Outbound Filtering
Outbound filtering is the inspection of email leaving your server. When a compromised account starts sending spam, it catches this before you do, stops the sending and tells you about it.
- Direction
- Outbound only
- Detection
- Volume · recipients · content · authentication · bounces
- Response
- Quota · suspend sending · admin alert
- Scope
- Isolation per account and per domain
- Starts at
- $49 USD / mo
The damage comes from inside, not outside

We look at signals appearing together, not at one alone
On its own none of these is proof: a user really may be sending a lot of mail. The decision comes from several signals coinciding, which keeps false positives low.
Volume spike
Sending far above the account’s normal rate, especially sudden jumps outside working hours.
Same body, many recipients
Near-identical content going to many different addresses in a short window.
Known phishing pattern
Fake invoice, payment and password-reset patterns are searched for in outgoing mail with the same rules.
Authentication failures
Repeated failed login attempts are usually seen right before a sending burst.
Bounce rate
A rise in mail sent to non-existent addresses signals purchased or generated lists.
Content and attachment scan
Outgoing messages are scanned for malicious attachments and links too, so your server never becomes a source of infection.

What happens, minute by minute, when an account is compromised?
The times below are typical. What matters is not the order but that the response happens while the sending is still in its first minute.
-
00:00
The account is compromised
With a stolen password, bulk sending starts from a single mailbox. As far as your server is concerned, this is a normal user sending mail.
-
+20 sec
The anomaly is caught
Volume, recipient count and content are evaluated together. Sending that falls outside the account’s normal behaviour and hourly quota is flagged.
-
+40 sec
Sending is stopped
Only that account’s outbound traffic is suspended. Queued messages are not deleted; they are held until a decision is made.
-
+1 min
The alert goes out
An incident record opens in the panel showing which account, how many messages and why it was stopped. The administrator is notified.
-
After
The pool stays clean
No other customer’s sending is affected. Because IP reputation never drops, there is no blocklisting and no days-long removal process.
The settings that cap the damage
Quotas are not a punishment but a buffer: they decide how many messages can get out in the seconds between detection and response. All of them are set per account and per domain.
| Limit | How it works | What it prevents |
|---|---|---|
| Hourly message quota | A per-account counter; sending pauses when it is exceeded | A compromised account firing off thousands of messages |
| Daily message quota | A total sending ceiling per domain | Undeclared bulk campaigns straining the pool |
| Recipient limit | The number of recipients in one message is capped | Sweeping a large address list with a single send |
| Concurrent connections | Open connections are limited per account | One account consuming the queue and resources |
| Warning threshold | An account nearing its quota is flagged in the panel | An interruption arriving without warning |
Values are set according to your plan and needs, and can be raised for approved bulk sending.
Outbound filtering pricing
Service starts at $49 USD per month. Outbound inspection is included in every plan at no extra cost.
Frequently asked questions
What is outbound filtering?
Outbound filtering is the inspection of email leaving your server before it reaches the recipient. Sending volume, recipient count, content and account behaviour are evaluated together; when an unusual send is detected the message is stopped and the administrator is alerted.
How do you notice a compromised account?
We do not rely on a single signal but on several appearing together: a sudden jump in sending volume, the same body going to many recipients, known phishing patterns, repeated failed authentication attempts and a rise in bounce rates. When these coincide, the account is flagged.
Will my legitimate bulk sending be blocked?
No. For known and approved sending, quotas can be raised per account and sending windows defined. Newsletter and notification traffic is evaluated separately this way, so a planned campaign is not confused with a sudden, undeclared spike.
How do I stay off blocklists?
The most common cause of blocklisting is outbound spam that goes unnoticed. Outbound filtering stops that sending at the source, so your IP reputation never drops. When sending also runs over a clean pool, the risk moves off your address; see the smarthost page for details.
Can the quotas be changed?
Yes. Hourly and daily limits are set per account and per domain and can be raised or lowered as needed. Accounts approaching their quota appear as a warning in the panel before any interruption.