Getting Bounce Messages for Emails You Never Sent (Backscatter) Print

  • 0

The symptom

Your inbox is suddenly filling with delivery failure notices, "Mail Delivery Failed," "Undeliverable," "Returned Mail," for messages you never wrote, often addressed to people you have never heard of, sometimes in languages you don't speak. It can be a trickle or hundreds a day.

The natural fear is that your account has been hacked and is sending spam. That is one possibility, but there is a second, far more common explanation that involves no break-in at all: backscatter.

What backscatter is

Spammers forge the From address on their mail, and they harvest real addresses to forge because real addresses make their spam look more legitimate. When a spammer stamps your address onto a million messages and sends them from their own servers, every receiving server that bounces one of those messages sends its bounce notice to the forged sender: you. You receive the debris of someone else's spam run, which is where the name comes from.

Nothing on your account sent anything. Your address was written onto the envelope by a stranger, the same way anyone can write any return address on a paper letter.

First: rule out the serious possibility

Because a genuinely compromised account produces similar bounce floods, spend five minutes ruling it out before dismissing the flood as backscatter:

  1. Log in to cPanel and open Email, Track Delivery. This shows mail actually sent from your account through our server.
  2. If Track Delivery shows only your own legitimate mail, the spam did not come from your account, and you are dealing with backscatter. The bounces relate to messages that never touched our server.
  3. If Track Delivery shows a stream of messages you did not send, your account is compromised. Change your email and cPanel passwords immediately and open a support ticket, and see our article on the signs of a compromised email account for the full checklist.

How to deal with backscatter

  1. Do not click links or open attachments in the bounce messages. Some "bounces" are themselves spam or phishing dressed up as delivery notices, and the attachment supposedly containing your original message is a classic malware delivery trick.
  2. Do not reply or try to unsubscribe from them. Replies confirm your address is live and read, which increases its value to spammers.
  3. Delete and wait it out. Spam runs move on. Most backscatter floods fade within days as the spammer rotates to other forged addresses.
  4. If the volume is unmanageable, open a support ticket. Server-side filtering can catch a substantial portion of backscatter, and we can look at tightening it for your account while the flood lasts.

Reducing the odds long-term

  • Make sure SPF, DKIM, and DMARC are configured for your domain. These do not stop a spammer forging your address, but they let well-run receiving servers detect the forgery and quietly discard the spam instead of bouncing it back at you, which shrinks the backscatter you receive and protects your domain's reputation at the same time. See our article on SPF, DKIM, and DMARC for what these records do and how to get them checked.
  • Avoid publishing your address as plain text on your website. Harvesting bots collect addresses from web pages, a contact form exposes less than a clickable email address.
  • Keep a catch-all address switched off unless you specifically need one, a catch-all mailbox receives backscatter for every invented address at your domain, not just real ones.

Good to know

Backscatter says nothing about your security and does not mean your address was leaked from our servers. Email addresses end up on spam lists through harvested web pages, leaked third-party databases, and plain guessing of common names. The forgery is annoying and unnerving, but on its own it is harmless, the checklist above exists to confirm you are in the harmless case.


Was this answer helpful?

« Back

Powered by WHMCompleteSolution