Since it hasn’t been explicitly stated yet, I’ll state it.
No one’s using your domain to send spam.
They’re using spoofed sender data to generate an email that looks like it’s from your domain. It’s about as easy as putting a fake return address on a piece of postal mail, so no, there’s really no way to stop it. SPF (as suggested) can make it easier for other mail servers to identify email that actually comes from your domain and email that doesn’t, but just like you can’t stop me from putting your postal address as the return address on all the death threats I mail, you can’t stop someone from putting your domain as the reply-to address on their spam.
SMTP just wasn’t designed to be secure, and it isn’t.
Related Posts:
- how to reduce the number of spam comments
- A spam bot loves me, what can I do?
- How to spam-filter a custom content type with the Akismet plugin?
- Getting trackback spam, even with trackbacks disabled
- How to block a someone from commenting?
- Reducing spammy user sign-ups
- How to reduce spam
- How do I permanently disable Pingbacks?
- What are all these spam subscribers doing here?
- How to disable WordPress trackbacks?
- How can I delete all my existing trackbacks?
- How can I delete all users which have never commented / have posted spam comments?
- Comment Spammed vs Trashed
- Contact Form 7 being hijacked to send spam? [closed]
- getting casino links on my woocommerce site [closed]
- How to locate & delete hidden pages on a site
- How is my non-published blog getting so much spam?
- Contact Form 7 Plugin send emails to my Gmail as spam [closed]
- Automated spam being caught in 2 posts. Can this be used to help get rid of spam on everyone’s sites?
- WordPress Site has 35K spam images
- WordPress Phone Verification
- Is the tagline area spam-bot proof?
- Spam email sent from my [email protected] account
- How to block spam blocks pointing to a same website [closed]
- WordPress VPS out of Memory Problem
- Is it possible to determine proxy based comments?
- How to track down a phantom contact form?
- How to get rid of spam forever?
- Spams, Scams on WordPress site – what to do?
- Auto block ALL IP’s indicated by Akismet?
- Simple comments spam solution
- WordPress and wamp sending “Delivery status notification Failure” to my inbox every 7 minutes
- Removing the “Website” Field from Comments and Replies?
- Experiences with adding Nonces to the comment form
- Tips for finding SPAM links injected into the_content
- How to deal with small scale comment spam on small commercial sites? [closed]
- What methods should be used to fend off splogs in a multiuser install? [closed]
- Local wordpress setup with SPAM in the incoming links dashboard section?
- Allow anonymous comments, but prevent spam [closed]
- How exactly does Bad Behavior plugin work?
- Is there any advantage to emptying comment spam?
- Why do I get email notifications about comments that WordPress has already determined are spam?
- Check spam in custom form – akismet
- What is the best way to avoid spammers registering to my blog?
- What do spammers gain by signing up as a user?
- Strategies for coping with hyperagressive spambots?
- Website is being flooded [closed]
- How Do I Prevent Junk Account Creation?
- Hacked website redirect, only on desktop, help with restoring it [closed]
- Something is generating spam pages on my site
- Buddypress Fake (non-bot) Users [closed]
- New users must comment when requesting username
- wp_redirection_404 table has grown to 7GB
- Invisible spam post in backend
- Auto delete WordPress users according to time
- How to make a secure blog that is completely private?
- Auto delete comment if Contains
- All users/comments suspected as bot? [closed]
- Spammers attacking my WordPress Site – Removing URL field from core? [closed]
- How to use a 3rd party library to send emails?
- Batch approve comments
- How do I filter users based on email address?
- Multisite signup spam troubles
- Is there a spam comment blocker that blocks IP addresses for a limited amount of time? [closed]
- CAPTCHA plugin where I can use my own images and ask my own questions? [closed]
- reCaptcha doesnt appear in comment (manual or plugin)
- Database hacked – random posts are modified
- Anonymous spam comments when only registered users can comment
- How to stop direct HTTP POST to a PHP script?
- Has anyone developed a anti-spam plugin to simply allow users to BLOCK whatever they wish to, but one that will also go easy on IP addresses?
- How to add captcha to publish widget
- Prevent Registration Where Role is None?
- Auto post Spams on my wordpress blog?
- Block registration by URL referrer?
- CPU overload spam – redirect link to wp-admin and new post
- WordPress site member verification emails going to spam on Outlook
- Block to accept and send email to specific domains
- Getting hundreds of spam orders in WooCommerce with failed stripe payment [closed]
- WordPress comment processing . Default unapproved comments detection before posting
- Spam Content Serving from old cached version of site?
- Block internal search queries with pre_get_posts and regex rules
- Why does my admin email address keep changing to something random?
- Using htaccess to prevent spam through wp-comments-post.php
- How can I automatically delete comments that contain a URL?
- I want to change the WordPress comments file
- Spam written by registred users
- Site has fake users registered with a similar pattern in username and email
- New accounts daily at WP Multi-User site under development, Analytics reports no traffic. What gives?
- Comment moderation
- Prevent incoming $_GET requests
- Hold a comment in the queue if it contains [X] or more links
- Contact form spam, without form?
- How do spam users register while I’ve only enabled registration by Gmail via Janrain?
- Auto-deleting comments that trigger the blacklist
- comments are going to spam
- How can I prevent wordpress from sending emails
- Can admin-ajax.php be used for spam purposes? And if yes, how to prevent that?
- How to hide and disable URL and email fields from comments?
- Fighting Spam – What can I do as an: Email Administrator, Domain Owner, or User?
- How to send emails and avoid them being classified as spam?