Skip to content
KVKK & GDPR Compliant Turkey Data Center 24/7 Technical Support destek@mxgate.com.tr
New: IP reputation monitoring is now free on every plan Start your 14-day free trial →
SOLUTION · OUTBOUND

Outbound Filtering

Outbound filtering is the inspection of email leaving your server. When a compromised account starts sending spam, it catches this before you do, stops the sending and tells you about it.

Direction
Outbound only
Detection
Volume · recipients · content · authentication · bounces
Response
Quota · suspend sending · admin alert
Scope
Isolation per account and per domain
Starts at
$49 USD / mo
THE REAL RISK

The damage comes from inside, not outside

A compromised mailbox
One stolen password is enough. Because the attacker sends from your server with your IP, no external filter stops it.
A badly configured form
A contact or signup form without validation can produce hundreds of messages a minute. No malice is needed, only neglect.
Neighbour effect on shared servers
Another customer sharing the same IP drags your delivery rate down too. You pay the price even when the problem is not yours.
The time it goes unnoticed
Outbound spam is usually noticed hours later, when delivery drops or a blocklist notice arrives. By then recovery takes days.
Email leaving the server being inspected: malicious and spam messages are separated while clean ones are approved and sent, keeping the IP reputation gauge in the green
Risky sending is separated before it leaves the server; the reputation gauge stays green.
WHAT GETS DETECTED

We look at signals appearing together, not at one alone

On its own none of these is proof: a user really may be sending a lot of mail. The decision comes from several signals coinciding, which keeps false positives low.

Volume spike

Sending far above the account’s normal rate, especially sudden jumps outside working hours.

Same body, many recipients

Near-identical content going to many different addresses in a short window.

Known phishing pattern

Fake invoice, payment and password-reset patterns are searched for in outgoing mail with the same rules.

Authentication failures

Repeated failed login attempts are usually seen right before a sending burst.

Bounce rate

A rise in mail sent to non-existent addresses signals purchased or generated lists.

Content and attachment scan

Outgoing messages are scanned for malicious attachments and links too, so your server never becomes a source of infection.

One flagged message being picked out of a row of email items for inspection
A message that trips several signals at once is flagged; high volume alone is not enough.
WHEN IT HAPPENS

What happens, minute by minute, when an account is compromised?

The times below are typical. What matters is not the order but that the response happens while the sending is still in its first minute.

  1. 00:00

    The account is compromised

    With a stolen password, bulk sending starts from a single mailbox. As far as your server is concerned, this is a normal user sending mail.

  2. +20 sec

    The anomaly is caught

    Volume, recipient count and content are evaluated together. Sending that falls outside the account’s normal behaviour and hourly quota is flagged.

  3. +40 sec

    Sending is stopped

    Only that account’s outbound traffic is suspended. Queued messages are not deleted; they are held until a decision is made.

  4. +1 min

    The alert goes out

    An incident record opens in the panel showing which account, how many messages and why it was stopped. The administrator is notified.

  5. After

    The pool stays clean

    No other customer’s sending is affected. Because IP reputation never drops, there is no blocklisting and no days-long removal process.

QUOTAS AND LIMITS

The settings that cap the damage

Quotas are not a punishment but a buffer: they decide how many messages can get out in the seconds between detection and response. All of them are set per account and per domain.

Limit How it works What it prevents
Hourly message quota A per-account counter; sending pauses when it is exceeded A compromised account firing off thousands of messages
Daily message quota A total sending ceiling per domain Undeclared bulk campaigns straining the pool
Recipient limit The number of recipients in one message is capped Sweeping a large address list with a single send
Concurrent connections Open connections are limited per account One account consuming the queue and resources
Warning threshold An account nearing its quota is flagged in the panel An interruption arriving without warning

Values are set according to your plan and needs, and can be raised for approved bulk sending.

PRICING

Outbound filtering pricing

Service starts at $49 USD per month. Outbound inspection is included in every plan at no extra cost.

Starter
$49
USD / mo
250,000 emails / month
Enterprise
$200
USD / mo
Unlimited email
See all plans and features
FAQ

Frequently asked questions

What is outbound filtering?

Outbound filtering is the inspection of email leaving your server before it reaches the recipient. Sending volume, recipient count, content and account behaviour are evaluated together; when an unusual send is detected the message is stopped and the administrator is alerted.

How do you notice a compromised account?

We do not rely on a single signal but on several appearing together: a sudden jump in sending volume, the same body going to many recipients, known phishing patterns, repeated failed authentication attempts and a rise in bounce rates. When these coincide, the account is flagged.

Will my legitimate bulk sending be blocked?

No. For known and approved sending, quotas can be raised per account and sending windows defined. Newsletter and notification traffic is evaluated separately this way, so a planned campaign is not confused with a sudden, undeclared spike.

How do I stay off blocklists?

The most common cause of blocklisting is outbound spam that goes unnoticed. Outbound filtering stops that sending at the source, so your IP reputation never drops. When sending also runs over a clean pool, the risk moves off your address; see the smarthost page for details.

Can the quotas be changed?

Yes. Hourly and daily limits are set per account and per domain and can be raised or lowered as needed. Accounts approaching their quota appear as a warning in the panel before any interruption.

Last updated: · Source: MXGate platform data, 2026