• Debian 11 has reached its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.81 is the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Mail-Settings: Scripts are not allowed to use sendmail - but it's possible to send spam

ehrenwert

Basic Pleskian
Hello,

I configured the plesk-outgoing-mail limitation as follows: Scripts are not allowed to send mails (see: http://d.pr/i/HqdO ).

But a simple php-script with mail()-command can successfully send mails.

How can I stop that?
 
@ehrenwert,

In the php.ini file, you should check for the line "disabled_functions = <values>".

The appropriate php.ini file can be defined as a general config file (use the command "php --ini" to find the appropriate file) or a per-domain config file (go to the domain directory and try to search for the php.ini file).

Adding the value "mail" to the <values> list (i.e. resulting a line, similar to "disabled_functions = mail,<other values>") will block php code to use the mail() command.

In short, a simple adjustment to the php.ini file can stop mails, sent with the php mail() function.

As a final note, it is "good practice" to check all php.ini files in the domain directories, i.e. that the line disabled_functions is present and that it contains the value "mail".

Kind regards....
 
Back
Top