You've created email accounts and forwarded a few addresses. Now you need to optimize delivery rates, prevent authentication failures, tune resource limits for real workloads, and diagnose obscure failures that basic documentation never covers. This guide assumes you're comfortable with cPanel's interface and focuses on the configuration decisions that separate functional email from production-ready email infrastructure.
Authentication Stack: Beyond the Wizard
Most cPanel installations offer an authentication wizard that generates SPF, DKIM, and DMARC records. While convenient, the defaults rarely match production requirements.
SPF Records for Complex Routing
The basic SPF record cPanel generates typically includes only your server's IP. Production environments require careful attention to include clauses:
v=spf1 a mx ip4:203.0.113.50 include:_spf.google.com include:spf.protection.outlook.com ~softfail
Key considerations:
- Include third-party senders before you migrate mail. If you use G Suite, Office 365, or transactional email services, add their include directives.
- Avoid excessive DNS lookups. SPF has a hard limit of ten DNS lookups. Each
include:andamechanism counts. Flatten your SPF record if you approach this limit by converting includes to explicitip4:orip6:ranges where possible. - Choose your failure mode carefully. Use
~softfailduring initial deployment to identify legitimate sources you missed without breaking delivery. Move to-failonly after monitoring for hidden senders. - Document dynamic IP scenarios. If your server IP changes, SPF breaks silently. Many shared hosting environments rotate IPs during migrations.
DKIM Selector Strategy
The default DKIM selector in cPanel is typically default._domainkey. For operational flexibility, consider:
# Generate additional selector via command line
cd /var/cpanel/domain_keys/
openssl genrsa -out yourdomain.com.backup.private 2048
openssl rsa -in yourdomain.com.backup.private -pubout -out yourdomain.com.backup.public
Multiple selectors let you:
- Rotate keys without downtime. Publish the new selector's public key in DNS, wait for TTL expiration, switch the active selector in Exim configuration, then remove the old key.
- Identify mail sources. Use different selectors for webmail, application mail, and administrative notices to trace delivery issues.
- Test configuration changes. Deploy experimental DKIM settings under a new selector while production traffic uses the stable selector.
Verify DKIM signing is actually applied:
grep -i dkim /var/log/exim_mainlog | tail -20
Look for "DKIM-Signature" headers in outbound messages. Missing signatures usually indicate Exim isn't configured to sign for the domain, often because the domain key files have incorrect permissions or the domain isn't properly recognized in /etc/localdomains.
DMARC Policy Progression
Start with monitoring, not enforcement:
_dmarc.yourdomain.com TXT "v=DMARC1; p=none; rua=mailto:[email protected]; ruf=mailto:[email protected]; fo=1"
Aggregate reports (rua) arrive daily as XML attachments showing authentication results from major receivers. Parse these to identify:
- Legitimate sources failing SPF or DKIM
- Spoofing attempts (volume and originating IPs)
- Alignment issues (mail sent via third parties that don't align with your domain)
After monitoring for several weeks with clean reports, escalate:
p=quarantine; pct=10
Apply enforcement to a percentage of traffic first. When confident, move to p=reject with pct=100. Tag subdomains explicitly:
_dmarc.subdomain.yourdomain.com TXT "v=DMARC1; p=reject; sp=reject"
The sp tag sets policy for subdomains. Without it, an attacker can spoof mail from arbitrary subdomains even when your main domain has strict policy.
Exim Configuration Tuning
cPanel's Exim configuration lives in /etc/exim.conf (auto-generated) and /etc/exim.conf.local (persistent customizations). Never edit exim.conf directly—it's rebuilt by cPanel.
Rate Limiting for Shared Hosting
Prevent a single account from monopolizing mail resources:
# In WHM: Home » Service Configuration » Exim Configuration Manager » Advanced Editor
# Or add to /etc/exim.conf.local in the appropriate ACL section
ACL:
acl_smtp_mail:
warn:
condition = ${if >{$rcpt_count}{100}}
message = Recipient count exceeds limit
log_message = Too many recipients from $sender_address
For outbound rate limiting by authenticated user:
warn:
ratelimit = 100 / 1h / strict / $authenticated_id
log_message = Account $authenticated_id sending too fast
Adjust the rate (messages per hour) based on legitimate user behavior. Monitor /var/log/exim_mainlog after deployment to catch false positives from bulk-sending users.
