CPGuard Email Security: Protecting Hosting Email from Spam and Phishing
CPGuard Email Security stops spam, phishing, and outbound spam relay that gets server IPs blacklisted — protecting both inbound and outbound email.
Contents
What is CPGuard Email Security?
CPGuard Email Security integrates with the hosting server mail stack to inspect both inbound and outbound email. Two primary objectives: filter spam and block phishing before it reaches user inboxes, and prevent the server from being used as a spam relay — which would result in the server IP being blacklisted and all outbound email rejected.
- Inspects both inbound and outbound email
- Spam filtering using SpamAssassin rules
- Phishing link and malware attachment detection
- Outbound scanning to prevent IP blacklisting
- ClamAV integration for virus scanning
Inbound Spam Filtering
Inbound email passes through multiple inspection layers: SPF, DKIM, and DMARC verification for the sending domain; SpamAssassin content analysis that assigns a spam score; URL checking against phishing blacklists; and ClamAV scanning of attachments.
- SPF, DKIM, DMARC verification for the sending domain
- SpamAssassin spam scoring for each message
- URLs in email body checked against phishing blacklists
- Attachments scanned by ClamAV
- Suspected email quarantined rather than silently deleted
Outbound Email Scanning
Outbound scanning is equally critical. If any account is compromised and used to send bulk spam, the server IP gets blacklisted by Spamhaus, Barracuda, Microsoft, Google, and other major email providers — causing every account on that server to have outbound email rejected. CPGuard detects accounts sending unusual volumes and suspends their outbound sending before the server IP is blocked.
- Monitors outbound email send rate per account per hour
- Automatically suspends accounts exceeding thresholds
- Alerts administrators when spam-like behaviour is detected
- Prevents IP blacklisting before it happens
Phishing Protection
Phishing emails trick recipients into clicking fake links impersonating banking sites, cloud services, or popular online platforms. CPGuard checks every URL in the email body against a continuously updated phishing database, and analyses email header characteristics to detect domain spoofing that impersonates trusted domains.
- URL scanning against phishing database
- Domain spoofing detection in From headers
- Blocks emails using look-alike domains (paypa1.com instead of paypal.com)
- Basic Business Email Compromise (BEC) protection
SPF, DKIM, DMARC Integration
CPGuard enforces the standard email authentication protocols: SPF identifies which servers may legitimately send email for a domain; DKIM signs email to verify it was not tampered with in transit; DMARC sets the policy for email that fails SPF or DKIM. Correct configuration of these records also helps outbound email avoid spam classification.
- Verifies SPF records for sending server authorisation
- Validates DKIM signatures in email headers
- Enforces DMARC policy (quarantine/reject)
- Provides DMARC aggregate reporting to domain owners
Email Attachment Scanning
Email attachments remain the most common malware delivery vector — PDFs with exploits, Excel macros executing PowerShell, executables disguised as documents. CPGuard uses ClamAV to scan every attachment before delivery, detecting known malware and blocking dangerous file types that should never be delivered via email.
- Scans every attachment using ClamAV
- Blocks dangerous file types: .exe, .bat, .vbs, .ps1
- Basic macro detection in Office files
- Quarantines email containing dangerous attachments
Configuring Email Security in DirectAdmin
On DirectAdmin-based hosting, server administrators access CPGuard Email Security settings directly through the control panel without SSH. End users typically do not need to configure anything — providers set sensible defaults — but may be able to adjust spam sensitivity for their own mailboxes if the provider enables this.
- Admins manage email security via DirectAdmin dashboard
- Spam score threshold configurable per domain
- Whitelist specific domains or addresses to bypass filtering
- Spam log available for troubleshooting missing email
Hosting with Server-Level Email Security
Server-level email security provides broader protection than client-side spam filters alone. Always ask what spam filtering and phishing protection your provider includes. AsiaGB.com provides hosting with server-level security, SSD storage, DirectAdmin, 24-hour Thai support, and 99% uptime.
- Server-level email security is more comprehensive than client-side filtering
- Outbound scanning protection is as important as inbound
- Ask your provider whether outbound spam protection is active