---
title: How To Track Spam Being Sent Out From a Local PC on your Network
description: Here are some tips to help you track spam messages sent from within your network.
image: https://blog.mdaemon.com/hs-fs/hubfs/Stock%20images/Concept%20of%20sending%20e-mails%20from%20your%20computer.jpeg?width=999&quality=low
---

[![MDaemon Technologies](https://blog.mdaemon.com/hs-fs/hubfs/MDaemon-Technologies_logo_large.png?width=564&height=110&name=MDaemon-Technologies_logo_large.png "MDaemon Technologies")](https://mdaemon.com/)

- [Blog Home](https://blog.mdaemon.com)

# MDaemon Technologies Blog

## [How To Track Spam Being Sent Out From a Local PC on your Network](https://blog.mdaemon.com/tracking-down-a-spambot)

 By [Brad Wyro](https://blog.mdaemon.com/author/brad-wyro)

- [Tweet](https://twitter.com/share)

![Concept of sending e-mails from your computer](https://blog.mdaemon.com/hs-fs/hubfs/Stock%20images/Concept%20of%20sending%20e-mails%20from%20your%20computer.jpeg?quality=low&width=712&name=Concept%20of%20sending%20e-mails%20from%20your%20computer.jpeg)

 

Has this happened to you? Let’s say you’re the MDaemon administrator for your company, and you’ve noticed that somewhere, somehow, spam messages are being sent from within your network. Perhaps one of your PCs has been compromised. What do you do? Here are some tips to help you track the issue down.

First, make sure you have the option “Authentication is always required when mail is from local accounts” enabled (located in MDaemon Remote Administration under Security | Sender Authentication | SMTP Authentication). Also enable “Credentials used must match those of the return-path address” and "Credentials used must match those of the From header address." Then, make sure “…unless message is sent to a local account” is unchecked to prevent intra-domain spam (between local domain users).

[![MDaemon-SMTP-Authentication_WebReady](https://blog.mdaemon.com/hs-fs/hubfs/MDaemon-SMTP-Authentication_WebReady.png?width=692&height=401&name=MDaemon-SMTP-Authentication_WebReady.png)](https://blog.mdaemon.com/hubfs/Imported_Blog_Media/SMTPAuth-2.png) Make sure the appropriate boxes are checked to require SMTP authentication

 

Next, find out if the spam messages are coming in from an authenticated session. To do this, locate one of the spam messages & open it up in Notepad to view its headers (or you can open it in Queue & Statistics Manager). Does the message have an X-Authenticated-Sender header? It will look something like this:

X-Authenticated-Sender: SpammerUser@example.com

 

If this header is present, then that is the user who authenticated to send the message. The first thing you should do in this case is to change the account’s password via the Accounts menu in MDaemon. Even if the spamming is going through the user’s mail client, until you give the user the new password and they update their mail client the authentication credentials will be rejected and the spamming will be temporarily stopped.

 

In newer versions of MDaemon, we've added Account Hijack Detection, which will automatically disable an account if it sends a specified number of outbound messages via an authenticated session in a given period of time. We recommend enabling this feature. In MDaemon, it's located under Security | Security Settings | Screening | Hijack Detection.

[![MDaemon-Hijack-Detection_WebReady](https://blog.mdaemon.com/hs-fs/hubfs/MDaemon-Hijack-Detection_WebReady.png?width=695&height=425&name=MDaemon-Hijack-Detection_WebReady.png)](https://blog.mdaemon.com/hubfs/Imported_Blog_Media/HijackDetection-2.png) Account Hijack Detection

 

The next step is to look at the Received headers. Find the one where the message was received by your server. Here is an example of what this header would look like:

Received from computer1 (computer1@example.com (192.198.1.121) by example.com (MDaemon PRO v17) with ESMTP id md50000000001.msg for <UserWhoWasSpammed@example.com >, Fri, 13 Sep 2016 21:00:00 -0800

 

Find the connecting IP (192.198.1.121) in the above example. This is the machine that is sending out spam. Locate that machine to deal directly with the spambot on that machine.

If the message wasn't authenticated or wasn't sent from your local network, locate the Message-ID header and copy that value.

