Your WordPress Website Secure
The Venbit Team
Web design & SEO, Seattle
Venbit is a Seattle-area web design, SEO, and digital marketing studio. Since 2011 we've designed, built, and ranked small-business websites for clients across the Puget Sound and around the country, so the numbers and advice here come from real projects, not a content mill.