Mail logs record every connection, login, delivery and rejection on a mail server. Reading them is the fastest way to answer "did this email arrive?", "why was it rejected?" and "is someone guessing my passwords?". This guide shows where the logs are, how to read Exim, Postfix and Dovecot lines, and the commands that answer the common questions. It is for administrators of their own VPS or server; on shared hosting you can't read the server's mail logs.
Exim logs deliveries to /var/log/exim_mainlog on cPanel and /var/log/exim/mainlog on DirectAdmin; Postfix and Dovecot usually log to /var/log/maillog on RHEL-family systems or /var/log/mail.log on Debian and Ubuntu, or only to the journal. Search by message ID to follow one email from arrival to delivery, count auth failed lines by IP to spot password guessing, and count arrivals per authenticated user to find a compromised mailbox.
On Domain India shared hosting, the mail logs belong to the whole server, so customers can't read them. If an email didn't arrive or was rejected, open a ticket with the sender, recipient, date and time, and any bounce message, and support can check the logs for you. For sending problems, see I can receive mail but cannot send it.
1. Where the logs are
| System | Delivery log (MTA) | Login log (IMAP/POP3) |
|---|---|---|
| cPanel & WHM | /var/log/exim_mainlog, plus exim_rejectlog and exim_paniclog | /var/log/maillog |
| DirectAdmin | /var/log/exim/mainlog, plus rejectlog and paniclog | /var/log/maillog |
| RHEL-family with Postfix | /var/log/maillog | /var/log/maillog |
| Debian or Ubuntu with Postfix | /var/log/mail.log, or the journal only | Same file, or the journal |
Recent Debian releases don't install rsyslog by default, so there may be no mail log file at all. Read the journal instead:
journalctl -u postfix -u dovecot --since "1 hour ago"
journalctl -u exim4 -f # follow live on Debian with EximLogs are rotated, usually daily or weekly. Older days are in files such as exim_mainlog-20260920.gz; search them with zgrep instead of grep.
2. Reading an Exim log line
Every Exim line has a timestamp, a message ID such as 1tAbCd-000Xyz-9Q, and a flag that says what happened:
| Flag | Meaning |
|---|---|
| <= | Message arrived (received) |
| => | Delivered to its first recipient |
| -> | Delivered to another recipient of the same message |
| == | Delivery deferred; Exim will retry |
| ** | Delivery failed permanently; a bounce is sent |
| Completed | Exim has finished with the message |
On an arrival line, A= shows how the sender authenticated. On cPanel it looks like A=dovecot_login:[email protected]; on DirectAdmin, A=login:[email protected]. H= is the remote host and IP, S= the size, and T= the subject if subject logging is on.
3. Follow one message
exigrep prints every line for the messages that match a pattern, grouped by message ID:
exigrep '[email protected]' /var/log/exim_mainlog
exigrep '1tAbCd-000Xyz-9Q' /var/log/exim_mainlogThe group shows whether the message arrived, where it was delivered, and the exact error if it was deferred or bounced. On Postfix, search for the queue ID in the same way:
grep 'to=<[email protected]>' /var/log/maillog
grep ' 4F2A91C0E3:' /var/log/maillogPostfix reports status=sent, status=deferred or status=bounced with the remote server's reply.
4. Spot password guessing
Current Dovecot versions log a failed login as a Login aborted line that contains auth failed, with the remote IP in rip=. Count failures by IP:
grep 'auth failed' /var/log/maillog \
| grep -oE 'rip=[0-9a-fA-F.:]+' | sort | uniq -c | sort -rn | head -20And by targeted mailbox:
grep 'auth failed' /var/log/maillog \
| grep -oE 'user=<[^>]*>' | sort | uniq -c | sort -rn | head -20A handful of failures from a user's own IP is usually a saved old password in a phone or laptop. Hundreds from many IPs against one mailbox is a guessing attack. Your firewall (for example CSF with its login-failure daemon, or fail2ban) should block these automatically; check its settings rather than adding blocks by hand one at a time.
