- Server operating system version
- Alma Linux 9.7
- Plesk version and microupdate number
- Obsidian 18.0.75
I have just set up the Plesk Email Security Extension and now my emails are being marked as spam - I believe - because they're being sent to remote addresses as if from localhost.
This is happening to emails from various accounts on the server . All accounts have fully valid SPF , DMARC and DKIM records. The Server IP should not be blacklisted. But the emails are coming in consistently as "SPAM", since this change over.
1) Is Plesk Email Security to blame?
2) If not; how to fix this and set emails going externally to be coming from the correct domain name?
Received email header in full:

See the lines:
And
Which look dodgy that it's appearing to send from localhost. rather than the sending domain ,
This is happening to emails from various accounts on the server . All accounts have fully valid SPF , DMARC and DKIM records. The Server IP should not be blacklisted. But the emails are coming in consistently as "SPAM", since this change over.
1) Is Plesk Email Security to blame?
2) If not; how to fix this and set emails going externally to be coming from the correct domain name?
Received email header in full:

See the lines:
spf=pass (sender IP is 127.0.0.1) smtp.mailfrom=[email protected] smtp.helo=plesk-server-address.co.uk
And
Received-SPF: pass (plesk-server-address.co.uk: localhost is always allowed.) client-ip=127.0.0.1; envelope-from=[email protected]; helo=plesk-server-address.co.uk;
X-Spam-Level:
Authentication-Results: plesk-server-address.co.uk (amavis); dkim=pass (2048-bit key) header.d=plesk-server-address.co.uk
Received: from plesk-server-address.co.uk ([127.0.0.1]) by plesk-server-address.co.uk (plesk-server-address.co.uk [127.0.0.1]) (amavis, port 10024) with ESMTP id K0tr2xyzfWGU for <[email protected]>; Mon, 2 Feb 2026 16:12:17 +0000 (UTC) Received: from [90.158.223.116] (unknown [185.248.15.80])
by plesk-server-address.co.uk (Postfix) with ESMTPSA id 200185200014D for <[email protected]>; Mon, 2 Feb 2026 16:12:17 +0000 (UTC)
Which look dodgy that it's appearing to send from localhost. rather than the sending domain ,