Troubleshooting Delivery Issues

The Ultimate Comprehensive Guide to Mastering EXIM: Complete Handbook

By the Domain India teamPublished 9 min read
Knowledge base article
Contents (10 sections)

Exim is the mail transfer agent (MTA) that accepts, routes and delivers email on most cPanel and DirectAdmin servers, and on many Debian-based systems. This handbook is the starting point for administrators who run Exim on their own server or VPS: how it is laid out, the settings that matter, how to check a change before it goes live, and where to go for queues, errors and spam control.

Key takeaways

Exim reads one main configuration, split into main settings, ACLs, routers and transports. On cPanel you change it only through WHM's Exim Configuration Manager; on a plain server you edit the file, check it with exim -bV, test with exim -bt and exim -bh, then reload. Deliverability comes from DNS (SPF, DKIM, DMARC, reverse DNS), with DKIM signing set on the SMTP transport. Keep Exim patched, never run an open relay, and read the main log before you change anything.

Own-server guide

Everything here needs root access on a server you run. On Domain India shared hosting (cPanel, DirectAdmin, Webuzo), the mail server serves every account on the machine, so customers can't change Exim, read its logs or restart it. If you are on shared hosting, go to section 9.

1. What Exim does, and where it lives

Exim does three jobs: it receives mail over SMTP, decides where each message should go, and delivers it, either to a local mailbox or to another server. When a delivery can't happen straight away, the message waits in the queue and Exim retries.

The layout depends on how you installed it:

SetupMain configurationMain logService name
cPanel & WHM/etc/exim.conf, generated by cPanel/var/log/exim_mainlogexim
DirectAdmin/etc/exim.conf, managed by CustomBuild/var/log/exim/mainlogexim
Debian or Ubuntu/etc/exim4/, built by update-exim4.conf/var/log/exim4/mainlogexim4
AlmaLinux or Rocky Linux (EPEL)/etc/exim/exim.conf/var/log/exim/main.logexim

Check the version and build options with exim -bV. It also parses the configuration, so it is the first test after any edit.

2. Installing Exim on a plain server

Debian and Ubuntu ship Exim as exim4:

bash
sudo apt update && sudo apt install exim4-daemon-heavy
sudo dpkg-reconfigure exim4-config    # choose "internet site" for a server that sends and receives

AlmaLinux and Rocky Linux use Postfix by default, and Exim comes from EPEL:

bash
sudo dnf install epel-release
sudo dnf install exim
sudo systemctl disable --now postfix
sudo alternatives --set mta /usr/sbin/sendmail.exim
sudo systemctl enable --now exim

Only one MTA should listen on port 25. On a cPanel or DirectAdmin server, Exim is already installed and managed by the panel: don't install another copy.

3. The settings that matter

The main section sets who the server is and what it will accept. These are real Exim options, shown with safe values:

text
primary_hostname = mail.example.com
domainlist local_domains    = @ : example.com
domainlist relay_to_domains =
hostlist   relay_from_hosts = localhost

tls_certificate = /etc/ssl/mail/fullchain.pem
tls_privatekey  = /etc/ssl/mail/privkey.pem
tls_advertise_hosts = *
auth_advertise_hosts = ${if eq{$tls_in_cipher}{}{}{*}}

message_size_limit = 25M
smtp_accept_max = 100
smtp_accept_max_per_host = 10
  • primary_hostname must match the server's reverse DNS (PTR) record, or many receivers will distrust your mail.
  • Keep relay_from_hosts to localhost unless you really run a smarthost for other machines. Adding a whole network range is how open relays happen.
  • auth_advertise_hosts as shown offers SMTP login only after TLS starts, so passwords never cross the network in clear text.

On cPanel, don't edit /etc/exim.conf: cPanel rebuilds it and your change disappears. Use WHM's Exim Configuration Manager, as explained in enhancing email security with Exim Configuration Manager. On DirectAdmin, put changes in the custom files that CustomBuild keeps across updates, not in the generated file.

4. Check before you reload

Exim gives you three tests that catch almost every mistake before real mail is affected:

bash
exim -bV                          # parses the config; an error here means do not reload
exim -bt [email protected]         # shows which router and transport a recipient would use
exim -bh 203.0.113.10             # runs a fake SMTP session "from" that IP, showing every ACL decision
exim -bP message_size_limit       # prints the current value of any option

Reload only when exim -bV is clean: systemctl reload exim (or exim4). Keep a copy of the working file so you can roll back.

5. SPF, DKIM and DMARC

Most of email authentication lives in DNS, not in exim.conf:

  • SPF is a TXT record listing the servers allowed to send for your domain, for example v=spf1 a mx ip4:203.0.113.10 -all.
  • DKIM signs each outgoing message. In Exim you set it on the SMTP transport that sends to other servers:
text
remote_smtp:
  driver = smtp
  dkim_domain      = ${lc:${domain:$h_from:}}
  dkim_selector    = mail
  dkim_private_key = /etc/exim/dkim/${dkim_domain}.key
  dkim_canon       = relaxed

Publish the matching public key as a TXT record at mail._domainkey.example.com. cPanel and DirectAdmin manage DKIM keys for you.

