Skip to content
AI Website Security
Urgency

When your host suspends the site

Where your site used to be, a page from your host; in your inbox, an email announcing a suspension. Everything that follows depends on one thing alone: the reason written in that email. It states what the host saw, and therefore what it expects before reopening. Here is the full order of steps, including those that happen without us — and the one item that shortens the exchange more than anything else: a dated report your host can verify on its own, without having to take our word for it.

What your host saw

A host suspends an account to protect the other accounts on the same machine, the reputation of its sending addresses, and its own. Four reasons come up again and again. Each calls for a different response, and the first task is to work out which one applies.

Mail

A mass mailing sent from the account

This is the most urgent concern for a hosting provider: the mail leaves their machines, and it's their own sending addresses that end up blocklisted elsewhere — so it's their other customers' mail that stops getting through. They want two things: the sending to stop, and for you to identify where it was coming from. An uploaded file, a contact form left open as a relay, a mailbox whose password is circulating: these are three different origins, and three different responses.

Resources

Unusually high resource consumption

Processor, memory, database queries: the account has exceeded what the machine can give to others. The cause falls into three categories, and the distinction determines everything that follows. An added file working for someone else. A surge of bots on expensive pages. Or your own site, grown heavy as it expanded — in which case the pattern looks like an intrusion and turns out to be a technical matter.

Report

A report received from a third party

A search engine, an antivirus vendor, a bank, a customer: someone wrote to your host before you did. Ask for a copy of it in your very first reply. A report almost always carries a specific address and a date, and those two elements are exactly what frames the investigation: they tell you where to look and from when.

Platform analysis

A file identified by the platform analysis

The host runs its own tools across the accounts it hosts, and one of them flagged a file. The report gives its full path and a date: that's a valuable starting point. It rarely gives the full extent. A flagged file is often accompanied by others, written for your site alone, that no signature match has ever encountered.

The order of steps, from the email to going back online

This order exists for a reason: each step protects the next. Asking for access before you've read the reason means asking for the wrong thing; cleaning up before you've made a copy means losing the evidence the host will ask for next.

Read exactly what the host wrote

The reason drives everything else: the response to an outgoing email issue has nothing in common with the response to an abuse report. From the email, note the date and time of the suspension, the exact reason in their own words, the file paths cited, the address to reply to, and the deadline if they state one. Answering beside the point is what drags the exchange out the most.

Ask for the evidence they saw

In reply, in a single short, specific request: a copy of the report, the matching log lines, the analysis report with full paths, the headers of an offending email. These items already exist on their side — they're what prompted the decision. They're worth hours of blind searching, and asking for them shows straight away that you're on the case.

Get read access with the site closed

A suspension closes the door to visitors; access to files, the database and the logs is often retained. Ask for it explicitly, for the time it takes to establish what happened. The request works in the host's favour: what they want is a substantiated answer rather than a promise. Failing that, ask at least for an archive of the current state of the files and the database.

Copy everything before touching anything

Files and database, in their current state, on separate storage. That state, however damaged, is the only material that will let you date what happened and later respond to the host, a client, or an insurer. Cleaned up first, it is gone for good—and with it half the answers the host is about to ask for.

Establish what changed, file by file

A path cited by the host is an entry point, rarely the full inventory. This is where the human eye reaches its limit: a live site carries tens of thousands of files, and the one that was added looks just like its neighbours. The question that can actually be answered is the reverse: how many files can account for their presence, and which ones cannot? Our analysis compares your site against the authentic code published by its vendors, and names each discrepancy with its date and location.

Respond with evidence the host can verify

A response that simply asserts "it's fixed" looks like every other one, and gets handled like every other one. A response that includes a dated, signed assessment—whose signature the recipient can verify independently on their end—is a different matter entirely: it shortens the exchange far more than any assertion, because it gives the person you're dealing with something to justify the reopening in their own file.

Request reinstatement by addressing their stated reason

Write briefly, in their terms: the reason exactly as they stated it, what was found, what was done, on what dates. Attach the assessment and the certificate of the resulting state. Close with what keeps the door shut going forward: access regained, versions restored to their original code, monitoring in place. A host reopens when it can put in writing why it reopened.

Free verification, for everyone and forever

The document is verified on our site, by your host itself

That is the point of this page. Each of our documents carries a signature, and anyone can check it on our verification page: your host, your client, your insurer. Free of charge, with no account, and forever. Your correspondent no longer has to believe you — they can see for themselves. That, and only that, is what makes a document hold up.

Why is verification free when the analysis is paid? Because they are two opposite things. A free analysis would almost always answer "nothing found": the expected good news, given without proof, to people who didn't need it. We sell certainty, not worry. Verification, on the other hand, is only worth something if everyone can carry it out, including those to whom we will never sell anything.

Concretely, your response to the host carries three signed documents: the report — what was observed, what was done, on these dates —, the attestation of the resulting state, and the document produced to be handed to a third party. The report states; the attestation commits; verification, in our case, settles the matter.

What you receive, and what it costs

One price per site, once. The analysis asks each file to justify its presence, compared with the authentic code published by its publisher; the rest is named, with its date and location.

The findings

Record — €99 per site

The complete diagnosis: the exact number, each file named, the dating, the likely entry point. And the three signed documents — the report, the attestation of the resulting state, and the document handed to a third party, the one your host will verify on their side.

The report and the action

Record + Restore — €199 per site

Everything above, plus the restoration action: it is verified after the fact, and it cancels itself if the site stops responding. A fresh scan follows, turning the findings into a restoration certificate — the document your host expects in order to reopen.

After reopening

A reopened account sometimes closes a second time, through the same door, because the door was left open. What changes the outcome comes down to one sentence: knowing the same day that an executable file has moved, rather than learning it from a suspension email. Monitoring states things precisely: when the certificate breaks, it announces that this site differs from the one that was certified. Your own deployment breaks it the same way — we re-certify after every deployment, and a break with no deployment warrants a close look. Watch, €99 per site per year; with the restoration action, €199.

One caveat, written here as it is on every document: a fully accounted-for site is one in which every file has been accounted for — which is already a great deal, and remains something other than a secure site. A stolen password, or an up-to-date but vulnerable extension, stays beyond the reach of a file comparison, and is stated as such to your host.

What your host expects comes down to a single dated document

The exact number, every file named, the probable date, and three signed documents whose signature it can verify itself, free of charge.

aiwebsitesecurity · aiwebsitesecurity · aiwebsitesecurity ·