Key highlights
- Enable SpamAssassin in cPanel to activate the free spam filter included with your shared hosting, since it’s off by default.
- Set your spam threshold and review the Spam Box regularly, so legitimate emails don’t get auto-deleted by mistake.
- Create global or account-level filters to block specific senders and sort mail automatically, without changing individual inbox settings.
- Upgrade to SpamExperts for domain-wide filtering at the MX level, if a single mailbox’s spam filter isn’t catching enough.
- Separate spam filtering from email deliverability, since one controls your inbox and the other depends on SPF, DKIM and DMARC.
Your business inbox is filling up with junk mail every week, and somewhere in that pile could be a client reply or an order confirmation you never saw. Email spam protection on shared hosting doesn’t require third-party software or a plugin. Most shared hosting accounts already include a spam filter. It just isn’t turned on by default.
This guide walks you through what’s included on your account, how to enable and configure it in cPanel, when a free filter isn’t enough and why some spam problems have nothing to do with filtering at all.
What email spam protection is available with Bluehost shared hosting
Most people assume spam protection is either fully active or missing entirely. On shared hosting, it’s usually a third option: installed but waiting for you to turn it on.
Bluehost shared hosting accounts include SpamAssassin, an email spam filter built into cPanel’s email tools. It scores incoming messages against known spam patterns and flags anything that crosses your threshold. The filter ships with every account, but it doesn’t run until you enable it manually. Until then, spam lands in your inbox the same as everything else.
Some accounts also include a Spam Box, a separate folder where flagged mail gets routed instead of deleted. Whether you use it depends on how you configure the filter next.
If you’ve never opened the Email menu in cPanel, there’s a good chance this filter has been sitting inactive since your account was created.
Also read: SpamAssassin Filters for Email Hosting Spam Protection
How to enable and configure SpamAssassin in cPanel
A spam filter sitting inactive doesn’t help you at all, and that’s the state most shared hosting accounts start in. Enabling it takes three settings, and each one is worth understanding before you turn it on.
Setting 1: Turn on spam filtering
Nothing gets filtered until this is switched on, no matter how good the underlying filter is.
- Log in to your hosting account and open the Email menu in cPanel.
- Select Spam Filters, then click Continue to open the settings page.
- Turn on “Process New Emails and Mark Them as Spam.”
- Turn on “Move New Spam to a Separate Folder (Spam Box)” so flagged mail stays out of your main inbox.
- Save your changes.
Setting 2: Set your spam threshold score
Too loose a threshold lets spam through. Too strict, and legitimate emails start getting flagged by mistake.
- Open Spam Threshold Score on the same settings page.
- Choose a number. Lower scores filter more aggressively, higher scores let more through.
- Save with Update Scoring Options.
Pro tip: Start at a moderate threshold and adjust after a week of watching what actually lands in your Spam Box, instead of guessing at the strictest setting from day one.
Setting 3: Review and manage your Spam Box
Flagged mail doesn’t disappear, it moves. If you never check that folder, a real message can sit there unnoticed indefinitely.
- Check your Spam Box on a set schedule, not just when something seems to be missing.
- Whitelist senders you trust instead of lowering your threshold across the board.
- Leave auto-delete off unless you’re confident in your filter’s accuracy, since deleted spam can’t be recovered.
- In webmail, subscribe to the spam folder so flagged mail shows up there too.
How to set global and account-level email filters
A spam score catches obvious junk, but it won’t stop every unwanted sender and it can’t tell your inbox to treat one address differently than another. Filters handle what scoring alone misses.
1. Create a global email filter
A rule set at the domain level applies to every mailbox on it, so you’re not repeating the same setup across multiple accounts.
- Open the Email menu in cPanel and select Global Email Filters.
- Click Create a New Filter and name it something you’ll recognize later.
- Set a rule based on sender, subject or a keyword in the message.
- Choose an action: discard, redirect or stop processing.
- Save the filter.
2. Create an account-level filter
Some rules only make sense for one address, like a support inbox that needs stricter filtering than your personal one.
- Open Email Filters and select the account you want to configure.
- Click Manage Filters, then Create a New Filter.
- Set your rule and choose an action.
- Save the filter.
