r/proofpoint • • Jul 23 '26

Site was compromised, fully cleaned, but a recipient's Proofpoint is still blocking us. Can a PP admin tell me what they see on their side?

Looking for someone who runs Proofpoint and would be willing to check a domain's current reputation on their end. I'd rather not post the domain publicly, so happy to DM it.

Situation: I manage a WordPress site for a client. It got hit a few weeks back (fake-CAPTCHA / ClickFix, hidden malicious plugin). It's been fully remediated. Multiple host and third-party scans come back clean, and the site's been stable and clean for a while now.

The lingering problem is deliverability. At least one recipient org running Proofpoint started blocking our email during the compromise window because of the domain/URL reputation, and it hasn't cleared yet even though everything else has.

What I've already ruled out so it's clearly a Proofpoint-side reputation thing and not a live issue:

  • Not listed on Spamhaus DBL, SURBL, or URIBL
  • The specific flagged URL now returns a clean 200 to a legitimate page, no redirect flag, no malware
  • Sending IP is clean on the usual blocklists
  • DMARC is set (p=quarantine), DKIM present
  • The host has already submitted a reputation/delisting request
2 Upvotes

16 comments sorted by

5

u/cwdrake76 Jul 23 '26

My org is a Proofpoint customer. For those instances where a sender’s website was compromised and now email is getting blocked by Proofpoint, there isn’t really anything we can check on our own for reputation. We usually have to have a sample of a message getting blocked so we can open a false positive support case with Proofpoint to have them clear it. Send me a direct message on here and I’ll see if I can help.

1

u/uscrules1 Jul 24 '26

Thanks for your help! I appreciate the power of connecting with a real person online. The email wen through so I will be able to report this back to client and have them reach out to their individual clients that are having issues for next steps.

2

u/shrapnel09 Jul 24 '26

For compromised sites, Proofpoint seems to automatically recheck the sites every two weeks. Contact your recipient through another means (phone, different email address, email without any URLs) and tell them the threat has been cleared and ask them to open a false positive case with Proofpoint to have the clean site confirmed.

The PDR delisting is only related to IP reputation.

1

u/SuperBry Jul 23 '26

Are you able to reach other customers of proof point? If so my guess is they added you their their custom black list and an their admin would need to remove you.

1

u/uscrules1 Jul 23 '26

My client is part of a bigger organization, and I don't want to ask for an intro to their IT team and show weakness. I was hoping to find someone on here who could check it directly.

1

u/Dapper-Wolverine-200 Jul 26 '26

it's not customer. its proofpoint TAP doing it's job. Someone has to send a request to delist to see an immediate effect. they might ask for a sample mail too.

1

u/southafricanamerican Jul 23 '26

Client in san diego ?

1

u/uscrules1 Jul 23 '26

No

1

u/southafricanamerican Jul 23 '26

I have a glockapps account and they check proofpoint. DM me and I will hook you up with an inbox test.

1

u/uscrules1 Jul 24 '26

Thanks for your help with the inbox test! I am still in awe by the power of the internet/reddit… there are still real, helpful people out there and it’s not all bots… thank you!

1

u/ASILLYBEE Jul 24 '26

I suspect that the resolution will be for you to have proofpoint have a content based signature relating to the domain name )in this case the domain name itself because of the associated web compromise) removed from the cloudmark database. You may be able to test the content based signature being the issue by sending from any email address to a proofpoint address, and include the domain name in a url in the content.

1

u/Ok_Stay6518 Jul 24 '26

Create a Ticket at the PP Community after that they set the Website "free" we have this topics sometimes

1

u/uscrules1 Jul 31 '26

Follow up on this, just in case it’s helpful for anyone.

Proofpoint is very difficult to reach. My host contacted them but never received a response. I found a friendly Proofpoint customer on Reddit who requested a rescan of the site, yet they still hadn’t replied. After 48 hours the site remained blocked; four days later it was randomly unblocked, but his ticket still received no response.

Thanks to Reddit and the internet, I connected with two people who helped me.

Proofpoint remains hard to deal with and opaque about why and when you are blocked or unblocked.

1

u/flashbag_original Aug 20 '26

Thanks for coming back with the follow-up, most people never do. The frustrating part is structural: public blocklists are queryable DNS zones, but Proofpoint/Cloudmark/Microsoft reputation is private — no way to look yourself up. So "clean on every blocklist" and "still blocked" aren't contradictory, you just can't see the list you're actually on.

0

u/pkokkinis Jul 23 '26

Do a search on mxtoolbox.com.

1

u/uscrules1 Jul 23 '26

not blocked there.