Version 0.1.0, 1 October 2026. Download (75 KB), SHA-256 5df918a10cd996799f5d144abcc101970fab31fbb7e2298be78362257c0aaa28. The installation steps are at the end of this page; inside the archive the same text is INSTALL.md. The code and the same archive as a release are also on GitHub.
Who it is for
Hosting providers whose servers run Plesk Obsidian 18.0.50 or newer on Linux. You install the extension as root and register the server once. After that every customer finds Email Spam Tester in Websites & Domains › their domain › Mail, next to Mail Settings. Service plans decide who gets which part of it.
What a web tester cannot do is look at the sending side: it only sees the email that reached it. The extension sends the test from your server, through Postfix, signed with the domain's DKIM key and from its IP and HELO name, so the report is about the setup the customer actually has. And because Plesk holds the domain's DNS zone, a missing record is often one button away.
What a customer sees
Test
At the top is a check that runs before any email is sent: whether this server passes the domain's SPF, whether Plesk signs with DKIM and the key in DNS is the one it signs with, the DMARC policy and the MX. Each problem has a Fix button, or Show the record when the domain's DNS is served somewhere else.
Below it the customer picks a mailbox of the domain and how the test goes out. It can go as that mailbox, or the way the website sends mail, under the subscription's own system user, which is how WordPress, contact forms and shop notifications send. The second one catches a common hosting problem, mail from PHP leaving with a sender the domain's SPF does not cover. The email is either the standard test email (a short message in English, text and HTML) or the customer's own, pasted as subject, HTML and optional text.
"Also check the folder at email providers" is on by default. In the background, in random order and two to four seconds apart, the server then sends one copy to each of 29 test mailboxes at 14 providers (Gmail, Outlook, Yahoo, GMX and Proton among them). Each copy carries its own Message-ID, so the extension can pick its lines out of Postfix's log. Over the next half hour the table fills in: Inbox, Spam or Promotions per provider, or, where a provider refused, its answer with the SMTP code. At Gmail these are public test mailboxes, and anyone there sees the subject, the sender name and the folder, so confidential content is better tested without the folder check.
The report has every check, the score out of 100 and the classic 0 to 10, the AI plan, and the same fix buttons, this time taking the IP the report actually saw the email come from.
History
All tests of the domain, newest first, with both scores and the folder counts, a chart of the score, and for each test the checks that moved since the previous one. After a DKIM fix the row says DKIM went from fail to pass.
Monitoring
If you allow it on the server, a customer can switch monitoring on for a domain. From then on each email the domain sends gets a technical report with DKIM, SPF and DMARC, the sending IP and blocklists. The tab sums up the last 24 hours by source, so mail from the website's PHP is counted apart from webmail or a mail app. Alerts come next, for example when DKIM fails in the latest emails or SPF fails for mail from the website. Below them are the latest emails with their reports. Two order confirmations from the same shop template count as one check within an hour, so a busy shop does not produce a thousand identical reports. An AI plan for a single email is there on request.
What the administrator gets
Tools & Settings › Mail › Email Spam Tester has the registration and the switch for monitoring on the whole server. Limits are set there per subscription for tests, folder checks, AI plans and monitored domains, and per monitored domain for emails a day. A table lists the server's own IPs with their reverse DNS, whether it matches the HELO name, and blocklists.
The extension adds four permissions to service plans, for the extension itself, the fix buttons, the folder check and monitoring, and all four are on by default. DNS buttons also need the plan's own permission to manage DNS, and the DKIM switch the one to manage mail settings.
Price
Free for now, like the tester itself; the changelog will say first if that changes. The limits you set apply under the ones Email Spam Tester keeps per server (folder checks, domain checks and monitored domains a day), and the administrator's page shows both with today's usage.
How it works and what leaves your server
The extension sends the test email from your server and decides nothing itself. What the checks found, the history, what changed, which DNS record to publish, the monitoring feed, the alerts and the limits are all worked out by the Email Spam Tester API, the same one the site uses. To the API go:
- the server's hostname, Plesk and extension versions, the number of domains and, if you give one, the administrator's email, once, at registration;
- the test emails;
- each subscription as a keyed hash, never its name;
- for the DNS check, the TXT records Plesk holds for the domain, its DKIM key, the server's IPs and HELO name, and a mailbox of the domain for DMARC reports;
- the lines of your mail log about our own test emails;
- with monitoring, copies of the domain's outgoing email.
Test reports have links, as on the site, and whoever has the link can open one. The monitoring feed is different, since it is your customers' real mail. Its reports open only with your server's key, and the copied email is deleted after two days, its report after 90. The privacy page has the rest.
Questions hosting providers ask
Does it change DNS by itself?
No. A record changes when the customer presses Fix and confirms the record as it is now and as it will be, and only when the world actually reads the domain's DNS from your server. An SPF record keeps every term it had; the server's IP is added first and costs no extra DNS lookup. An existing DMARC policy is never replaced. Every change goes into Plesk's action log and can be undone from the Test tab, as long as nobody has edited the record since. Public resolvers remember a missing record for the zone's SOA minimum, three hours in Plesk's default template, so a test right after a fix may still show the old result.
How does monitoring copy the mail?
A Plesk mail handler runs after Plesk signs the email with DKIM. It passes every message on unchanged and, for a domain that has monitoring on, hands a copy to a Postfix listener on 127.0.0.1 that accepts only our monitoring addresses. Postfix then delivers the copy like any other email, from the same IP and with the same signature. Whose mail it is comes from the SMTP login or the subscription's system user, never from the sender address alone, so nobody can push their mail into another customer's feed. The handler is installed to /usr/local/lib/email-spam-tester, the list of domains to /etc/email-spam-tester/monitor.json.
