Email Spam Spanish version

Support article

Microsoft Detects Spam Sent from Your Domain: What to Do

What to do if Microsoft detects spam sent from your domain or hosting service. Check compromised accounts, SPF, DKIM, PTR and website security.

Published: 26/08/2026 Updated: 26/08/2026

What this alert means

If you have received a notice saying that messages Microsoft considers spam are being sent from your domain, an email account or your server’s IP address, it is important to investigate as soon as possible.

Microsoft monitors email delivered to services such as Outlook.com, Hotmail and other Microsoft mailboxes. When it detects a high percentage of messages being marked as unwanted, it can affect the reputation of the IP address or domain used to send them.

These notices usually include details such as:

  • The IP address from which the messages were sent.
  • The domain related to the sending activity.
  • The percentage of messages that Microsoft users marked as spam.
  • Recommendations for correcting the problem.

This does not necessarily mean that you intentionally sent spam. In many cases, the source is a compromised email account, an infected website or a form or application sending messages without authorization.

Why this may be happening

The most common causes are the following:

An email account has been compromised

If an email account password has been stolen, a third party may use it to send large volumes of messages.

This can happen because of:

  • Weak or reused passwords.
  • Computers infected with malware.
  • Passwords saved in compromised programs or devices.
  • Phishing.
  • Credential leaks from other services.

A website is infected or has been hacked

A WordPress, PrestaShop or other CMS installation may be used to send email if it contains:

  • Vulnerable plugins or modules.
  • Outdated themes or extensions.
  • Malicious files.
  • Backdoors installed after an intrusion.
  • Insecure forms.

In these cases, the email may be sent directly by the website without necessarily using a regular email account.

A form is being used to send spam

A poorly protected contact form can be exploited by bots to send messages in bulk.

Pay particular attention to:

  • Contact forms.
  • Registration forms.
  • Password recovery systems.
  • Custom-built forms.

You are sending legitimate messages, but recipients consider them spam

The messages may also be legitimate while Microsoft detects a high number of recipient complaints.

This often happens with:

  • Newsletters sent to contacts who do not remember subscribing.
  • Old databases.
  • Purchased contact lists or lists collected without consent.
  • Messages sent without a clear unsubscribe option.
  • Frequent sends to users who do not interact with the messages.

How to fix it

1. Check whether you recognize the sending activity

First, confirm whether you or someone authorized has recently run campaigns, newsletters or bulk email sends.

If you recognize the messages, check that the recipients expressly agreed to receive them.

It is best to use a confirmed subscription system, also known as confirmed opt-in or double opt-in.

All commercial messages and newsletters should also include a simple, visible way to unsubscribe.

If you do not recognize the sending activity, treat the case as a possible security incident.

2. Change the passwords for your email accounts

If there is any possibility that an account has been compromised, change its password immediately.

Use a password that is:

  • Long.
  • Unique.
  • Different from the one used on other services.
  • Difficult to guess.

Do not reuse the previous password.

You should also change the credentials saved in email programs, mobile phones, tablets and other devices that use the account.

3. Review the domain’s email accounts

Check whether there are accounts that are no longer used or that you do not recognize.

If you find unnecessary accounts, delete them or change their passwords.

It is also worth checking whether any account is generating an unusually high sending volume.

4. Review your website’s security

If you use WordPress, PrestaShop or another CMS:

  1. Update the CMS.
  2. Update plugins, modules and themes.
  3. Remove extensions you do not use.
  4. Check for unknown administrator users.
  5. Change administration passwords.
  6. Check the website files for suspicious changes.

A compromised website may continue sending spam even after you change email passwords, so it is important to review both areas.

5. Protect your website forms

If you have public forms, make sure they include measures to prevent automated abuse.

Depending on the application, you can add:

  • CAPTCHA.
  • Sending limits.
  • Additional validation.
  • Bot protection.
  • Security plugins or modules.

6. Check SPF and DKIM

SPF and DKIM records help email providers verify that messages sent using your domain are legitimate.

SPF

SPF specifies which servers are authorized to send email using your domain.

DKIM

DKIM adds a cryptographic signature to messages to show that they came from an authorized server and were not modified during delivery.

If you use the email service included with your hosting, check that these records are correctly configured in the domain’s DNS zone.

Important: do not copy SPF or DKIM records from other domains. Each configuration may be different.

