Troubleshooting Delivery Issues

The Ultimate Comprehensive Guide to Mastering Mail Log Analysis

By the Domain India teamPublished 6 min read
Knowledge base article
Contents (8 sections)

Mail logs record every connection, login, delivery and rejection on a mail server. Reading them is the fastest way to answer "did this email arrive?", "why was it rejected?" and "is someone guessing my passwords?". This guide shows where the logs are, how to read Exim, Postfix and Dovecot lines, and the commands that answer the common questions. It is for administrators of their own VPS or server; on shared hosting you can't read the server's mail logs.

Key takeaways

Exim logs deliveries to /var/log/exim_mainlog on cPanel and /var/log/exim/mainlog on DirectAdmin; Postfix and Dovecot usually log to /var/log/maillog on RHEL-family systems or /var/log/mail.log on Debian and Ubuntu, or only to the journal. Search by message ID to follow one email from arrival to delivery, count auth failed lines by IP to spot password guessing, and count arrivals per authenticated user to find a compromised mailbox.

On shared hosting?

On Domain India shared hosting, the mail logs belong to the whole server, so customers can't read them. If an email didn't arrive or was rejected, open a ticket with the sender, recipient, date and time, and any bounce message, and support can check the logs for you. For sending problems, see I can receive mail but cannot send it.

1. Where the logs are

SystemDelivery log (MTA)Login log (IMAP/POP3)
cPanel & WHM/var/log/exim_mainlog, plus exim_rejectlog and exim_paniclog/var/log/maillog
DirectAdmin/var/log/exim/mainlog, plus rejectlog and paniclog/var/log/maillog
RHEL-family with Postfix/var/log/maillog/var/log/maillog
Debian or Ubuntu with Postfix/var/log/mail.log, or the journal onlySame file, or the journal

Recent Debian releases don't install rsyslog by default, so there may be no mail log file at all. Read the journal instead:

bash
journalctl -u postfix -u dovecot --since "1 hour ago"
journalctl -u exim4 -f          # follow live on Debian with Exim

Logs are rotated, usually daily or weekly. Older days are in files such as exim_mainlog-20260920.gz; search them with zgrep instead of grep.

2. Reading an Exim log line

Every Exim line has a timestamp, a message ID such as 1tAbCd-000Xyz-9Q, and a flag that says what happened:

FlagMeaning
<=Message arrived (received)
=>Delivered to its first recipient
->Delivered to another recipient of the same message
==Delivery deferred; Exim will retry
**Delivery failed permanently; a bounce is sent
CompletedExim has finished with the message

On an arrival line, A= shows how the sender authenticated. On cPanel it looks like A=dovecot_login:[email protected]; on DirectAdmin, A=login:[email protected]. H= is the remote host and IP, S= the size, and T= the subject if subject logging is on.

3. Follow one message

exigrep prints every line for the messages that match a pattern, grouped by message ID:

bash
exigrep '[email protected]' /var/log/exim_mainlog
exigrep '1tAbCd-000Xyz-9Q' /var/log/exim_mainlog

The group shows whether the message arrived, where it was delivered, and the exact error if it was deferred or bounced. On Postfix, search for the queue ID in the same way:

bash
grep 'to=<[email protected]>' /var/log/maillog
grep ' 4F2A91C0E3:' /var/log/maillog

Postfix reports status=sent, status=deferred or status=bounced with the remote server's reply.

4. Spot password guessing

Current Dovecot versions log a failed login as a Login aborted line that contains auth failed, with the remote IP in rip=. Count failures by IP:

bash
grep 'auth failed' /var/log/maillog \
  | grep -oE 'rip=[0-9a-fA-F.:]+' | sort | uniq -c | sort -rn | head -20

And by targeted mailbox:

bash
grep 'auth failed' /var/log/maillog \
  | grep -oE 'user=<[^>]*>' | sort | uniq -c | sort -rn | head -20

A handful of failures from a user's own IP is usually a saved old password in a phone or laptop. Hundreds from many IPs against one mailbox is a guessing attack. Your firewall (for example CSF with its login-failure daemon, or fail2ban) should block these automatically; check its settings rather than adding blocks by hand one at a time.