Connection and Timeout Tuning
Default Exim timeouts are conservative. For high-volume servers with reliable connectivity:
smtp_accept_max = 50
smtp_accept_max_per_host = 10
smtp_connect_backlog = 50
smtp_receive_timeout = 5m
received_header_max = 30
Key parameters:
smtp_accept_max: Total concurrent inbound SMTP connections. Increase if legitimate mail is deferred with "too many connections."smtp_accept_max_per_host: Per-IP limit. Raise cautiously; spammers respect this limit too.smtp_receive_timeout: How long to wait for client commands. Shorter timeouts free resources faster but may disconnect slow clients.received_header_max: Maximum hops. Lower values (e.g., 15-20) block mail loops faster.
After changes, verify syntax and reload:
exim -bV # Check configuration validity
systemctl restart exim
Custom Retry Rules
Exim's default retry schedule queues failed messages for days. Fine-tune for your environment in /etc/exim.conf.local:
begin retry
# Retry DNS failures quickly (often transient)
*@* dns_failed F,2h,15m; G,16h,1h,1.5; F,4d,6h
# Connection refused suggests server down; retry less aggressively
*@* refused_conn F,2h,30m; G,16h,2h,1.5; F,4d,8h
# Quota exceeded rarely resolves quickly
*@* quota_exceeded F,1h,15m; F,6h,30m; F,2d,6h
Format: pattern error_type retry_schedule
Retry schedules use F (fixed intervals) and G (geometric backoff). The last component sets the overall timeout before giving up.
Queue Management and Troubleshooting
A growing queue signals delivery issues. Examine it systematically.
Queue Inspection
List all messages:
exim -bp | less
Count by recipient domain:
exim -bp | exiqsumm
This reveals patterns—one domain absorbing all retry attempts, a specific sender flooding the queue, or widespread delivery failures.
Inspect a specific message:
exim -Mvh <message-id> # Headers
exim -Mvb <message-id> # Body
exim -Mvl <message-id> # Log entries
Selective Queue Actions
Force immediate delivery attempt for one message:
exim -M <message-id>
Freeze all messages to a problematic domain:
exiqgrep -i -f @spammer.com | xargs exim -Mf
Delete frozen messages older than a threshold:
exiqgrep -z -o 172800 | xargs exim -Mrm
-z matches frozen, -o 172800 matches messages older than 48 hours (in seconds).
Before bulk deletion, examine a sample to ensure you're not removing legitimate mail. Check the message source, bounce reason, and sender.
Delivery Failure Patterns
Common queue issues and diagnostic steps:
DNS resolution failures: Check /etc/resolv.conf on the server. Test resolution manually:
dig MX recipient-domain.com
host -t MX recipient-domain.com
If your server can't resolve MX records, outbound mail queues until DNS is restored.
Greylisting by recipient: Temporary 4xx deferrals that resolve after retry. These are normal; ensure your retry schedule accommodates them (default Exim config does).
Blacklist blocks: Extract IPs from bounce messages and check:
host 50.113.0.203.zen.spamhaus.org
If listed, identify the cause (compromised account, open relay, poor list hygiene) and request delisting after fixing the issue.
