Exim is the mail transfer agent (MTA) that accepts, routes and delivers email on most cPanel and DirectAdmin servers, and on many Debian-based systems. This handbook is the starting point for administrators who run Exim on their own server or VPS: how it is laid out, the settings that matter, how to check a change before it goes live, and where to go for queues, errors and spam control.
Exim reads one main configuration, split into main settings, ACLs, routers and transports. On cPanel you change it only through WHM's Exim Configuration Manager; on a plain server you edit the file, check it with exim -bV, test with exim -bt and exim -bh, then reload. Deliverability comes from DNS (SPF, DKIM, DMARC, reverse DNS), with DKIM signing set on the SMTP transport. Keep Exim patched, never run an open relay, and read the main log before you change anything.
Everything here needs root access on a server you run. On Domain India shared hosting (cPanel, DirectAdmin, Webuzo), the mail server serves every account on the machine, so customers can't change Exim, read its logs or restart it. If you are on shared hosting, go to section 9.
1. What Exim does, and where it lives
Exim does three jobs: it receives mail over SMTP, decides where each message should go, and delivers it, either to a local mailbox or to another server. When a delivery can't happen straight away, the message waits in the queue and Exim retries.
The layout depends on how you installed it:
| Setup | Main configuration | Main log | Service name |
|---|---|---|---|
| cPanel & WHM | /etc/exim.conf, generated by cPanel | /var/log/exim_mainlog | exim |
| DirectAdmin | /etc/exim.conf, managed by CustomBuild | /var/log/exim/mainlog | exim |
| Debian or Ubuntu | /etc/exim4/, built by update-exim4.conf | /var/log/exim4/mainlog | exim4 |
| AlmaLinux or Rocky Linux (EPEL) | /etc/exim/exim.conf | /var/log/exim/main.log | exim |
Check the version and build options with exim -bV. It also parses the configuration, so it is the first test after any edit.
2. Installing Exim on a plain server
Debian and Ubuntu ship Exim as exim4:
sudo apt update && sudo apt install exim4-daemon-heavy
sudo dpkg-reconfigure exim4-config # choose "internet site" for a server that sends and receivesAlmaLinux and Rocky Linux use Postfix by default, and Exim comes from EPEL:
sudo dnf install epel-release
sudo dnf install exim
sudo systemctl disable --now postfix
sudo alternatives --set mta /usr/sbin/sendmail.exim
sudo systemctl enable --now eximOnly one MTA should listen on port 25. On a cPanel or DirectAdmin server, Exim is already installed and managed by the panel: don't install another copy.
3. The settings that matter
The main section sets who the server is and what it will accept. These are real Exim options, shown with safe values:
primary_hostname = mail.example.com
domainlist local_domains = @ : example.com
domainlist relay_to_domains =
hostlist relay_from_hosts = localhost
tls_certificate = /etc/ssl/mail/fullchain.pem
tls_privatekey = /etc/ssl/mail/privkey.pem
tls_advertise_hosts = *
auth_advertise_hosts = ${if eq{$tls_in_cipher}{}{}{*}}
message_size_limit = 25M
smtp_accept_max = 100
smtp_accept_max_per_host = 10primary_hostnamemust match the server's reverse DNS (PTR) record, or many receivers will distrust your mail.- Keep
relay_from_hoststo localhost unless you really run a smarthost for other machines. Adding a whole network range is how open relays happen. auth_advertise_hostsas shown offers SMTP login only after TLS starts, so passwords never cross the network in clear text.
On cPanel, don't edit /etc/exim.conf: cPanel rebuilds it and your change disappears. Use WHM's Exim Configuration Manager, as explained in enhancing email security with Exim Configuration Manager. On DirectAdmin, put changes in the custom files that CustomBuild keeps across updates, not in the generated file.
4. Check before you reload
Exim gives you three tests that catch almost every mistake before real mail is affected:
exim -bV # parses the config; an error here means do not reload
exim -bt [email protected] # shows which router and transport a recipient would use
exim -bh 203.0.113.10 # runs a fake SMTP session "from" that IP, showing every ACL decision
exim -bP message_size_limit # prints the current value of any optionReload only when exim -bV is clean: systemctl reload exim (or exim4). Keep a copy of the working file so you can roll back.
5. SPF, DKIM and DMARC
Most of email authentication lives in DNS, not in exim.conf:
- SPF is a TXT record listing the servers allowed to send for your domain, for example
v=spf1 a mx ip4:203.0.113.10 -all. - DKIM signs each outgoing message. In Exim you set it on the SMTP transport that sends to other servers:
remote_smtp:
driver = smtp
dkim_domain = ${lc:${domain:$h_from:}}
dkim_selector = mail
dkim_private_key = /etc/exim/dkim/${dkim_domain}.key
dkim_canon = relaxedPublish the matching public key as a TXT record at mail._domainkey.example.com. cPanel and DirectAdmin manage DKIM keys for you.
