WPSecureOps

Guides · For agencies

Too many Wordfence emails? What to turn off and what to keep

Wordfence can email about scan findings, firewall events, password use, administrator sign-ins and service state. Multiplied across a fleet, those individually defensible alerts become a stream no one reads. The fix is not a mail rule that hides everything. It is deciding which messages require action today and which belong in a summary.

Why the volume explodes

A fresh Wordfence install enables most security-event alerts: scan issues, deactivation, the firewall being turned off, blocked IPs, login lockouts, breached-password attempts, valid lost-password requests, administrator sign-ins, and increased attack rate. Automatic-update mail and non-admin sign-in mail are off by default, but that still leaves enough enabled switches to overwhelm a busy site or an agency inbox.

Volume itself becomes an operational vulnerability. A backdoor alert has the same sender and similar subject-line weight as a hundred messages saying the firewall blocked traffic exactly as designed. Once the reader learns that most Wordfence mail requires no decision, the important message is punished by the noise that came before it.

Open the Wordfence Email Alert Preferences

In WordPress, go to Wordfence → All Options → Email Alert Preferences. Expand the panel, make the changes below, and use Save Changes at the top of the page. The recipient lives in a different panel: Wordfence → All Options → General Wordfence Options → Where to email alerts.

Take a screenshot or export the finished configuration before rolling it out. On a fleet, that reference is what lets you tell a deliberate exception from quiet configuration drift six months later.

Wordfence Email Alert Preferences showing alert switches and the scan severity dropdown
The Email Alert Preferences panel and scan-severity dropdown. Layout can vary by Wordfence version. Screenshot source: WP Mail SMTP.

Wordfence email settings: switch by switch

This is a managed-site baseline, not a universal prescription. “Keep” means the email can reasonably trigger same-day action; “Off” means the information should still be reviewed in Wordfence, a central console, or the weekly activity report. Defaults below are from the current Wordfence 8.x configuration for a fresh installation. Sites upgraded from older releases can retain previous values, especially the hourly cap.

Fresh-install defaults checked against the current Wordfence plugin configuration.
SwitchFresh defaultRecommendedWhy
Wordfence automatically updatedOffOff with managed updatesYour maintenance system should verify versions; turn this on only if no other process does.
Wordfence deactivatedOnKeep onUnexpected deactivation removes both visibility and protection.
Web Application Firewall turned offOnKeep onA disabled WAF is a protection-state change, not routine traffic.
Scan results at this severity or greaterOn · Low (25)High (75)Critical and High findings interrupt; Medium and Low stay available for scheduled review.
IP address blockedOnOffA block usually means the firewall worked. Review the aggregate, not every source IP.
Someone locked out from loginOnOffInternet-facing login pages accumulate lockouts that rarely need one-by-one action.
Login blocked for a breached passwordOnKeep onA real account used a known-breached password; reset it and review that user's access.
Lost-password form used for a valid userOnOff on busy sitesThis is common user activity. Investigate patterns in aggregate unless the site is unusually sensitive.
Administrator signs inOnNew devices onlyKeep the parent switch on and enable its child option to suppress familiar-device logins.
Non-admin user signs inOffOffMembership and commerce sites can generate a message for every customer session.
Large increase in attacksOnUsually offIt reports blocked traffic volume, not proof that an attack succeeded.
Maximum alerts per hour5Keep 5The cap prevents a burst from monopolising the mailbox; older upgraded sites may still be unlimited.

What should stay on

Keep Wordfence-deactivated and WAF-turned-off alerts. Silence caused by the security plugin itself being disabled is the one silence you cannot safely interpret as calm. Keep the breached-password login alert too: the attempt was blocked, but the account owner is demonstrably using a credential already present in breach lists and needs a reset.

Keep scan-result email enabled and set “Alert me with scan results of this severity level or greater” to High. Wordfence's native levels are Critical 100, High 75, Medium 50 and Low 25. The threshold changes what interrupts you by email; it does not remove lower-severity findings from the scan results. Medium maintenance work can remain visible for the weekly queue without competing with malware or exposed credentials in today's inbox.

