Skip to content

Configure automatic outbound spam limits

Outbound limits help stop excessive mail from compromised mailboxes and websites. The sending block remains until an administrator removes it.

  1. With Spam AutoShield and outbound limits enabled, cPFence checks Rspamd’s rate-limit events for excessive sending.
  2. It adds detected senders to the outgoing-email block list. This block does not expire automatically.
  3. Email and Slack alerts use your configured notification channels. Investigate the sender before removing its block.
  1. Open Spam AutoShield → Settings and enable the master on the intended mail servers.
  2. Use Edit rate limits to open System Settings.
  3. Enable Outbound rate limits and set SMTP hourly limit and Website hourly limit.
  4. Save, check the result, and configure email or Slack notifications if alerts are required.

System Settings with Spam AutoShield, Outbound rate limits, SMTP and Website hourly limit fields, server scope and Save changes.

The controls show saved settings for this server. Check the results after saving. Select the image for full size; use browser Back to return.

Filter the policy table to Block → Outgoing email to inspect blocked senders. Resolve the unwanted sending, then follow Unblock outgoing email.

If maintenance requires a temporary pause, turn Outbound rate limits off on the intended servers and save. Re-enable it afterwards. This switch does not remove existing sender blocks.

From a root terminal on the intended mail server, enable Spam AutoShield if needed:

Terminal window
cpfence --activate-spam-autoshield

Block a sender manually:

Terminal window
cpfence --add-spam-autoshield-out-email [email protected]

After fixing the cause, remove that same block:

Terminal window
cpfence --del-spam-autoshield-out-email [email protected]

Use the actual local sending account. These commands affect this mail server, not the WebUI’s server selection. Read the result and refresh its outgoing-email list. Change compromised passwords and check the account’s devices or website before restoring delivery.

The current settings are SPAM_AUTOSHIELD_LIMITS, MAX_SMTP_MSGS_PER_HOUR and MAX_WEB_MSGS_PER_HOUR in /etc/cpfcli/config.conf. Prefer the WebUI controls above. If editing the file as root, save a copy first and apply the change with:

Terminal window
cpfence --restart

This applies configured-off shutdowns and restarts configured-on protections, so plan the interruption and check the final output. Keep the Spam AutoShield master enabled for filtering; the outbound-limit switch controls this additional protection.