I've recently upgraded to 4.20 and found that I received some emails last night from the shop email account (which is not shown anywhere on the website. It appears that a registration was done, however not confirmed, so user is not active, but within seconds of registering has been able to send 3 spam emails which appear in the email queue.
How does this happen and is there something I can do to prevent it happening again?
Would you be more specific as to the type of "spam" you received? (From / To / Subject)
If you have these templates set up: Customer.WelcomeMessage Customer.EmailValidationMessage and the customer registers with a bogus email, the other email server could reject as 'undeliverable'.
Also, without regards to registration, a spammer could use Contact Us page to send you spam.