WPSecureOps

Glossary · Malware

The site may be advertised in spam

Wordfence type
spamvertizeCheck
Category
Malware
Severity
High

The domain appears in spam-related reputation data, which usually follows a compromise.

What Wordfence found

Wordfence checks whether the domain shows up in spam reputation sources. A hit means the domain is being promoted through spam somewhere, typically by a third party rather than the owner.

Why it matters

Spamvertising usually means the site is hosting injected pages for someone else's campaign, or its mail is being relayed. Either way, deliverability and domain reputation suffer, and email from the domain begins landing in junk folders.

How to fix it

  1. 1Scan for injected content, especially unfamiliar directories under uploads.
  2. 2Check whether the site is sending mail it should not — review any mail-sending plugin's logs.
  3. 3Confirm SPF, DKIM and DMARC are configured, so the domain cannot be spoofed as easily.
  4. 4Clean the compromise before chasing the reputation listings, or they will simply return.

How WPSecureOps treats it

The connector reports this as spamvertizeCheck. WPSecureOps files it under Malware and bands it by the numeric severity Wordfence assigns, so findings of this kind from every site you manage arrive in one queue rather than one email per site. Titles and descriptions are stripped of HTML and the site's absolute path is replaced before anything leaves the server.

See this finding in context