Troubleshooting Delivery Issues

Fixing Exim 421 Error: Causes and Solutions

By the Domain India teamPublished 9 min read
Knowledge base article
Contents (9 sections)

An SMTP "421" reply means "service not available, try again later". It is a temporary refusal: the mail is not lost, and a correctly configured server keeps it in the queue and retries. This guide is for administrators of their own server or VPS running the Exim mail server, such as a cPanel or DirectAdmin server. It shows how to find out who sent the 421 and why, and how to fix the common causes.

Key takeaways

First read the log to see which side sent the 421. If a remote server (Gmail, Outlook, another host) sent it, you are being rate-limited or distrusted: check blocklists, reverse DNS, SPF, DKIM and DMARC, and look for a spamming script or mailbox. If your Exim sent it to a client, it is protecting itself from too many connections or high load: find the cause before raising limits. On Domain India shared hosting you can't change Exim; check your sending limits and open a ticket instead.

Own-server guide

Every command here needs root access on a server you run. On shared hosting you cannot view the server's mail log, change Exim or restart services. If you use Domain India shared hosting, go to section 8.

1. What a 421 is, and what it is not

SMTP replies starting with 4 are temporary; replies starting with 5 are permanent. A 421 also closes the connection, and the sending server retries later, usually for several days before it bounces the message. One 421 is not a lost email; a long run of them means something is wrong with reputation, load or configuration. The text after the code gives the reason, often with an enhanced code such as 4.7.0 (policy or reputation).

2. Find the 421 in your log

The main Exim log is /var/log/exim_mainlog on cPanel servers and /var/log/exim/mainlog on DirectAdmin servers. Search it:

bash
# cPanel
grep " 421 " /var/log/exim_mainlog | tail -n 30
# DirectAdmin
grep " 421 " /var/log/exim/mainlog | tail -n 30

Then follow one message from start to end with its ID:

bash
exigrep 1uAbCd-0001Xy-2Z /var/log/exim_mainlog

Two patterns tell you which side is refusing:

What the log showsWho sent the 421Go to
SMTP error from remote mail server after ...: 421 ...The receiving server refused your mailSections 3 and 4
Your server's own reply, such as "Too many concurrent SMTP connections"Your Exim refused a client or another serverSections 5 and 6

3. A remote server sent the 421: reputation and rate limits

Large mailbox providers answer 421 when mail from your IP or domain looks risky, or arrives faster than they accept from you. Common reasons:

  • Your IP is on a blocklist. Check it with a public multi-blocklist checker such as MXToolbox. For a manual check, reverse the IP's four parts: for 203.0.113.10, look up 10.113.0.203.zen.spamhaus.org. Spamhaus refuses queries sent through large public resolvers, so run it from a server with its own resolver, and treat an answer of 127.255.255.254 as "query blocked", not "listed".
  • Missing or wrong reverse DNS. The IP's PTR record should name your server's hostname, and that hostname should resolve back to the same IP. Check with dig -x 203.0.113.10 +short. PTR records are set by whoever owns the IP, usually your hosting provider.
  • Missing authentication. Gmail, Yahoo and Outlook expect SPF, DKIM and DMARC on the sending domain, and bulk senders must have all three.
  • Too much mail too fast, from a newsletter or a new IP with no sending history.

Check the domain's DNS records:

bash
dig +short TXT example.com                 # SPF: v=spf1 ...
dig +short TXT _dmarc.example.com          # DMARC: v=DMARC1; p=...
dig +short TXT default._domainkey.example.com   # DKIM on cPanel (selector "default")
dig +short TXT x._domainkey.example.com         # DKIM on DirectAdmin (selector "x")

A simple SPF for a server that sends its own mail is v=spf1 a mx ip4:203.0.113.10 ~all. Add an include: for any other service that sends as your domain, and keep one SPF record per domain. Send a test to a checker such as mail-tester.com to see all three results at once.

4. Find and stop the source of bad mail

Most sudden 421s from Gmail or Outlook follow a spam run from the server itself: a hacked mailbox, or a PHP script abused through a contact form. Look at what is in the queue and who sent it:

bash
exim -bpc                       # how many messages are queued
exim -bp | exiqsumm | sort -rn | head    # top recipient domains

On cPanel, this well-known one-liner lists the folders that PHP scripts sent mail from, with a count:

bash
grep "cwd=" /var/log/exim_mainlog | grep -v /var/spool | \
  awk -F"cwd=" '{print $2}' | awk '{print $1}' | sort | uniq -c | sort -rn | head

For mailboxes, count logins used to send (A=dovecot_login: on cPanel) in the log. Change the password of any compromised mailbox, fix or remove the abused script, then clean the spam out of the queue with the commands in Managing the Exim mail queue. Only then request delisting from any blocklist, or it will happen again.