- DMARC is a TXT record at
_dmarc.example.com. Start withv=DMARC1; p=none; rua=mailto:[email protected], read the reports for a few weeks, and only then move toquarantineorreject. Jumping straight torejectcan block your own legitimate mail.
For the full DNS side, see the SPF, DKIM and DMARC guide and setting up DMARC.
6. Logs and the mail queue
The main log records every message: <= arrival, => delivery, -> extra recipient, ** permanent failure, == deferred. The fastest way to follow one message is exigrep:
exigrep '[email protected]' /var/log/exim_mainlog | tail -50
eximstats /var/log/exim_mainlog > /tmp/mail-report.txtFor the queue, exim -bpc counts messages, exim -bp | exiqsumm summarises them, and exiqgrep selects them by sender, recipient or age. Retry one message with exim -M ID. Use exim -qff only when you mean to force every message, frozen ones included. Full guides: managing the Exim mail queue and clearing a queue after a spam run.
7. Common errors
| Code | Meaning | Where to start |
|---|---|---|
| 421 | Temporary refusal; the connection is closed and the sender retries | Find which side sent it; see fixing Exim 421 |
| 451 | Temporary local problem, often DNS lookups, greylisting or a busy spool | Read the log line for the reason; check DNS resolution and disk space |
| 550 relay not permitted | The sender did not authenticate, or the domain is not yours to relay | Make the mail client use SMTP authentication over TLS |
| 550 or 554 from a remote server | Rejected as spam, blocklisted IP or failed authentication | Check blocklists, PTR, SPF, DKIM and DMARC |
For bounce messages in plain words, see understanding email bounce-backs.
8. Security and spam control
ratelimit ACL condition to cap messages per authenticated user or per host, so one hacked mailbox can't flood the queue.On a DirectAdmin server, Easy Spam Fighter and Rspamd do much of this for you; see Easy Spam Fighter and Rspamd in DirectAdmin.
9. Exim at Domain India
Shared hosting. Our cPanel and DirectAdmin servers run Exim, managed by us for every account on the server. You can't change it, but you control your own side: SPF, DKIM (on by default for new cPanel accounts), mail filters and your mail client settings. Outgoing mail is limited to 200 messages per hour per account on cPanel and 1,000 per day (200 per mailbox by default) on DirectAdmin. If mail won't send, see I can receive mail but I cannot send it, or open a ticket with the address and the bounce message.
VPS. A Domain India VPS is self-managed with root access, so you can install and configure Exim as in this guide. Before you plan a mail server, ask support about outbound port 25 and setting reverse DNS (PTR) for your IP; both matter for delivery. See setting up a mail server on a VPS and troubleshooting SMTP relay on a VPS.
Just need business email? Business Email gives you mailboxes on your own domain without managing an MTA. The price on the card is a Domain India list price, excluding 18% GST.
- Priced per mailbox - start with one
- Email at your own domain ([email protected])
- Add and remove mailboxes yourself
- Webmail with calendar, contacts and tasks
Frequently asked questions
How do I check that my Exim configuration is valid?
Run exim -bV. It parses the configuration and reports any error before you reload. Then test routing with exim -bt and an address, and a full SMTP session with exim -bh and an IP address.
Can I edit /etc/exim.conf on a cPanel server?
No. cPanel regenerates the file and overwrites manual edits. Make changes through WHM's Exim Configuration Manager, which keeps them across updates.
Where are the Exim logs?
On cPanel servers the main log is /var/log/exim_mainlog. On DirectAdmin it is /var/log/exim/mainlog, and on Debian or Ubuntu it is /var/log/exim4/mainlog.
How do I enable DKIM in Exim?
Set dkim_domain, dkim_selector and dkim_private_key on the SMTP transport that delivers to remote servers, then publish the public key as a TXT record under the selector's _domainkey name. cPanel and DirectAdmin manage DKIM keys for you.
What does "550 relay not permitted" mean?
The server refused to pass the message on because the sender did not authenticate, or the destination domain is not one it relays for. Configure the mail client to use SMTP authentication over TLS.
Can I change Exim settings on Domain India shared hosting?
No. The mail server serves every account on the shared server, so its settings are managed by Domain India. You can manage your own SPF, DKIM, filters and mail client settings, and open a ticket if mail is not being delivered.
Ready to go further? Start with managing the Exim mail queue, compare VPS plans if you want to run your own mail server, or look at Business Email if you only need mailboxes.
Mailboxes on your own domain with webmail, without running a mail server yourself.
See Business Email