cPanel Exim Custom Transport Filters & Phishing Defense in Pakistan

Implement custom Exim system filter regex rules and quarantine hooks on cPanel mail servers to intercept CEO fraud, wire transfer spoofing, and malicious payloads in Pakistan.

cPanel Exim Custom Transport Filters & Phishing Defense in Pakistan

Corporate organizations, financial brokerages, and textile exporters across Pakistan face an escalating wave of highly targeted Business Email Compromise (BEC) and executive impersonation attacks. In these sophisticated “CEO fraud” schemes, cybercriminals register visually identical lookalike domains (e.g. c0rp.com.pk instead of corp.com.pk) or spoof executive display names, issuing urgent instructions to accounting teams to divert millions of rupees in supplier invoice payments to fraudulent bank accounts.

Standard Bayesian spam filters (like default SpamAssassin) frequently fail to catch these attacks because the emails contain no obvious malware attachments or traditional spam keywords—they read like ordinary business correspondence.

Hosting corporate email infrastructure on bare-metal Dedicated Servers gives administrators root-level power to deploy custom Exim System Transport Filters. By evaluating raw email headers, display name mismatches, and banking trigger phrases before messages ever reach the user’s inbox, you can intercept and neutralize financial fraud in real time.


Understanding the Exim System Filter Pipeline

Unlike per-user mail filters configured inside cPanel’s webmail interface, an Exim System Filter executes globally with root privileges before local delivery routing occurs:

  1. Envelope Arrival: An external mail server connects to Exim and delivers an email payload.
  2. System Filter Inspection: Exim passes the raw message headers and body through the centralized system filter script (/etc/cpanel_exim_system_filter).
  3. Regex Pattern Evaluation: The filter checks:
    • Does the From: display name contain an internal executive’s name (e.g. “Mian Muhammad - CEO”) while the Reply-To: or envelope sender belongs to an external Gmail/Proton address?
    • Does the email body contain wire transfer keywords paired with urgent banking routing codes?
  4. Execution Action: If matched, the filter can silently drop the message, append warning headers (X-Security-Warning: External Executive Impersonation), or divert it into a quarantined security compliance mailbox.
Inbound Email Arrives
          │
          ▼
   [Exim MTA Ingress]
          │
          ▼
   [Global System Filter (/etc/cpanel_exim_system_filter)]
          │
 ┌────────┴────────────────────────────────────────┐
 ▼                                                 ▼
Clean Message                                     Matches Phishing Pattern
Deliver to Inbox                                  (Display Name Spoof / Fake IBAN)
                                                   ├── Append High-Visibility Warning Banner
                                                   └── Divert Copy to Security Ops (/quarantine/)

Step 1: Enabling and Customizing the Exim System Filter

In cPanel, global filtering is governed by /etc/cpanel_exim_system_filter. Never edit this file directly, as cPanel updates will overwrite your changes. Instead, create a custom template copy:

# Create persistent system filter drop-in
cp /etc/cpanel_exim_system_filter /etc/cpanel_exim_system_filter_custom
chmod 644 /etc/cpanel_exim_system_filter_custom
chown root:mail /etc/cpanel_exim_system_filter_custom

Instruct WHM to use this custom filter file:

  1. Navigate to WHM > Service Configuration > Exim Configuration Manager > Basic Editor > Filters.
  2. Set Exim System Filter File to /etc/cpanel_exim_system_filter_custom.
  3. Save changes.

Step 2: Crafting BEC & Financial Spoofing Filter Rules

Append the following defensive rules to the bottom of /etc/cpanel_exim_system_filter_custom:

# /etc/cpanel_exim_system_filter_custom - NextGen Anti-Phishing Rules

# 1. Executive Display Name Spoofing Defense
# Flags external emails attempting to pose as the CEO or CFO
if
  $h_from: contains "Tariq Malik" or
  $h_from: contains "Chief Executive Officer"
then
  if $sender_address does not contain "@nextgen.pk" then
    headers add "X-NextGen-Security: SUSPECTED_EXECUTIVE_IMPERSONATION"
    headers add "Subject: [EXTERNAL SPOOF WARNING] $h_subject:"
    deliver "[email protected]"
  endif
endif

# 2. Wire Transfer & Fake Invoice Phishing Intercept
# Blocks dangerous execution scripts bundled in ZIP/ISO/IMG containers
if $header_content-type: matches "(?i)multipart/mixed" then
  if $message_body: matches "(?i)(urgent payment|wire transfer|updated bank account|change in iban|swift code)" then
    if $message_body: matches "(?i)\\.(iso|img|vbs|exe|scr|bat|ps1)\\b" then
      fail text "Message rejected by enterprise policy: Suspected malicious financial attachment."
      seen finish
    endif
  endif
endif

# 3. Warning Injection for First-Time External Senders
if $sender_address does not contain "@nextgen.pk" then
  if $h_subject: matches "(?i)(invoice|overdue payment|remittance)" then
    headers add "X-Security-Notice: EXTERNAL SENDER - Verify banking details verbally before processing funds."
  endif
endif

Step 3: Rebuilding Exim Configuration and Applying Rules

Rebuild Exim’s runtime maps and restart the mail service to compile the system filter:

/scripts/buildeximconf
/scripts/restartsrv_exim

Verify that Exim accepts the custom filter syntax without syntax errors:

# Test system filter syntax
exim -bV

Step 4: Auditing Filter Hits in Real Time

Inspect /var/log/exim_mainlog for custom filter intercepts:

# Monitor system filter triggers
grep -E "(SUSPECTED_EXECUTIVE_IMPERSONATION|soc-quarantine)" /var/log/exim_mainlog

Look for explicit log entries confirming intercept:

2026-09-30 17:05:12 1sX8fB-0002bA-3c <= [email protected] H=(mail-lj1-f175.google.com) [209.85.218.175] P=esmtps S=2415 [email protected]
2026-09-30 17:05:12 1sX8fB-0002bA-3c => [email protected] <[email protected]> R=central_filter T=local_delivery

Deploying custom Exim transport filters on bare-metal Dedicated Servers in Pakistan empowers security administrators to prevent multi-million rupee financial wire scams, defend brand reputation, and ensure comprehensive email protection across all corporate domains.


Defend Your Corporate Communications with NextGen Dedicated Servers

Protect your business from CEO fraud, spear-phishing, and ransomware attacks with custom Exim transport filters, dedicated IP routing, and enterprise hardware security in Pakistan.

Explore Pakistan Dedicated Servers