5. Your Exim sent the 421: too many connections

Exim refuses new connections with a 421 when a limit is reached. The reply text names the limit:

Exim replySetting that caused it
Too many concurrent SMTP connections; please try again latersmtp_accept_max (all clients together)
Too many concurrent SMTP connections from this IP address; please try again latersmtp_accept_max_per_host
Too much load; please try again latersmtp_load_reserve (server load is too high)

Before you raise a limit, ask why so many connections arrive: one IP opening dozens is often an attack or a misbehaving app, so block it in your firewall instead. Check current values with exim -bP smtp_accept_max smtp_accept_max_per_host smtp_load_reserve.

If the traffic is legitimate, change the value the way your panel expects, because both panels rebuild /etc/exim.conf and overwrite hand edits:

  • cPanel: WHM › Exim Configuration Manager › Advanced Editor.
  • DirectAdmin: put the setting in /etc/exim.variables.conf.custom, then rebuild the configuration with CustomBuild (./build exim_conf in /usr/local/directadmin/custombuild).

6. Server load, disk and spool permissions

If the reply mentions load, or Exim stops accepting mail altogether, check the server itself:

bash
uptime                 # load average
df -h /var             # a full disk stops the mail spool
ss -tlnp | grep -E ':(25|465|587) '   # Exim listening on the SMTP ports

The spool directories must belong to the user Exim runs as, which depends on the panel (for example mailnull on cPanel and mail on DirectAdmin). Confirm it rather than guessing:

bash
exim -bP exim_user exim_group
ls -ld /var/spool/exim /var/spool/exim/input

If ownership changed, for example after restoring files as root, set it back to that user and group. Then restart Exim with systemctl restart exim and watch the panic log, /var/log/exim_paniclog on cPanel or /var/log/exim/paniclog on DirectAdmin.

7. When the problem is outbound port 25

If messages to other servers time out instead of getting a 421, your server cannot reach port 25 at all. Test with nc -vz gmail-smtp-in.l.google.com 25. Check your firewall's outgoing rules (in CSF: TCP_OUT and SMTP_BLOCK in /etc/csf/csf.conf), and ask your provider whether outgoing port 25 is open on the network.

8. On Domain India hosting

Shared hosting (cPanel, DirectAdmin, Webuzo): the mail server is managed by us, so none of the commands above apply. The usual cause of refused sending on shared hosting is the account's sending limit: 200 messages per hour per account on cPanel and 1,000 per day on DirectAdmin. See I can receive mail but I cannot send it, and open a ticket with the full bounce message if mail still won't go.

Your own server: a Domain India VPS is self-managed with full root access. The DirectAdmin panel option uses Exim, so this guide applies to it directly.

Frequently asked questions

What does SMTP error 421 mean?

421 means the mail service is temporarily unavailable and the connection is being closed. It is a temporary error, so the sending server keeps the message and retries. The text after the code explains the reason, such as rate limiting, too many connections or high load.

Will my email be lost after a 421 error?

Not straight away. The sending server queues the message and retries, usually for several days, before it gives up and returns a bounce to the sender. Fix the cause so the retries succeed.

Why does Gmail return 421 for mail from my server?

Usually because mail from your IP or domain looks risky: the IP is on a blocklist, reverse DNS is missing, SPF, DKIM or DMARC fail, or the server recently sent spam. Fix authentication and stop any spam source, then Gmail accepts mail again over time.

How do I fix "Too many concurrent SMTP connections" in Exim?

Find out who opens the connections first; one IP opening many is often an attack, which you should block in the firewall. If the traffic is legitimate, raise smtp_accept_max or smtp_accept_max_per_host through WHM's Exim Configuration Manager on cPanel, or exim.variables.conf.custom on DirectAdmin.

Can I fix an Exim 421 error on shared hosting?

No. On shared hosting the provider manages Exim. On Domain India shared hosting, check the sending limit of 200 messages per hour per account on cPanel or 1,000 per day on DirectAdmin, and open a support ticket with the full bounce message.

Should I delete the whole mail queue to fix a 421?

No. Deleting the queue also removes legitimate mail waiting for a retry. Remove only spam or frozen messages from a known bad sender, after you have stopped the source.

Ready to go further? Clean up stuck mail with Managing the Exim mail queue, or see VPS plans if you want your own mail server.

Mail refused on your hosting?

Send us the full bounce or error message and the address you sent from, and we will check the mail server logs for you.

Open a support ticket

Ready when you are

Get Business Email from ₹60/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Exim 421 Error: Causes and Fixes | Domain India