  • DMARC is a TXT record at _dmarc.example.com. Start with v=DMARC1; p=none; rua=mailto:[email protected], read the reports for a few weeks, and only then move to quarantine or reject. Jumping straight to reject can block your own legitimate mail.

For the full DNS side, see the SPF, DKIM and DMARC guide and setting up DMARC.

6. Logs and the mail queue

The main log records every message: <= arrival, => delivery, -> extra recipient, ** permanent failure, == deferred. The fastest way to follow one message is exigrep:

bash
exigrep '[email protected]' /var/log/exim_mainlog | tail -50
eximstats /var/log/exim_mainlog > /tmp/mail-report.txt

For the queue, exim -bpc counts messages, exim -bp | exiqsumm summarises them, and exiqgrep selects them by sender, recipient or age. Retry one message with exim -M ID. Use exim -qff only when you mean to force every message, frozen ones included. Full guides: managing the Exim mail queue and clearing a queue after a spam run.

7. Common errors

CodeMeaningWhere to start
421Temporary refusal; the connection is closed and the sender retriesFind which side sent it; see fixing Exim 421
451Temporary local problem, often DNS lookups, greylisting or a busy spoolRead the log line for the reason; check DNS resolution and disk space
550 relay not permittedThe sender did not authenticate, or the domain is not yours to relayMake the mail client use SMTP authentication over TLS
550 or 554 from a remote serverRejected as spam, blocklisted IP or failed authenticationCheck blocklists, PTR, SPF, DKIM and DMARC

For bounce messages in plain words, see understanding email bounce-backs.

8. Security and spam control

Never be an open relay
Relay only for authenticated users and localhost. Test from outside after every change.
Rate-limit senders
Use the ratelimit ACL condition to cap messages per authenticated user or per host, so one hacked mailbox can't flood the queue.
Filter at SMTP time
DNS blocklists and HELO checks in the RCPT ACL stop most junk before it is accepted; see custom Exim ACLs.
Scan content
Connect SpamAssassin or Rspamd and ClamAV through the DATA ACL, and tune scores against your own mail.
Keep Exim patched
Exim has had serious remote-code-execution bugs. Install updates promptly from your OS or panel vendor.
Watch the log
A sudden jump in outgoing mail from one user or script is the usual sign of a compromise.

On a DirectAdmin server, Easy Spam Fighter and Rspamd do much of this for you; see Easy Spam Fighter and Rspamd in DirectAdmin.

9. Exim at Domain India

Shared hosting. Our cPanel and DirectAdmin servers run Exim, managed by us for every account on the server. You can't change it, but you control your own side: SPF, DKIM (on by default for new cPanel accounts), mail filters and your mail client settings. Outgoing mail is limited to 200 messages per hour per account on cPanel and 1,000 per day (200 per mailbox by default) on DirectAdmin. If mail won't send, see I can receive mail but I cannot send it, or open a ticket with the address and the bounce message.

VPS. A Domain India VPS is self-managed with root access, so you can install and configure Exim as in this guide. Before you plan a mail server, ask support about outbound port 25 and setting reverse DNS (PTR) for your IP; both matter for delivery. See setting up a mail server on a VPS and troubleshooting SMTP relay on a VPS.

Just need business email? Business Email gives you mailboxes on your own domain without managing an MTA. The price on the card is a Domain India list price, excluding 18% GST.

Business Email
₹60/mo + GST
  • Priced per mailbox - start with one
  • Email at your own domain ([email protected])
  • Add and remove mailboxes yourself
  • Webmail with calendar, contacts and tasks
See plan details

Frequently asked questions

How do I check that my Exim configuration is valid?

Run exim -bV. It parses the configuration and reports any error before you reload. Then test routing with exim -bt and an address, and a full SMTP session with exim -bh and an IP address.

Can I edit /etc/exim.conf on a cPanel server?

No. cPanel regenerates the file and overwrites manual edits. Make changes through WHM's Exim Configuration Manager, which keeps them across updates.

Where are the Exim logs?

On cPanel servers the main log is /var/log/exim_mainlog. On DirectAdmin it is /var/log/exim/mainlog, and on Debian or Ubuntu it is /var/log/exim4/mainlog.

How do I enable DKIM in Exim?

Set dkim_domain, dkim_selector and dkim_private_key on the SMTP transport that delivers to remote servers, then publish the public key as a TXT record under the selector's _domainkey name. cPanel and DirectAdmin manage DKIM keys for you.

What does "550 relay not permitted" mean?

The server refused to pass the message on because the sender did not authenticate, or the destination domain is not one it relays for. Configure the mail client to use SMTP authentication over TLS.

Can I change Exim settings on Domain India shared hosting?

No. The mail server serves every account on the shared server, so its settings are managed by Domain India. You can manage your own SPF, DKIM, filters and mail client settings, and open a ticket if mail is not being delivered.

Ready to go further? Start with managing the Exim mail queue, compare VPS plans if you want to run your own mail server, or look at Business Email if you only need mailboxes.

Email without running a mail server

Mailboxes on your own domain with webmail, without running a mail server yourself.

See Business Email

Ready when you are

Get Business Email from ₹60/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app