Message-ID: <123.xyx.someone@example.net>

 

Then open the MDaemon SMTP-IN log that covers the time when that message was received by MDaemon (based on the timestamp in the received header) and search for that Message-ID in the log (in the 250 response line when the message is accepted):

Thu 2016-09-12 20:00:00: --> 250 Ok, message saved <Message-ID: <123.xyx.someone@example.net>>

 

Look at the rest of transaction and see why the message was accepted/not rejected - spam score, DNSBLs, etc.

Also, if your external domain is listed in the Trusted Hosts list (Security | Security Settings | Trusted Hosts), try removing it from this list.

 

Check back often for more tips & tricks!

 

 Tags: [Stop Spam Email](https://blog.mdaemon.com/topic/stop-spam-email)

![Brad Wyro](https://blog.mdaemon.com/hs-fs/hubfs/Brad-2023v2.jpg?width=100&height=100&name=Brad-2023v2.jpg)

#### Written by [Brad Wyro](https://blog.mdaemon.com/author/brad-wyro)

Brad has worked in technical and marketing roles at MDaemon Technologies, where he contributes as Content Marketing Manager. Brad balances technical and creative information to develop easy to understand videos and content to educate prospects and customers.

[![BACK TO ALL ARTICLES](https://hubspot-no-cache-na2-prod.s3.amazonaws.com/cta/default/6572702/05b24dbb-70a6-4eaa-9507-321cb27f7228.png)](https://hubspot-cta-redirect-na2-prod.s3.amazonaws.com/cta/redirect/6572702/05b24dbb-70a6-4eaa-9507-321cb27f7228)

### Subscribe to Email Updates

- [Popular](https://blog.mdaemon.com/tracking-down-a-spambot#tab-2)
- [Recent](https://blog.mdaemon.com/tracking-down-a-spambot#tab-1)
- [Categories](https://blog.mdaemon.com/tracking-down-a-spambot#tab-3)