Does it slow outgoing mail down?
The handler reads the message and hands it back. The copy is passed to the local listener by a separate process, so the original does not wait for the copy's delivery. I sent a 5 MB attachment through both sendmail and SMTP with monitoring on, and both the original and the copy arrived.
What has been tested live?
Plesk Obsidian 18.0.81 on Ubuntu 24.04, on a server with a public IP and a domain whose DNS it serves: install, uninstall and reinstall, registration, a test with the folder check from a domain with no DKIM, SPF or DMARC, the three fix buttons, a second test with all three passing, the history, and monitoring of email from the website and from a mail app. The web pages were tested on a local Plesk. Not tested yet: other Linux distributions and Plesk versions, a server that relays through a smarthost, and qmail instead of Postfix. Plesk for Windows is not supported. Write to me if you run it on one of those.
Install, step by step
This guide assumes you have root on a Plesk server. Every command below is meant to be copied and pasted as it is.
1. What you need
- Root SSH access to the server.
- Plesk Obsidian 18.0.50 or newer on Linux, with Postfix as the mail server (the Plesk default). Tested live on Plesk Obsidian 18.0.81 on Ubuntu 24.04.
- Outgoing port 25 open, so email from the server can reach
t.email-spam-tester.com. Many VPS providers block it by default. - Outgoing HTTPS to
email-spam-tester.com.
You can check both before installing. The first command should print a line that starts with 220, the second should print 200:
timeout 10 bash -c 'exec 3<>/dev/tcp/t.email-spam-tester.com/25 && head -1 <&3'
curl -s -o /dev/null -w '%{http_code}\n' https://email-spam-tester.com/health
2. Install
Log in over SSH as root. Download the extension and its checksum:
cd /root
curl -fsSLO https://email-spam-tester.com/plesk/latest.zip
curl -fsSLO https://email-spam-tester.com/plesk/latest.zip.sha256
Check that the download is intact. You should see latest.zip: OK. If you see FAILED, download again and do not continue:
sha256sum -c latest.zip.sha256
Install it:
plesk bin extension --install /root/latest.zip
The last line should be The extension was successfully installed.
3. Register the server
In Plesk, go to Tools & Settings › Mail › Email Spam Tester and press Register this server. You can leave an email address for notices about the service; it is optional.
Registration sends the server's hostname, the Plesk and extension versions, the number of subscriptions and that email. The answer is a key that stays on this server, encrypted in the extension's settings; customers never see it.
Customers find Email Spam Tester in Websites & Domains › a domain › Mail; until the server is registered it only tells them to ask you.
4. Choose who gets what
In Service Plans › a plan › Permissions (and in each subscription's own permissions) the extension adds four permissions, all on by default:
- Email Spam Tester: the extension itself;
- fix DNS and mail settings: the DKIM, SPF and DMARC buttons. DNS buttons also need the plan's own permission to manage DNS, and the DKIM switch its permission to manage mail settings;
- folder check: sending a copy to test mailboxes at email providers;
- constant monitoring: switching monitoring on for a domain.
Limits per subscription (tests, folder checks, AI plans, monitored domains, monitored emails per domain a day) are on the same Tools & Settings › Mail › Email Spam Tester page.
5. Constant monitoring (optional)
Nothing is copied until you allow it and a customer switches it on for their domain. On the extension's page in Tools & Settings, press Allow constant monitoring on this server. This adds:
- a Plesk mail handler that runs after DKIM signing for outgoing email, passes every message through unchanged and, for domains switched on, hands a copy to
- a Postfix listener on
127.0.0.1:10597that accepts only Email Spam Tester's monitoring addresses, so the copy leaves from the same IP and HELO as the original; - the list of monitored domains in
/etc/email-spam-tester/monitor.json.
The same page has Disable on the whole server, which removes all three and switches every domain off.
To see where it stands from the command line:
/usr/local/psa/admin/sbin/modules/email-spam-tester/est-monitor status
"state": "active" means it is on; "off" means it was never allowed or has been removed; "partial" means a piece is missing (Plesk sometimes rewrites Postfix's master.cf on an update), and Repair on the same page puts it back. A daily task does the same on its own.
6. Upgrade
Download the new latest.zip and its checksum as in step 2, check it, then:
plesk bin extension --upgrade /root/latest.zip
The registration, limits and monitoring stay as they were; if monitoring is on, its files are brought up to the new version.
7. Uninstall
plesk bin extension --uninstall email-spam-tester
This takes monitoring out of Postfix and Plesk's mail handlers and switches every monitored domain off. It never touches DNS records, including the ones customers created with the extension's buttons.
If monitoring was on, it is worth taking it out first, so that a failure there is visible rather than only in Plesk's log:
/usr/local/psa/admin/sbin/modules/email-spam-tester/est-monitor disable
It prints the state at the end; "state": "off" means the handler, the listener and the list are gone.
8. If something does not work
- "The mail server did not accept the email" on a test: the local Postfix refused it, and the text after the colon is its own answer. Check that Postfix is running (
systemctl status postfix). - A test waits and nothing arrives: after 30 seconds the test page shows what the server's mail log says about it. A connection to port 25 that times out means your provider blocks outgoing port 25; run the first check from step 1 to confirm.
- A fix shows a record to copy instead of a button: the domain's DNS is served by another server (a registrar or Cloudflare); add the record there.
- Right after a DNS fix, a test still shows the old result: public DNS resolvers may remember that a record was missing for as long as the zone's SOA minimum TTL (three hours in Plesk's default zone template). Test again later.