WPSecureOps

Glossary · Malware

The site may be advertised in spam

Wordfence type
spamvertizeCheck
Category
Malware
Severity
High

The domain appears in spam-related reputation data, which usually follows a compromise.

The alert usually reads
Your site is being advertised in spam emails.

What Wordfence found

Wordfence checks whether the domain shows up in spam reputation sources. A hit means the domain is being promoted through spam somewhere, typically by a third party rather than the owner.

Why it matters

Spamvertising usually means the site is hosting injected pages for someone else's campaign, or its mail is being relayed. Either way, deliverability and domain reputation suffer, and email from the domain begins landing in junk folders.

How to fix it

  1. 1Scan for injected content, especially unfamiliar directories under uploads.
  2. 2Check whether the site is sending mail it should not — review any mail-sending plugin's logs.
  3. 3Confirm SPF, DKIM and DMARC are configured, so the domain cannot be spoofed as easily.
  4. 4Clean the compromise before chasing the reputation listings, or they will simply return.

Common questions

What does 'spamvertised' actually mean?
Spam emails somewhere on the internet contain links to your domain. Spammers link through legitimate sites — via an open redirect, an injected page, or a compromised install — because established domains slip past mail filters that would catch theirs. Your domain lends them its reputation, and burns it in the process.
Where do I look for what the spammers are using?
Three usual suspects: an open redirect (any URL on your site that forwards wherever a parameter says), injected pages you do not know exist (site:yourdomain.com in Google reveals them), and compromised contact or search forms that echo attacker text into outgoing mail. Server access logs for odd, repeated URL patterns will usually show the abused path.
What is the damage if I ignore it?
Your domain accrues spam reputation: your own outgoing mail starts landing in junk folders, mail providers may block the domain outright, and blocklist entries once earned take effort to shed. Mail deliverability is slow to lose and slower to win back — this is worth resolving before that compounding starts.

How WPSecureOps treats it

The connector reports this as spamvertizeCheck. WPSecureOps files it under Malware and bands it by the numeric severity Wordfence assigns, so findings of this kind from every site you manage arrive in one queue rather than one email per site. Titles and descriptions are stripped of HTML and the site's absolute path is replaced before anything leaves the server.

Primary references

Product behaviour and remediation guidance were checked against these primary sources.

  1. Wordfence: How to interpret scan results
  2. Wordfence: If your site is hacked
  3. Google Search Console: Security Issues report

See this finding in context