### Lists by Topic

- [Email Security (73)](https://blog.mdaemon.com/tag/email-security)
- [MDaemon Email Server (45)](https://blog.mdaemon.com/tag/mdaemon-email-server)
- [Email How To (37)](https://blog.mdaemon.com/tag/email-how-to)
- [Email Best Practices (29)](https://blog.mdaemon.com/tag/email-best-practices)
- [Phishing (28)](https://blog.mdaemon.com/tag/phishing)
- [Product Updates (28)](https://blog.mdaemon.com/tag/product-updates)
- [Security Gateway for Email (27)](https://blog.mdaemon.com/tag/security-gateway-for-email)
- [Stop Spam Email (25)](https://blog.mdaemon.com/tag/stop-spam-email)
- [Cybersecurity (24)](https://blog.mdaemon.com/tag/cybersecurity)
- [Email Security Best Practices (23)](https://blog.mdaemon.com/tag/email-security-best-practices)
- [Email Server (22)](https://blog.mdaemon.com/tag/email-server)
- [Two-Factor Authentication (18)](https://blog.mdaemon.com/tag/two-factor-authentication)
- [Email Gateway How-To (17)](https://blog.mdaemon.com/tag/email-gateway-how-to)
- [Email Security Trends (15)](https://blog.mdaemon.com/tag/email-security-trends)
- [SecurityGateway (13)](https://blog.mdaemon.com/tag/securitygateway)
- [Health Care Security (12)](https://blog.mdaemon.com/tag/health-care-security)
- [Spear Phishing (12)](https://blog.mdaemon.com/tag/spear-phishing)
- [Data Leak Prevention (11)](https://blog.mdaemon.com/tag/data-leak-prevention)
- [Email Encryption (11)](https://blog.mdaemon.com/tag/email-encryption)
- [Anti-Spoofing (10)](https://blog.mdaemon.com/tag/anti-spoofing)
- [MDaemon Webmail (10)](https://blog.mdaemon.com/tag/mdaemon-webmail)
- [Email Archiving (8)](https://blog.mdaemon.com/tag/email-archiving)
- [Email Management (8)](https://blog.mdaemon.com/tag/email-management)
- [Email Privacy (8)](https://blog.mdaemon.com/tag/email-privacy)
- [Email Spoofing (8)](https://blog.mdaemon.com/tag/email-spoofing)
- [Business Email Compromise (7)](https://blog.mdaemon.com/tag/business-email-compromise)
- [Anti-Virus (6)](https://blog.mdaemon.com/tag/anti-virus)
- [Email Software (6)](https://blog.mdaemon.com/tag/email-software)
- [Tutorial (6)](https://blog.mdaemon.com/tag/tutorial)
- [Update (6)](https://blog.mdaemon.com/tag/update)
- [Collaboration (5)](https://blog.mdaemon.com/tag/collaboration)
- [Email Authentication (5)](https://blog.mdaemon.com/tag/email-authentication)
- [Compliance (4)](https://blog.mdaemon.com/tag/compliance)
- [Email Remote Administration (4)](https://blog.mdaemon.com/tag/email-remote-administration)
- [MailStore Archive Server (4)](https://blog.mdaemon.com/tag/mailstore-archive-server)
- [Microsoft 365 Exchange Alternative (4)](https://blog.mdaemon.com/tag/microsoft-365-exchange-alternative)
- [Passwords (4)](https://blog.mdaemon.com/tag/passwords)
- [Software update (4)](https://blog.mdaemon.com/tag/software-update)
- [Archive (3)](https://blog.mdaemon.com/tag/archive)
- [Attachments (2)](https://blog.mdaemon.com/tag/attachments)
- [Business Email (2)](https://blog.mdaemon.com/tag/business-email)
- [Cloud (2)](https://blog.mdaemon.com/tag/cloud)
- [DMARC (2)](https://blog.mdaemon.com/tag/dmarc)
- [Industry Insight (2)](https://blog.mdaemon.com/tag/industry-insight)
- [MDaemon (2)](https://blog.mdaemon.com/tag/mdaemon)
- [insider threats (2)](https://blog.mdaemon.com/tag/insider-threats)
- [msp (2)](https://blog.mdaemon.com/tag/msp)
- [Anti-Relay (1)](https://blog.mdaemon.com/tag/anti-relay)
- [BEC (1)](https://blog.mdaemon.com/tag/bec)
- [Backscatter (1)](https://blog.mdaemon.com/tag/backscatter)
- [Bayesian Learning (1)](https://blog.mdaemon.com/tag/bayesian-learning)
- [Content Filter (1)](https://blog.mdaemon.com/tag/content-filter)
- [DNS-BL (1)](https://blog.mdaemon.com/tag/dns-bl)
- [Disaster Recovery (1)](https://blog.mdaemon.com/tag/disaster-recovery)
- [Email Collaboration (1)](https://blog.mdaemon.com/tag/email-collaboration)
- [Email Software Reviews (1)](https://blog.mdaemon.com/tag/email-software-reviews)
- [Encrypt (1)](https://blog.mdaemon.com/tag/encrypt)
- [External Email Threats (1)](https://blog.mdaemon.com/tag/external-email-threats)
- [Gateway (1)](https://blog.mdaemon.com/tag/gateway)
- [Inbox (1)](https://blog.mdaemon.com/tag/inbox)
- [Inbox Zero (1)](https://blog.mdaemon.com/tag/inbox-zero)
- [Macros (1)](https://blog.mdaemon.com/tag/macros)
- [Monitoring (1)](https://blog.mdaemon.com/tag/monitoring)
- [Quarantine (1)](https://blog.mdaemon.com/tag/quarantine)
- [RelayFax (1)](https://blog.mdaemon.com/tag/relayfax)
- [Software (1)](https://blog.mdaemon.com/tag/software)
- [Training (1)](https://blog.mdaemon.com/tag/training)
- [Troubleshooting (1)](https://blog.mdaemon.com/tag/troubleshooting)
- [Upgrade (1)](https://blog.mdaemon.com/tag/upgrade)
- [Web Conferencing (1)](https://blog.mdaemon.com/tag/web-conferencing)
- [Windows Server (1)](https://blog.mdaemon.com/tag/windows-server)
- [internal email threat (1)](https://blog.mdaemon.com/tag/internal-email-threat)
- [ssl (1)](https://blog.mdaemon.com/tag/ssl)
- [tax scams (1)](https://blog.mdaemon.com/tag/tax-scams)