Authentication failures at destination: Recipient servers enforce SPF/DKIM. Check your authentication records are published and valid:
dig TXT yourdomain.com +short # SPF
dig TXT default._domainkey.yourdomain.com +short # DKIM
Resource Limits and Mailbox Optimization
Per-Account Quotas and Limits
cPanel sets mailbox quotas in WHM under "Edit a Mail User." For programmatic management:
# View current quota for [email protected]
/scripts/quota [email protected]
# Set 5GB quota (value in MB)
/scripts/modify_quotas [email protected] 5120
Monitor quota usage:
du -sh /home/username/mail/domain.com/user/
Maildir storage is fragmented by design (one file per message). High message counts slow filesystem operations. Users with tens of thousands of messages in a single folder benefit from:
- Periodic archival to local storage or archive services
- IMAP folder hierarchy instead of dumping everything in INBOX
- Filesystem choice: XFS handles large directories better than ext4 in typical configurations
Exim Spool and Temporary Files
Exim's spool directory (/var/spool/exim) accumulates temporary files during processing. On busy servers:
df -h /var/spool/exim
If spool fills, Exim rejects new mail. Prevent this by:
- Separate partition for
/var/spool/eximto isolate it from root filesystem - Regular cleanup of old input and msglog files (Exim's built-in retry logic usually handles this, but check for stale entries after crashes)
- Monitor queue depth with server monitoring tools
IMAP Connection Limits
Dovecot (cPanel's IMAP/POP3 server) limits concurrent connections per user. Defaults are conservative:
# /etc/dovecot/dovecot.conf or included conf.d/ files
mail_max_userip_connections = 10
Users with multiple devices or aggressive sync intervals hit this limit. Symptoms include intermittent connection failures in mail clients. Increase cautiously—each connection consumes memory and file descriptors.
Advanced Filtering and Routing
Server-Level Filters
cPanel's interface offers basic filters. For complex routing, edit /etc/vfilters/ or use Exim system filters.
Example system filter in /etc/exim.system_filter:
if $header_subject: contains "[BULK]" then
deliver "[email protected]"
finish
endif
if $message_size is above 25M then
fail text "Message size exceeds 25MB limit"
endif
Enable it by adding to Exim configuration:
system_filter = /etc/exim.system_filter
System filters run before user delivery, enabling policy enforcement (size limits, content scanning integration, routing by header patterns) across all domains.
Conditional Routing Based on Sender Authentication
Route authenticated versus unauthenticated mail differently:
begin routers
authenticated_outbound:
driver = dnslookup
condition = ${if eq{$authenticated_id}{}}
transport = remote_smtp_authenticated
ignore_target_hosts = 0.0.0.0:127.0.0.0/8
no_more
This pattern lets you apply different DKIM selectors, source IPs (on multi-IP servers), or relay rules for authenticated versus incoming mail.
Monitoring and Alerting
Production email requires visibility into delivery metrics, queue depth, and authentication failures.
Log Analysis
Exim's main log is verbose. Extract useful metrics:
# Delivery success rate
grep "=>" /var/log/exim_mainlog | wc -l # Successful deliveries
grep "==" /var/log/exim_mainlog | wc -l # Deferred
grep "**" /var/log/exim_mainlog | wc -l # Failed
# Top senders by volume
grep "<=" /var/log/exim_mainlog | awk '{print $6}' | sort | uniq -c | sort -rn | head
For ongoing monitoring, parse logs into a time-series database or use log aggregation tools. Key metrics:
- Messages sent/received per hour
- Queue depth over time
- Deferred/failed ratios
- Authentication failure count
- Unique sending IPs (detect compromised accounts)
Alerting on Anomalies
Set thresholds that indicate operational issues:
- Queue depth above baseline + variance
- Sudden spikes in sending from a single account (compromise indicator)
- Elevated bounce rates (DNS issues, blacklisting, or authentication problems)
- Disk usage on
/var/spool/eximapproaching capacity
Integrate with your existing monitoring stack (Prometheus exporters, Nagios plugins, or custom scripts).
Conclusion
Advanced email configuration in cPanel moves beyond account creation into the operational details that determine whether mail reaches inboxes reliably. Proper authentication, tuned resource limits, systematic queue management, and visibility into delivery metrics separate a functional mail server from a production-ready one. Treat each configuration change as testable: deploy incrementally, monitor impact, and document what worked for your specific environment. Email deliverability is less about perfect configuration than consistent monitoring and rapid response to the inevitable failures that production traffic surfaces.