What the Increased Attack Rate email really means

The subject usually reads “[Wordfence Alert] Increased Attack Rate”. It is generated when Wordfence sees a burst of requests blocked by firewall rules or the global IP blocklist. That is evidence of hostile traffic, but it is also evidence that the firewall is handling that traffic; by itself, it is not evidence that the site was compromised.

For a managed fleet, turn this switch off unless an immediate traffic spike changes what the team will do. Use firewall statistics, Live Traffic, hosting metrics, or a central event view to assess patterns without one message per burst. Keep it on for a quiet, high-value site only when someone has agreed to inspect unusual traffic immediately — and remember that the response is investigation, not manually blocking every address already handled by Wordfence.

Use the Email Summary as the weekly layer

Below Email Alert Preferences, Wordfence exposes an Activity Report with an “Enable email summary” option. It is on weekly by default on a fresh install, and can run daily, weekly, or monthly. Weekly is the useful interval for a managed site: frequent enough to show trends, quiet enough to remain a summary rather than another alert stream.

The report aggregates recent security activity and recently modified files. Leave Wordfence's default exclusions for wp-content/cache and wp-content/wflogs unless you have a reason to inspect those high-churn paths. The summary does not aggregate across installations, so twenty sites still produce twenty reports; route them to a folder reviewed in one weekly session, or replace that layer with a cross-site dashboard that someone actually opens.

The failure mode of over-muting

Do not turn every switch off, forward the remainder to an unread folder, and call the inbox solved. Every disabled category needs a replacement: a weekly review slot, a dashboard owner, a last-scan check, or an activity report. An alert disabled without a replacement is a decision not to know.

Use a simple test for every message type: what would we do if this arrived? If the answer is “nothing, because Wordfence already blocked it”, aggregate it. If the answer is “change a password, investigate a new finding, or restore a protection control today”, keep the interruption. Revisit the decision after the first month using actual volume rather than fear of what might be useful.

Past a handful of sites, stop tuning inboxes

Every recommendation above is per-site configuration, multiplied by the fleet and exposed to drift as new clients arrive. Past roughly ten sites, keep the shared mailbox as an audit trail but work from a console that can sort findings across sites. Wordfence Central and WPSecureOps take different approaches; the important change is replacing forty independent subject lists with one owned workflow.

Test the final route end to end. Wordfence uses WordPress mail, so a saved address and enabled checkbox do not prove delivery. Send a test from Wordfence → Tools → Diagnostics, verify it reaches the shared destination, and make failed delivery visible through the site's SMTP or transactional mail system.

Common questions

How do I change the Wordfence alert email address?
Open Wordfence → All Options → General Wordfence Options and edit “Where to email alerts”, then save. Wordfence accepts multiple recipients separated by commas. For an agency, use a monitored shared address rather than a person's mailbox, and send a test email from Wordfence → Tools → Diagnostics so a correctly saved setting is not mistaken for confirmed delivery.
How do I stop Wordfence admin-login emails?
Open Wordfence → All Options → Email Alert Preferences. Either turn off “Alert me when someone with administrator access signs in”, or leave it on and enable the child option that alerts only when the administrator signs in from a new device. The second choice preserves a useful anomaly signal without emailing for every familiar daily login.
Will I miss a hack if I set scan email to High?
The setting changes the minimum severity that triggers scan-result email; it does not delete Medium or Low findings from Wordfence. Critical and High results still interrupt you, while lower-severity maintenance items remain in scan results and central dashboards for a weekly review. The safe setup therefore requires that the scheduled review genuinely happens and checks last-scan health too.

Referenced in this guide

The other guides

Primary references

Product behaviour and remediation guidance were checked against these primary sources.

  1. Wordfence: Alert types and severity levels
  2. Wordfence: Global options and email alert preferences
  3. Wordfence plugin source: Default configuration
  4. Wordfence: Scan documentation

One queue instead of forty inboxes