see all

### Posts by Topic

- [Email Security (73)](https://blog.mdaemon.com/tag/email-security)
- [MDaemon Email Server (45)](https://blog.mdaemon.com/tag/mdaemon-email-server)
- [Email How To (37)](https://blog.mdaemon.com/tag/email-how-to)
- [Email Best Practices (29)](https://blog.mdaemon.com/tag/email-best-practices)
- [Phishing (28)](https://blog.mdaemon.com/tag/phishing)
- [Product Updates (28)](https://blog.mdaemon.com/tag/product-updates)
- [Security Gateway for Email (27)](https://blog.mdaemon.com/tag/security-gateway-for-email)
- [Stop Spam Email (25)](https://blog.mdaemon.com/tag/stop-spam-email)
- [Cybersecurity (24)](https://blog.mdaemon.com/tag/cybersecurity)
- [Email Security Best Practices (23)](https://blog.mdaemon.com/tag/email-security-best-practices)
- [Email Server (22)](https://blog.mdaemon.com/tag/email-server)
- [Two-Factor Authentication (18)](https://blog.mdaemon.com/tag/two-factor-authentication)
- [Email Gateway How-To (17)](https://blog.mdaemon.com/tag/email-gateway-how-to)
- [Email Security Trends (15)](https://blog.mdaemon.com/tag/email-security-trends)
- [SecurityGateway (13)](https://blog.mdaemon.com/tag/securitygateway)
- [Health Care Security (12)](https://blog.mdaemon.com/tag/health-care-security)
- [Spear Phishing (12)](https://blog.mdaemon.com/tag/spear-phishing)
- [Data Leak Prevention (11)](https://blog.mdaemon.com/tag/data-leak-prevention)
- [Email Encryption (11)](https://blog.mdaemon.com/tag/email-encryption)
- [Anti-Spoofing (10)](https://blog.mdaemon.com/tag/anti-spoofing)
- [MDaemon Webmail (10)](https://blog.mdaemon.com/tag/mdaemon-webmail)
- [Email Archiving (8)](https://blog.mdaemon.com/tag/email-archiving)
- [Email Management (8)](https://blog.mdaemon.com/tag/email-management)
- [Email Privacy (8)](https://blog.mdaemon.com/tag/email-privacy)
- [Email Spoofing (8)](https://blog.mdaemon.com/tag/email-spoofing)
- [Business Email Compromise (7)](https://blog.mdaemon.com/tag/business-email-compromise)
- [Anti-Virus (6)](https://blog.mdaemon.com/tag/anti-virus)
- [Email Software (6)](https://blog.mdaemon.com/tag/email-software)
- [Tutorial (6)](https://blog.mdaemon.com/tag/tutorial)
- [Update (6)](https://blog.mdaemon.com/tag/update)
- [Collaboration (5)](https://blog.mdaemon.com/tag/collaboration)
- [Email Authentication (5)](https://blog.mdaemon.com/tag/email-authentication)
- [Compliance (4)](https://blog.mdaemon.com/tag/compliance)
- [Email Remote Administration (4)](https://blog.mdaemon.com/tag/email-remote-administration)
- [MailStore Archive Server (4)](https://blog.mdaemon.com/tag/mailstore-archive-server)
- [Microsoft 365 Exchange Alternative (4)](https://blog.mdaemon.com/tag/microsoft-365-exchange-alternative)
- [Passwords (4)](https://blog.mdaemon.com/tag/passwords)
- [Software update (4)](https://blog.mdaemon.com/tag/software-update)
- [Archive (3)](https://blog.mdaemon.com/tag/archive)
- [Attachments (2)](https://blog.mdaemon.com/tag/attachments)
- [Business Email (2)](https://blog.mdaemon.com/tag/business-email)
- [Cloud (2)](https://blog.mdaemon.com/tag/cloud)
- [DMARC (2)](https://blog.mdaemon.com/tag/dmarc)
- [Industry Insight (2)](https://blog.mdaemon.com/tag/industry-insight)
- [MDaemon (2)](https://blog.mdaemon.com/tag/mdaemon)
- [insider threats (2)](https://blog.mdaemon.com/tag/insider-threats)
- [msp (2)](https://blog.mdaemon.com/tag/msp)
- [Anti-Relay (1)](https://blog.mdaemon.com/tag/anti-relay)
- [BEC (1)](https://blog.mdaemon.com/tag/bec)
- [Backscatter (1)](https://blog.mdaemon.com/tag/backscatter)
- [Bayesian Learning (1)](https://blog.mdaemon.com/tag/bayesian-learning)
- [Content Filter (1)](https://blog.mdaemon.com/tag/content-filter)
- [DNS-BL (1)](https://blog.mdaemon.com/tag/dns-bl)
- [Disaster Recovery (1)](https://blog.mdaemon.com/tag/disaster-recovery)
- [Email Collaboration (1)](https://blog.mdaemon.com/tag/email-collaboration)
- [Email Software Reviews (1)](https://blog.mdaemon.com/tag/email-software-reviews)
- [Encrypt (1)](https://blog.mdaemon.com/tag/encrypt)
- [External Email Threats (1)](https://blog.mdaemon.com/tag/external-email-threats)
- [Gateway (1)](https://blog.mdaemon.com/tag/gateway)
- [Inbox (1)](https://blog.mdaemon.com/tag/inbox)
- [Inbox Zero (1)](https://blog.mdaemon.com/tag/inbox-zero)
- [Macros (1)](https://blog.mdaemon.com/tag/macros)
- [Monitoring (1)](https://blog.mdaemon.com/tag/monitoring)
- [Quarantine (1)](https://blog.mdaemon.com/tag/quarantine)
- [RelayFax (1)](https://blog.mdaemon.com/tag/relayfax)
- [Software (1)](https://blog.mdaemon.com/tag/software)
- [Training (1)](https://blog.mdaemon.com/tag/training)
- [Troubleshooting (1)](https://blog.mdaemon.com/tag/troubleshooting)
- [Upgrade (1)](https://blog.mdaemon.com/tag/upgrade)
- [Web Conferencing (1)](https://blog.mdaemon.com/tag/web-conferencing)
- [Windows Server (1)](https://blog.mdaemon.com/tag/windows-server)
- [internal email threat (1)](https://blog.mdaemon.com/tag/internal-email-threat)
- [ssl (1)](https://blog.mdaemon.com/tag/ssl)
- [tax scams (1)](https://blog.mdaemon.com/tag/tax-scams)

