Mail logs tell you whether an email arrived, where it went and why it failed. On a Linux server running Exim, the quickest way to answer those questions is grep for the current log and zgrep for the compressed older ones. This page gives you the searches that matter; they need root access to your own VPS or server.
On cPanel servers the Exim log is /var/log/exim_mainlog; on DirectAdmin it is /var/log/exim/mainlog. Use grep on the current file, zgrep on rotated .gz files, and exigrep to follow one message from arrival to delivery. On Domain India shared hosting the mail logs cover the whole server, so customers can't read them; open a ticket and support will check them for you.
For log formats, Postfix and Dovecot, password-guessing and spam investigations, see The Ultimate Comprehensive Guide to Mastering Mail Log Analysis.
1. Where the mail logs are
| System | Delivery log | Mailbox login log |
|---|---|---|
| cPanel | /var/log/exim_mainlog | /var/log/maillog |
| DirectAdmin | /var/log/exim/mainlog | /var/log/maillog |
| Debian or Ubuntu | /var/log/mail.log, or only the journal | Same |
Logs are rotated, so older days sit in compressed files such as exim_mainlog-20260920.gz. The examples below use the cPanel path; on DirectAdmin, swap in /var/log/exim/mainlog.
2. Search the current log with grep
grep '[email protected]' /var/log/exim_mainlog # every line mentioning an address
grep -c '[email protected]' /var/log/exim_mainlog # how many lines
grep -i 'example.com' /var/log/exim_mainlog # a whole domain, any case
grep -n 'SMTP error' /var/log/exim_mainlog # with line numbers
tail -f /var/log/exim_mainlog | grep '[email protected]' # watch liveTo follow one email, use exigrep rather than grep. It groups every line for each matching message by its message ID, so you see arrival, delivery and any error together:
exigrep '[email protected]' /var/log/exim_mainlog3. Search older, compressed logs with zgrep
zgrep works like grep on .gz files, without unpacking them:
zgrep '[email protected]' /var/log/exim_mainlog-20260920.gz
zgrep -C 3 '[email protected]' /var/log/exim_mainlog-*.gz # 3 lines of context
zgrep -h '[email protected]' /var/log/exim_mainlog-*.gz | sort | uniq -cexigrep reads compressed files too, so exigrep '[email protected]' /var/log/exim_mainlog-20260920.gz works.
4. Searches that answer common questions
| Question | Search for | Where |
|---|---|---|
| Did the message arrive? | <= with the address | Exim log |
| Was it delivered? | => or -> | Exim log |
| Is it waiting to retry? | == | Exim log |
| Did it bounce? | ** | Exim log |
| Did someone fail to log in to send? | authenticator failed | Exim log |
| Did someone fail to log in to a mailbox? | auth failed | /var/log/maillog |
For example, today's hard bounces on cPanel:
grep "^$(date +%F)" /var/log/exim_mainlog | grep ' \*\* 'The end of each bounce or deferral line carries the remote server's reply, such as a 550 refusal or a 421 temporary error. That reply is usually the answer.
5. On Domain India shared hosting
Customers can't read the server's mail logs, because they contain every account's mail. If an email didn't arrive or bounced, open a ticket with the sender, the recipient, the date and time, and any bounce message, and support can check the logs. Outgoing mail is limited per account: 200 messages per hour on cPanel and 1,000 per day on DirectAdmin. For sending problems, see I can receive mail but I cannot send it.
On a Domain India VPS, which is self-managed with full root access, every command on this page works on your own logs.
Where is the Exim mail log?
On cPanel servers it is /var/log/exim_mainlog. On DirectAdmin servers it is /var/log/exim/mainlog. Mailbox logins over IMAP and POP3 are logged in /var/log/maillog on both.
How do I search compressed mail logs?
Use zgrep, which works like grep on .gz files without unpacking them, for example zgrep '[email protected]' /var/log/exim_mainlog-*.gz. exigrep also reads compressed logs.
What is the difference between grep and exigrep?
grep prints single matching lines. exigrep prints every line of each matching message, grouped by message ID, so you see arrival, delivery and errors for one email together.
Can I read mail logs on Domain India shared hosting?
No. The mail logs cover every account on the server, so customers can't read them. Open a support ticket with the sender, recipient, date and time of the email and any bounce message, and support can check them for you.
Ready to dig deeper? Read the full mail log analysis guide, or open a ticket about a missing email on shared hosting.
Send us the sender, recipient, date and time and any bounce message, and we will check the server logs.
Open a support ticket