WPSecureOps

Guides · For agencies

Too many Wordfence emails: what to turn off, and what must stay

Wordfence's defaults email you about administrator sign-ins, lockouts, blocked attacks and every completed scan — sensible for one site someone watches closely, unworkable multiplied by a fleet or left running for a year. The fix is not a filter that hides everything. It is knowing which of those emails carries a decision and which merely carries news.

Why the volume explodes

Almost every email switch in Wordfence ships enabled: alerts when an administrator signs in, when someone is locked out, when a user tries a forgotten password, when the plugin updates itself, when a scan finishes. Each is individually defensible. Together they produce a stream in which the signal — a scan that found malware — arrives with the same subject-line urgency as a note that someone mistyped their password.

Volume itself is the vulnerability. The documented failure pattern of compromised WordPress sites is rarely 'no alert was sent'; it is 'the alert was sent, and had been preceded by three hundred emails nobody read'.

Safe to turn off on a managed site

In Wordfence's Email Alert Preferences, these switches generate the bulk of the noise and almost never carry a decision:

  • Alert when someone with administrator access signs in — on a site where admins log in daily, this is pure volume. Keep the variant that only fires for a sign-in from a new device or location if you want the security value without the noise.
  • Alert when a non-admin user signs in — off, always, on any site with real users.
  • Alert when someone is locked out — lockouts on an internet-facing WordPress site are weather, not news. The firewall handles them; a summary view shows patterns better than one email per event.
  • Alert when an IP is blocked — same reasoning; this is the firewall doing its job.
  • Alert when Wordfence is updated — your update process should know this; your inbox does not need to.

What must stay on

Scan result alerts stay, and one switch does most of the work: "Only send email alerts for issues of this severity or greater". Set it to High. Criticals and highs email immediately — those are the findings where the same-day response changes the outcome. Mediums and lows still appear in every scan's results; they belong in a weekly review, not an interrupt.

Keep the alert for Wordfence being deactivated or its firewall being disabled, if your version exposes it. Silence caused by the security plugin itself being switched off is the one silence you cannot afford to misread as calm.

The failure mode of over-muting

The opposite mistake is real: mute everything, forward it to a folder, and the folder becomes a write-only archive. If you turn a category of email off, something must replace it — a weekly review slot, a dashboard someone actually opens, a check that scans are still completing. An alert you disabled without a replacement is a decision to not know.

A useful test: for each email type, ask what you would do on receiving it. If the honest answer is 'nothing', turn it off and let the information reach you in aggregate. If the answer is 'act today', it stays as an email — that is what email is for.

Past a handful of sites, stop tuning inboxes

Every recommendation above is per-site configuration, multiplied by your fleet, drifting as sites get added. Past roughly ten sites the durable answer is to stop treating an inbox as a security console: route everything to a shared address as an audit trail, and read findings in one place that sorts them by severity across every site — Wordfence Central, a MainWP-style console, or WPSecureOps, whose entire premise is that a queue sorted worst-first replaces forty parallel email streams.

Common questions

Will I miss a hack if I set the threshold to High?
The threshold only limits which findings interrupt you by email — every finding, at every severity, is still in the scan results and still visible in any dashboard reading them. Malware signatures, backdoors and known-vulnerable components score at or above High in Wordfence's model, so the interrupts you keep are precisely the compromise-shaped ones.
Is there a digest option instead of per-event email?
Wordfence can send a scheduled summary of recent activity (Email Summary in the options), which works well as the weekly aggregate for everything you muted. What it does not do is aggregate across sites — each install summarises itself, which is exactly the limitation that pushes fleets towards a central console.
Why am I getting alerts for sites at 3am when nothing is wrong?
Scan schedule. Each site scans on its own clock, defaulting into the night hours, and emails its results on completion. Spread your fleet's scan times across the working day instead — findings then arrive while someone can act, and a scan failure surfaces the same morning rather than in yesterday's small hours.

Referenced in this guide

The other guides

One queue instead of forty inboxes