Pro tip: Test a new filter with “Redirect” before switching it to “Discard,” so you can confirm it’s catching the right messages before anything gets deleted automatically.
3. Blacklist and whitelist senders
A spam score can misjudge a sender you trust, or let through one you’ve already flagged as unwanted and this overrides that judgment directly.
- Add a sender or domain to your blacklist. This works as a direct email spam blocker and marks their mail as spam regardless of score.
- Add a trusted sender to your whitelist so their mail bypasses filtering entirely.
- Update both lists as your regular contacts change, since a stale whitelist stops protecting you.
When to upgrade to SpamExperts for domain-wide protection
SpamExperts is a spam filtering service that works at the domain level instead of mailbox by mailbox. SpamAssassin filters one mailbox at a time, based on scoring rules you set yourself. If you’re running multiple email accounts on one domain, or spam volume keeps climbing past what a threshold adjustment can fix, that per-mailbox limit becomes the actual problem.
SpamExperts filters at the domain level instead. Once activated, it updates your MX records and routes all incoming mail through its filtering system before it reaches your server, so every mailbox on the domain gets covered by one configuration instead of several separate ones. Flagged messages go to a quarantine you can review through your own SpamPanel, rather than a spam folder inside each inbox.
It’s available as a paid add-on from your hosting dashboard’s Marketplace, not something you configure inside cPanel.
Spam filtering vs. email deliverability: What each one actually controls
A spam filter and a deliverability problem look identical from the inbox: mail that should have arrived didn’t. But they sit on opposite ends of the same conversation.
Spam filtering controls what happens to mail that reaches your inbox. SpamAssassin and SpamExperts both work on incoming mail. Each one decides what gets through and what gets flagged. Neither one touches anything you send.
Deliverability is about your outgoing mail reaching someone else’s inbox, a separate layer of email protection from filtering. It depends on your sending domain’s reputation. It also depends on which servers are authorized to send on your behalf. Receiving providers like Gmail and Outlook then decide whether to trust the message enough to skip their spam folder. Three DNS records govern this. SPF lists which servers can send for your domain. DKIM adds a signature that proves the message wasn’t altered in transit. DMARC sets what happens when a message fails either check.
Shared hosting environments run multiple domains on the same IP address. If another account on that IP gets flagged for sending spam, every domain on the same IP can see delivery rates drop. That happens independent of anything you’ve configured on your own account. Tightening your spam filter doesn’t fix this. The problem isn’t what’s landing in your inbox, it’s what’s failing to land in someone else’s.
If your own mail is going to spam for other people, check your SPF, DKIM and DMARC records first. If your inbox is the one filling with junk, that’s what the filtering steps above are for.
Final thoughts
Spam protection on shared hosting isn’t complicated. It’s just often left off. Turning on your filter, tuning the threshold and checking your Spam Box on a schedule closes most of the gap. Add SpamExperts if you’re managing more mailboxes than one filter can reasonably cover. Check your SPF, DKIM and DMARC records if the problem is on the outbound side instead.
Manually managing every layer of email and account security eats into time you’d rather spend running your business. Get started with Bluehost Web Hosting plans, where spam filtering, SSL and malware scanning are included on every plan, not add-ons you configure separately.
FAQs
Yes. SpamAssassin comes with every shared hosting account through cPanel’s Email menu. It isn’t active until you turn it on, so check your Spam Filters settings if you haven’t configured it yet.
The filter ships inactive by default. Enabling it takes three settings: turning on spam processing, setting your threshold score and routing flagged mail to a Spam Box. None of that happens until you configure it in cPanel.
SpamAssassin filters one mailbox at a time based on a threshold you set. SpamExperts filters at the domain level, covering every mailbox on that domain through a single configuration and it’s a paid Marketplace add-on rather than a built-in cPanel tool.
Spam filters control incoming mail, not outgoing. If your own messages are landing in other people’s spam folders, that’s a deliverability issue tied to your SPF, DKIM and DMARC records, not something a spam filter setting can fix.
Check your Spam Box first, since flagged mail moves there rather than getting deleted, unless auto-delete is turned on. If it’s not there, the sender’s domain may need to be added to your whitelist to prevent it from happening again.

Write A Comment