5. Find a mailbox that is sending spam

A compromised mailbox shows up as one authenticated user with far more arrivals than normal. Count today's authenticated arrivals per user on cPanel:

bash
grep "^$(date +%F)" /var/log/exim_mainlog | grep ' <= ' \
  | grep -oE 'A=dovecot_(login|plain):[^ ]+' | cut -d: -f2 \
  | sort | uniq -c | sort -rn | head

On DirectAdmin, use /var/log/exim/mainlog and A=(login|plain): in the pattern. If one address stands out, change its password at once, check its forwarders and filters, and look at the queue with exim -bp | exiqsumm. For the queue itself, see Managing the Exim mail queue.

Scripts that send through PHP rather than a mailbox show as arrivals from a local user with no A=. On cPanel, lines with cwd=/home/username/… point to the directory the script ran from.

6. Rejections and deferrals

bash
grep "^$(date +%F)" /var/log/exim_rejectlog | tail -50     # what Exim refused today
grep ' == ' /var/log/exim_mainlog | tail -50                # recent deferrals
grep ' \*\* ' /var/log/exim_mainlog | tail -50              # recent hard bounces

Read the remote server's reply at the end of the line. The common ones:

  • 550 5.7.1 or "blocked": the receiving server refused your IP or content. Check your IP against public blocklists and your SPF, DKIM and DMARC records.
  • 421 or 451, deferred: a temporary problem or greylisting. Exim retries on its own.
  • Relay access denied (Postfix): a client tried to send to an outside address without logging in.

7. Summaries and monitoring

  • eximstats /var/log/exim_mainlog prints totals, top senders, top destinations and errors for a log file.
  • pflogsumm does the same for Postfix.
  • tail -f or journalctl -f shows lines live while you reproduce a problem.
  • For several servers, ship logs to a central system such as Loki, Graylog or an ELK stack, and alert on sudden jumps in bounces or failed logins.

Keep logs long enough to investigate complaints, and check /etc/logrotate.d/ so they don't fill the disk.

8. Running this on Domain India

On shared hosting, outgoing mail is limited per account: 200 messages per hour on cPanel and 1,000 per day on DirectAdmin. See Do you limit the amount of mail I can send.

A Domain India VPS is self-managed with full root access, so you read and keep your own mail logs. Prices on the card are live and exclude 18% GST.

VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details

If you'd rather not run a mail server, Business Email gives you managed mailboxes with DKIM signing on every message.

Business Email
₹60/mo + GST
  • Priced per mailbox - start with one
  • Email at your own domain ([email protected])
  • Add and remove mailboxes yourself
  • Webmail with calendar, contacts and tasks
See plan details
Where is the Exim mail log on cPanel and DirectAdmin?

On cPanel it is /var/log/exim_mainlog, with exim_rejectlog and exim_paniclog beside it. On DirectAdmin it is /var/log/exim/mainlog. IMAP and POP3 logins are in /var/log/maillog on both.

How do I trace one email through Exim?

Run exigrep with the recipient address or the message ID against the main log. It prints every line for the matching messages, grouped by message ID, including the delivery result or error.

What do the symbols in an Exim log mean?

<= means the message arrived, => and -> mean it was delivered, == means delivery was deferred and will be retried, and ** means delivery failed permanently.

How can I find failed email logins?

Search the Dovecot log for "auth failed" and count the rip= values to see which IP addresses are failing, or the user= values to see which mailboxes are targeted.

Can I see the mail logs on Domain India shared hosting?

No. The mail logs cover every account on the server, so customers can't read them. Open a support ticket with the sender, recipient, date and time of the email, and support can check the logs for you.

Why is there no /var/log/mail.log on my Debian server?

Recent Debian releases log to the systemd journal and don't install rsyslog by default. Use journalctl with the mail service's unit, or install rsyslog if you want a text log file.

Ready to run your own mail server? Compare VPS plans, or choose Business Email for managed mailboxes. For a missing or rejected email on shared hosting, open a support ticket with the message details.

Missing an email on shared hosting?

Send us the sender, recipient, date and time and any bounce message, and we will check the server logs.

Open a support ticket

Ready when you are

Get Business Email from ₹60/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Mail Log Analysis for Exim, Postfix and Dovecot