What immediate steps should we take if a 138 Enterprise Email account is sending bulk spam?
Direct Conclusion & Objective: If a 138 Enterprise Email account is sending bulk spam, it strongly indicates that the account credentials or a connected third-party client have been compromised. The immediate objective is to contain the breach, halt unauthorized outbound traffic, and secure the account perimeter.
Root Causes & Evidence Checks: Bulk spam sending typically occurs due to weak passwords, phishing attacks, or malware on a local device. Before proceeding, administrators should verify the scope of the issue by checking the login, attack, and sending logs to record the time, IP addresses, and specific behaviors associated with the unauthorized sending.
Immediate Action Plan (Solutions):
- Credential Reset: Immediately change the password and revoke suspicious clients or client-specific passwords. Administrators can log in, navigate to "Organization & Users - User Management", open the target account, and set a new password. Alternatively, users can reset it via "Personal Settings". The new password must be at least 8 characters long and include letters, numbers, and special symbols.
- Revoke Third-Party Access: If the user accesses email via third-party standard protocol clients, ensure that client-specific passwords are regenerated or revoked to cut off unauthorized connections.
- Audit Account Configurations: Thoroughly check auto-forwarding, filtering rules, aliases, and security verification information. Attackers often set up hidden forwarding rules to intercept replies or maintain persistence.
Service Boundaries & Limitations: Please note that 138 official customer service typically does not directly reset passwords for standard sub-accounts; this must be handled by your enterprise administrator. If the primary administrator account is compromised and the bound phone is unavailable, you must apply for a reset using the contract-registered email to the official support channel for verification.
Next Steps & Recommendation: Once the account is secured, verify that your domain's sender authentication mechanisms—specifically SPF, DKIM, and DMARC—are correctly configured and enforced to prevent domain spoofing. We recommend establishing a routine employee phishing awareness process and enforcing multi-factor authentication for high-risk accounts such as finance and management.


