Spam, phishing, and malicious mail
Spam is usually unsolicited bulk email. Phishing steals information through a fake sign-in, payment, or document page. Malicious mail attempts to execute code through an attachment, macro, or link. One message can fit several categories; looking like advertising does not make it safe.
Inspect suspicious mail safely
- Do not click links, open attachments, auto-load images, or reply.
- Inspect the actual From and Reply-To, not only the display name. Watch for substituted letters and look-alike Unicode characters.
- Verify urgency, secrecy, unusual payment/IBAN changes, or password requests through a second channel.
- Use the application's Report Spam/Junk action; deleting alone may provide no filtering feedback.
- If data was disclosed, disconnect the device, change the password from a clean device, and contact support@eurovdc.eu.
Mailcow SOGo/webmail filters
Sign in to Corporate Email at https://mail.YOURDOMAIN.com/user. Marking a message as Junk/Spam helps classification. When creating webmail rules, narrowly scope sender, subject, or header conditions; avoid a broad rule that deletes everything. Moving matches to a separate folder for several days is safer than immediate deletion.
Block one address when it repeatedly abuses the mailbox. Blocking an entire domain can reject legitimate customers on the same provider. The visible From address is easy to spoof, so inspect headers and authentication results in high-risk cases.
DirectAdmin SpamAssassin
For Hosting email, open https://SERVER:2222 or https://DOMAIN:2222 → Email Management → SpamAssassin Setup or Spam Filter. An overly aggressive score threshold increases false positives. First route spam to a separate folder, observe samples, and adjust gradually. Do not enable “delete all spam” before validation.
If your account is sending spam
- Stop sending, terminate active sessions, and set a unique strong password.
- Update and scan phones/computers plus website forms, plug-ins, CMS installations, and scripts.
- Review forwarding, filters, signatures, and unknown accounts.
- Verify SPF, DKIM, and DMARC. They reduce spoofing but do not compensate for a stolen password.
- Provide support with the incident time and sample recipients for queue/log review.
Long-term reduction
Avoid unnecessary public exposure of addresses; add rate limits and bot protection to forms. Send newsletters only with explicit consent and trustworthy unsubscribe. Never reuse the mailbox password elsewhere. For false positives, apply narrow whitelisting instead of broad bypasses.
EuroVDC product note and shared technical reference
First confirm which product hosts the mailbox. Corporate Email (Mailcow) uses securemail.eurovdc.eu for incoming and outgoing mail. Hosting email (DirectAdmin) uses mail.yourdomain.com or the server hostname supplied in the service activation details. Using one product's hostname for the other can cause connection or certificate-name errors even when the password is correct.
| Protocol | Secure port | Encryption | Purpose |
|---|---|---|---|
| IMAP | 993 | SSL/TLS | Recommended; synchronizes folders between devices |
| SMTP | 587 | STARTTLS | Recommended outgoing connection |
| SMTP | 465 | SSL/TLS | Alternative outgoing connection |
| POP3 | 995 | SSL/TLS | Only for specific download requirements |
The username is always the full email address. SMTP authentication is mandatory; use the same full username and mailbox password as incoming mail. Do not select Microsoft 365 or Outlook.com, and do not use Microsoft-hosted server names. Corporate webmail is https://mail.YOURDOMAIN.com/user; replace YOURDOMAIN.com with your domain.
Client area and DirectAdmin path
- Sign in to the EuroVDC client area.
- Open the relevant product, then view Connection Settings and the DNS wizard.
- Record the server name, account-specific DKIM text, and displayed DNS status.
- For Hosting email, sign in at https://SERVER:2222 or https://DOMAIN:2222. Open Email Accounts, create or locate the mailbox, then use “+” → Configure Email Client on its row to obtain the exact hostname and ports.
Corporate Email DNS summary
| Name | Type | Target/value |
|---|---|---|
| CNAME | securemail.eurovdc.eu | |
| @ | MX | securemail.eurovdc.eu, priority 10 |
| @ | TXT | v=spf1 mx ip4:45.84.90.12 -all |
| dkim._domainkey | TXT | Account-specific DKIM value from the DNS wizard |
| _dmarc | TXT | Commonly v=DMARC1; p=reject; adkim=r; aspf=r; pct=100 |
| autodiscover and autoconfig | CNAME | securemail.eurovdc.eu |
Autodiscover and autoconfig help compatible applications propose server settings; they do not remove password security or SMTP authentication. Always compare discovered values with the product screen. DNS changes may appear differently across networks until cached records expire.
Quick checklist
- Corporate Email and Hosting email have been distinguished.
- The full email address is entered as the username.
- 993/SSL-TLS and either 587/STARTTLS or 465/SSL-TLS are paired correctly.
- SMTP authentication is enabled and its password is not blank.
- Webmail, receiving, and sending have been tested separately.
- DNS matches the wizard, and the exact error and test time are recorded.
For a visual reference, download the Email Setup Card from PDF help files. If the issue remains, send the mailbox address, device/application version, complete error, and screenshot to support@eurovdc.eu. EuroVDC services operate from Sofia, EU; never include your password in a support request.