5. Find a mailbox that is sending spam
A compromised mailbox shows up as one authenticated user with far more arrivals than normal. Count today's authenticated arrivals per user on cPanel:
grep "^$(date +%F)" /var/log/exim_mainlog | grep ' <= ' \
| grep -oE 'A=dovecot_(login|plain):[^ ]+' | cut -d: -f2 \
| sort | uniq -c | sort -rn | headOn DirectAdmin, use /var/log/exim/mainlog and A=(login|plain): in the pattern. If one address stands out, change its password at once, check its forwarders and filters, and look at the queue with exim -bp | exiqsumm. For the queue itself, see Managing the Exim mail queue.
Scripts that send through PHP rather than a mailbox show as arrivals from a local user with no A=. On cPanel, lines with cwd=/home/username/… point to the directory the script ran from.
6. Rejections and deferrals
grep "^$(date +%F)" /var/log/exim_rejectlog | tail -50 # what Exim refused today
grep ' == ' /var/log/exim_mainlog | tail -50 # recent deferrals
grep ' \*\* ' /var/log/exim_mainlog | tail -50 # recent hard bouncesRead the remote server's reply at the end of the line. The common ones:
- 550 5.7.1 or "blocked": the receiving server refused your IP or content. Check your IP against public blocklists and your SPF, DKIM and DMARC records.
- 421 or 451, deferred: a temporary problem or greylisting. Exim retries on its own.
- Relay access denied (Postfix): a client tried to send to an outside address without logging in.
7. Summaries and monitoring
eximstats /var/log/exim_mainlogprints totals, top senders, top destinations and errors for a log file.pflogsummdoes the same for Postfix.tail -forjournalctl -fshows lines live while you reproduce a problem.- For several servers, ship logs to a central system such as Loki, Graylog or an ELK stack, and alert on sudden jumps in bounces or failed logins.
Keep logs long enough to investigate complaints, and check /etc/logrotate.d/ so they don't fill the disk.
8. Running this on Domain India
On shared hosting, outgoing mail is limited per account: 200 messages per hour on cPanel and 1,000 per day on DirectAdmin. See Do you limit the amount of mail I can send.
A Domain India VPS is self-managed with full root access, so you read and keep your own mail logs. Prices on the card are live and exclude 18% GST.
- 1 vCPU
- 2 GB DDR4 RAM
- 64 GB NVMe SSD Storage
- 2 TB Monthly Bandwidth
If you'd rather not run a mail server, Business Email gives you managed mailboxes with DKIM signing on every message.
- Priced per mailbox - start with one
- Email at your own domain ([email protected])
- Add and remove mailboxes yourself
- Webmail with calendar, contacts and tasks
Where is the Exim mail log on cPanel and DirectAdmin?
On cPanel it is /var/log/exim_mainlog, with exim_rejectlog and exim_paniclog beside it. On DirectAdmin it is /var/log/exim/mainlog. IMAP and POP3 logins are in /var/log/maillog on both.
How do I trace one email through Exim?
Run exigrep with the recipient address or the message ID against the main log. It prints every line for the matching messages, grouped by message ID, including the delivery result or error.
What do the symbols in an Exim log mean?
<= means the message arrived, => and -> mean it was delivered, == means delivery was deferred and will be retried, and ** means delivery failed permanently.
How can I find failed email logins?
Search the Dovecot log for "auth failed" and count the rip= values to see which IP addresses are failing, or the user= values to see which mailboxes are targeted.
Can I see the mail logs on Domain India shared hosting?
No. The mail logs cover every account on the server, so customers can't read them. Open a support ticket with the sender, recipient, date and time of the email, and support can check the logs for you.
Why is there no /var/log/mail.log on my Debian server?
Recent Debian releases log to the systemd journal and don't install rsyslog by default. Use journalctl with the mail service's unit, or install rsyslog if you want a text log file.
Ready to run your own mail server? Compare VPS plans, or choose Business Email for managed mailboxes. For a missing or rejected email on shared hosting, open a support ticket with the message details.
Send us the sender, recipient, date and time and any bounce message, and we will check the server logs.
Open a support ticket