• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Question suspicious email address automatically created in plesk panel

skrdknd

New Pleskian
Server operating system version
CentOS 7
Plesk version and microupdate number
18.0.55
I have Plesk installed on my dedicated server and a couple of client accounts. Five suspect email addresses were recently generated automatically in one of the customers. [email protected] is the email address.

Why was this email produced, and how can it be avoided?

Can somebody give me some tips on how to avoid it?
 
They could have been created by a script through API. They could have also been created by an extension, although I am not aware of extensions that do this. It is also possible that - if a subscription allows root access - a script in the subscription itself runs a Plesk command on the server to create the mailboxes. Finally, it is thinkable that a hacker gained access to the account by stealing username and password and simply created the mailboxes manually. That can be avoided by using the Google Authenticator 2FA extension to protect account access.
 
If you install the Action Log extension, you can monitor who or what creates a mail account (amongst others):
 
Back
Top