2 weeks ago, my website has been hacked by sending spoof email. every seconds there is auth log that saying some one is trying to log in.
and my email activity spike up. and the result, my mail transaction account has been suspended.
so i destroy droplet and rebuild one, which get different ip. it look fine for 2 weeks. but just yesterday, it happend again. all my mail transaction spike up. and has been suspended. its similar attack.
can anyone help me? what should I do…
These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.
Click below to sign up and get $100 of credit to try our products over 60 days!
Hello,
There are a few things that I could suggest:
Scan your local devices with a couple of antivirus programs to make sure that there is no malware
On your servers, make sure to use strong email passwords so that they could not be easily brute-forced
If you have any other software like Apache, PHP, Wordpress - make sure that it is up to date, or even better move it on a separate droplet so that it does not affect your email server directly
Close down any ports that are not supposed to be accessed by everyone
Disable SSH password authentication and use only SSH keys
Make sure that you’ve installed the latest patches on your system
Regards, Bobby