7. Check the IP address PTR record

The PTR record, also known as reverse DNS, links an IP address to a server name.

Microsoft recommends that mail-sending servers have a valid PTR record.

With shared hosting, VPS or dedicated servers, PTR management may depend on how the service is configured.

If you are not sure whether the IP address used to send email has a correct PTR record, ask support to check it.

8. Stop all bulk sending until the problem is solved

If you find a compromised account, an infected website or sending activity that is generating complaints, temporarily stop the sends.

Continuing to send email while the problem exists can damage the reputation of the domain or IP address further.

If the emails are legitimate

If you use your domain for newsletters, commercial communications or email campaigns, review these best practices:

  • Send only to users who asked to receive your messages.
  • Use confirmed subscription whenever possible.
  • Do not use purchased databases.
  • Do not send to addresses obtained without consent.
  • Always include a clear unsubscribe link or mechanism.
  • Remove addresses that repeatedly bounce from your lists.
  • Avoid continuing to send to users who do not interact with your messages.
  • Configure SPF and DKIM correctly.

The fact that a message is legitimate to the sender does not mean that the recipient considers it wanted.

If many users mark your messages as spam, your sending reputation may be affected.

If you do not recognize the sending activity

If you did not send the messages Microsoft detected, there may be a security incident.

In that case, we recommend that you:

  1. Change the passwords for all affected email accounts.
  2. Change the hosting panel and CMS passwords.
  3. Check the computers and devices used to access email.
  4. Update WordPress, PrestaShop or other applications.
  5. Review plugins, modules and themes.
  6. Look for suspicious files or recent changes.
  7. Review forms and scripts that may send email.
  8. Contact support if you need help identifying the source of the sending activity.

Changing only the email password may not be enough if the spam originates from a compromised website.

What can happen if the problem is not solved

If the sending continues, Microsoft or other email providers may lower the reputation of the domain or IP address used to send messages.

As a result, legitimate emails may:

  • Reach the spam folder.
  • Be rejected.
  • Take longer to be delivered.
  • Return temporary delivery errors.

For this reason, it is important to solve the source of the problem rather than only trying to stop messages from being classified as spam.

Common problems

I changed the password, but emails are still being sent

The source may not be an email account. It could be a website, form or application installed on the hosting account.

Review the website’s security as well.

Microsoft marks emails I did send as spam

Check how you obtained the recipients’ addresses and how many users are marking the messages as unwanted.

Also review SPF, DKIM, the domain’s reputation and the message content.

Do SPF and DKIM completely prevent spam?

No.

SPF and DKIM help authenticate email, but they do not prevent a legitimate compromised account from being used to send spam.

Password and website security remain essential.

Should I delete all my email accounts?

Usually not.

The important thing is to identify which account, website or application is generating the sends and correct the source of the problem.

Frequently asked questions

Why did Microsoft detect my domain?

Because one or more messages sent from an IP address related to your service reached Microsoft accounts, and some of them were considered or marked as spam.

Does this mean that my domain is on a blocklist?

Not necessarily.

An alert of this type means that Microsoft detected behavior that may affect sending reputation, but it does not automatically mean that the domain is included on a public blocklist.

Could WordPress be responsible?

Yes.

A compromised WordPress installation, a vulnerable plugin or a poorly protected form can be used to send unauthorized messages.

Could a stolen email password be responsible?

Yes.

It is one of the most common causes. If you do not recognize the sending activity, change the passwords as soon as possible.

What information should I send to support?

If you need us to review the case, include all the information available in the notice you received, especially:

  • Affected domain.
  • IP address shown in the notice.
  • Approximate date of the sends.
  • Affected email address, if known.
  • Copy of the notice received.
  • Information about campaigns or bulk sends carried out recently.

This information will make it easier to locate the source of the problem.

Conclusion

If Microsoft detects spam related to your domain, the most important thing is to determine whether the messages are legitimate or whether an account, website or application has been compromised.

If the sending is legitimate, review recipient consent, the unsubscribe process and your SPF, DKIM and PTR configuration.

If you do not recognize the messages, change the passwords, review the website’s security and stop any suspicious sending activity.

If the problem continues after these checks, contact miHosting.com support with the notice you received and all available details. We can help identify the source of the sending activity and review the service configuration.