Containment
Use timestamps, queue IDs, remote responses, source IP, VMTA, sender domain and message class to establish the failure boundary. Avoid reacting to one isolated delivery attempt.
Disable or rotate compromised credentials, preserve logs, and identify every message submitted through the account.
Controls
- Bind authenticated users to allowed envelope sender patterns
- Restrict source networks when possible
- Separate credentials per application/customer
- Alert on new domains and unusual volume
Recovery
Re-enable sending only after sender authorization is enforced and all dependent applications use the new credential.
Operational rule: collect evidence before changing policy, make one controlled change, verify the result, and retain a rollback path.