See all

#### About MDaemon Technologies

MDaemon Technologies is a pioneer in developing email and email security software helping to protect customers from evolving cyber-security threats. Its products and services are trusted by thousands of organizations in over 140 countries. For more than two decades, the company’s products have been developed with the ongoing input of IT professionals who demand reliable, affordable software that requires minimal effort to manage.

The software can be deployed in virtual, hosted cloud, on-premises, or hybrid network environments. The company sells its software and services directly and through a network of global channel partners.

For more information, visit [www.mdaemon.com](https://www.altn.com/).

Copyright © 1996-2026 MDaemon Technologies.  View [privacy policy](https://mdaemon.com/policies/privacy-policy).

 

###### Contact Us

 +1.817-601-3222

[sales@help.mdaemon.com](mailto:sales@help.mdaemon.com)

 6340 Lake Worth Blvd.  
 Fort Worth, TX 76135

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Brad Wyro",
    "url" : "https://blog.mdaemon.com/author/brad-wyro"
  },
  "dateModified" : "2025-10-28T18:55:11.875Z",
  "datePublished" : "2017-06-22T14:52:03.000Z",
  "headline" : "How To Track Spam Being Sent Out From a Local PC on your Network",
  "image" : [ "https://blog.mdaemon.com/hs-fs/hubfs/Stock%20images/Concept%20of%20sending%20e-mails%20from%20your%20computer.jpeg?width=999&quality=low" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.mdaemon.com/tracking-down-a-spambot",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.mdaemon.com/hubfs/MDaemon-Technologies_logo_large.png"
    },
    "name" : "MDaemon Technologies"
  }
}
```