A hosting abuse warning or suspension notice requires a prompt, documented response. Preserve evidence first. Then contain the affected website or mailbox, secure access, investigate the cause, and record each repair. A clear remediation report gives mybox the information needed to review the incident and consider reinstatement.
Table of Contents
1. Record the warning and start an incident timeline
Save the full abuse notification, including the affected service, stated reason, requested action, and any deadline. Do not delete the message after taking action. Create a simple timeline with the time you received the warning and the time of each investigation, containment, credential reset, cleanup, and test.
Note the symptoms that led to the warning. Common signs of a compromised website include unexpected redirects, browser security warnings, unusual files on the server, spam sent from the account, and alerts from search engines or security tools. These signs are described in mybox’s SSH investigation and cleanup article.
2. Preserve evidence before removing anything
Preserve the available logs, suspicious files, warning messages, and relevant account information before deleting or replacing files. Keep original copies in a separate location when possible. Record file names, paths, timestamps, and the reason each item appears suspicious.
Web server and mail logs can help identify script execution errors, incorrect server responses, PHP mail() problems, and failed or blocked email sending. They are also useful when checking whether the incident affected the website, mail service, or both. See mybox’s article about web server and mail logs.
Do not rely only on screenshots. Keep the original notification and the relevant log extracts together with your timeline. This makes it easier to connect the provider’s warning with the actions taken.
3. Contain the affected services
Identify whether the warning concerns the website, a mailbox, the hosting account, or more than one service. Limit activity from the affected service while you investigate. For example, separate the affected website or mailbox from unaffected services in your incident notes and avoid treating the entire account as clean until the review is complete.
Containment should reduce further abuse while preserving evidence. Record what was isolated, when it was isolated, and what remained available. If the warning concerns spam, preserve mail-related evidence before clearing messages or changing mail settings. If it concerns website activity, preserve suspicious files and web server logs before cleanup.
4. Reset credentials and review access
Reset the credentials connected to the affected service. Include website, hosting, mailbox, and other relevant account credentials in the review. Record which credentials were changed and when.
A password reset is an important response, but it is not a complete cleanup. Known credentials may be reused, while malicious files, backdoors, unauthorized users, or other changes inside the website may remain. This causal distinction is covered in mybox’s article about why changing passwords is not enough after a hack.
5. Investigate the cause and remove persistence
Compare the current website and service state with the expected state. Review unusual files, unexpected redirects, unauthorized users, and changes that could allow the activity to continue. For a website, SSH access can support investigation and cleanup when SSH is available. The relevant procedure is described in mybox’s SSH investigation and cleanup article.
Do not treat the first suspicious file as the complete cause. Check whether other files, backdoors, users, or website changes remain. For mailbox abuse, review the mail evidence and sending-related errors in the available mail logs. For website abuse, compare the reported activity with web server logs and the files found during the review.
6. Document proof of cleanup
Keep a remediation record that answers these points:
- Which service was affected.
- What symptoms or warning were observed.
- Which files, users, messages, or settings were reviewed.
- Which suspicious items or unauthorized changes were removed.
- Which credentials were reset.
- When containment and cleanup took place.
- What checks were completed after cleanup.
- Whether website redirects, browser warnings, unusual files, spam, or service errors remained after the work.
Attach relevant evidence, such as the provider warning, log extracts, file paths, and before-and-after notes. Keep the record factual and separate confirmed findings from actions that are still in progress.
7. Prepare a safe reinstatement request
Send the host a concise response that identifies the affected service and refers to the original warning. Include the incident timeline, the evidence preserved, the containment steps, the credential resets, the suspected root cause, and the cleanup completed.
State what you checked after remediation and include the evidence that supports those checks. If part of the review is still in progress, say which part and what action is underway. Ask the host to review the remediation and advise whether the service can be reinstated.
Keep the request focused on the reported abuse. Do not send unrelated account information or credentials in the appeal. Continue preserving the incident record and respond to any follow-up from mybox with the relevant evidence.
Quick checklist
- Save the abuse warning and record its requirements.
- Start a timeline.
- Preserve website, mail, and server evidence before deletion.
- Identify every affected service.
- Contain the affected website or mailbox.
- Reset relevant credentials.
- Review files, logs, users, and service changes.
- Remove malicious files, backdoors, unauthorized users, and other confirmed changes.
- Test and document the post-cleanup state.
- Send mybox a factual reinstatement request with the remediation evidence.