Articles in this section

Plesk user can't reset password: user may intercept mail sent to the domain

kb: bug Plesk for Windows Plesk for Linux

Applicable to:

  • Plesk for Linux
  • Plesk for Windows

Symptoms

  • Resetting the password with the Forgot your password button on the login screen displays a green confirmation message, but the user never receives the reset link
  • This error is logged to /var/log/plesk/panel.log on Linux or %plesk_dir%admin\logs\php_error.log on Windows:

    ERR [panel] Password reset request for email 'jdoe@example.com' (user 'user') was denied: user 'mail@example.com' may intercept mail sent to the domain 'example.com'

  • The mail service is disabled for the user's email domain in Domains > example.com > Mail Settings

Cause

This behavior is caused by a product issue: PPPM-12991

If there is no mail server and MSMTP is used, it may be PPP-53183 instead.

Resolution

To work around this issue, the admin can reset the password for the user, or the user can change the email address used for one with a different domain.

Reset Password

Forward these steps to the Plesk administrator to get the password reset.

  1. Log in to Plesk
  2. Go to the appropriate user settings depending on the type of user account:
    • Subscriptions > example.com > Users > john.doe
    • Customers > John Doe
    • Resellers > John Doe
  3. Enter the desired password (or click on Generate to get a new one)
  4. Press OK to save the changes and send the new password to the user if necessary.
Change User Email

The Plesk administrator can update the email used on the account to one that is not hosted by Plesk (e.g. from example.com to gmail.com). This will allow password reset links to leave the server.

  1. Log in to Plesk
  2. Go to the appropriate user settings depending on the type of user account:
    • Subscriptions > example.com > Users > john.doe
    • Customers > John Doe
    • Resellers > John Doe
  • Update the email in the email field
  • Press OK to save the changes

The user can now request a reset link.

Was this article helpful?

Comments

4 comments
Date Votes
  • Das Plesk nutzt nur Relay Server ohne E-Mail Server im Plesk, da die E-Mails auf einem externen System liegen.

    Der Kunde hat nur diese Domain.

    Der Workarround ist nicht nutzbar.

    Aber auch wenn man beim User eine Externe E-Mail Adresse einträgt kommt dieser Fehler :-(

    0
  • This is not acceptable as workaround

    2
  • This is a fairly significant bug; almost none of our customers use Plesk for email anymore, so none of them can use password reset.

    2
  • Please allow an option to disable this “feature”.  It's very frustrating to see a success message on screen and an error message in the logs. 

    0

Please sign in to leave a comment.