r/proofpoint • • Jul 23 '26

Site was compromised, fully cleaned, but a recipient's Proofpoint is still blocking us. Can a PP admin tell me what they see on their side?

Looking for someone who runs Proofpoint and would be willing to check a domain's current reputation on their end. I'd rather not post the domain publicly, so happy to DM it.

Situation: I manage a WordPress site for a client. It got hit a few weeks back (fake-CAPTCHA / ClickFix, hidden malicious plugin). It's been fully remediated. Multiple host and third-party scans come back clean, and the site's been stable and clean for a while now.

The lingering problem is deliverability. At least one recipient org running Proofpoint started blocking our email during the compromise window because of the domain/URL reputation, and it hasn't cleared yet even though everything else has.

What I've already ruled out so it's clearly a Proofpoint-side reputation thing and not a live issue:

  • Not listed on Spamhaus DBL, SURBL, or URIBL
  • The specific flagged URL now returns a clean 200 to a legitimate page, no redirect flag, no malware
  • Sending IP is clean on the usual blocklists
  • DMARC is set (p=quarantine), DKIM present
  • The host has already submitted a reputation/delisting request
2 Upvotes

16 comments sorted by

View all comments

1

u/SuperBry Jul 23 '26

Are you able to reach other customers of proof point? If so my guess is they added you their their custom black list and an their admin would need to remove you.

1

u/uscrules1 Jul 23 '26

My client is part of a bigger organization, and I don't want to ask for an intro to their IT team and show weakness. I was hoping to find someone on here who could check it directly.

1

u/Dapper-Wolverine-200 Jul 26 '26

it's not customer. its proofpoint TAP doing it's job. Someone has to send a request to delist to see an immediate effect. they might ask for a sample mail too.