On high-density shared hosting servers in Pakistan, email deliverability is frequently compromised by the “bad neighbor” effect. If a single WordPress website on a shared server is compromised by malware or a compromised email mailbox begins sending spam, major global anti-spam networks (Spamhaus, Microsoft Outlook Smart Network Data Services, Gmail) blacklist the server’s primary public IP address.
As a result, every other legitimate corporate client hosted on that server experiences blocked outbound emails.
To insulate high-value corporate clients and e-commerce stores from shared IP penalties, cPanel & WHM provides native support for multi-IP outbound routing via /etc/mailips and /etc/mailhelo.
By assigning dedicated outbound IPs and matching Forward-Confirmed Reverse DNS (FCrDNS) HELO banners to specific domains, sysadmins can completely isolate client email reputations.
In this guide, we configure automated multi-IP outbound routing in Exim, enforce rDNS alignment, and test delivery on enterprise bare-metal Dedicated Servers and Dedicated Servers in Pakistan.
1. How Exim Evaluates Outbound IPs and HELO Banners
When a cPanel user sends an email, Exim’s remote SMTP transport (remote_smtp) inspects /etc/mailips to determine the local network interface IP to bind to, and /etc/mailhelo to determine the hostname to announce in the initial EHLO handshake:
+--------------------------------------------------------------+
| Outbound Email Dispatched |
| From: [email protected] |
+------------------------------+-------------------------------+
|
v
+--------------------------------------------------------------+
| Exim remote_smtp Transport |
| - Queries /etc/mailips --> Binds socket to 198.51.100.55 |
| - Queries /etc/mailhelo --> Announces: mail.clientstore.pk |
+------------------------------+-------------------------------+
|
v (Matches PTR: 198.51.100.55 -> mail.clientstore.pk)
+--------------------------------------------------------------+
| Recipient Mail Server (Gmail / Outlook) |
| - Validates FCrDNS (Forward-Confirmed Reverse DNS) |
| - Reputation isolated to 198.51.100.55 |
| - Result: 100% Inbox Placement |
+--------------------------------------------------------------+
2. Enabling Multi-IP Support in WHM
Log in to WHM as root and navigate to:
Home » Service Configuration » Exim Configuration Manager.
In the Basic Editor tab:
- Search for: Reference /etc/mailips for outgoing SMTP connections
Set to: On. - Search for: Reference /etc/mailhelo for outgoing SMTP connections
Set to: On. - Search for: Send outgoing mail from the IP that matches the domain name in /etc/mailips (*: IP is default)
Set to: On.
Click Save at the bottom of the page. WHM will update /etc/exim.conf.localopts and restart Exim.
3. Configuring /etc/mailips and /etc/mailhelo
Step 1: Mapping Domains to Dedicated IPs (/etc/mailips)
Edit /etc/mailips via SSH:
nano /etc/mailips
Add domain-specific mappings followed by the server’s default fallback IP (*):
# High-Value Corporate Domain on Dedicated Clean IP
corporate.pk: 198.51.100.50
# E-commerce Store on Dedicated Transactional IP
clientstore.pk: 198.51.100.55
# Server Default Fallback for all other shared accounts
*: 198.51.100.2
Ensure file permissions are correct:
chmod 644 /etc/mailips
chown root:mail /etc/mailips
Step 2: Mapping Domains to FCrDNS HELO Hostnames (/etc/mailhelo)
Next, edit /etc/mailhelo:
nano /etc/mailhelo
Provide the corresponding hostname for each domain. The HELO banner must match the reverse DNS (PTR) record of the assigned IP:
# HELO matching PTR of 198.51.100.50
corporate.pk: mail.corporate.pk
# HELO matching PTR of 198.51.100.55
clientstore.pk: mail.clientstore.pk
# Fallback matching PTR of 198.51.100.2
*: server.nextgen.pk
Ensure file permissions:
chmod 644 /etc/mailhelo
chown root:mail /etc/mailhelo
4. Validating Forward-Confirmed Reverse DNS (FCrDNS)
The most critical step in multi-IP routing is ensuring your PTR records match forward A records:
# 1. Verify PTR resolves to the configured HELO hostname
dig +short -x 198.51.100.55
# Expected Output: mail.clientstore.pk.
# 2. Verify forward A record of that hostname resolves back to the IP
dig +short mail.clientstore.pk
# Expected Output: 198.51.100.55
If forward and reverse records do not match perfectly, Gmail and Microsoft 365 will reject outbound emails with 550 5.7.1 Client host rejected: cannot find your reverse hostname.
5. Testing Outbound Routing via CLI
To verify that Exim binds to the correct IP when sending on behalf of clientstore.pk, send a test message using the swaks Swiss Army Knife for SMTP or via Exim CLI:
# Send test email originating from clientstore.pk
exim -v -odq [email protected] <<EOF
From: [email protected]
To: [email protected]
Subject: Multi-IP Verification Test
Testing outbound interface binding.
EOF
Run queue processing for this message:
exim -qff -v
Inspect Exim’s transmission log:
Connecting to mx.example.com [203.0.113.10]:25 ... connected
SMTP>> EHLO mail.clientstore.pk
...
SMTP<< 250-mx.example.com Hello mail.clientstore.pk [198.51.100.55]
Notice that Exim successfully bound its socket to 198.51.100.55 and greeted the remote server as mail.clientstore.pk!
For servers managing massive transactional volume alongside outbound IP rotation, review our guides on cPanel Exim Smarthost Relay and cPanel ModSecurity SecDataDir Tuning.
Deploy Dedicated Bare-Metal Servers with Dedicated Subnets
Protect your clients' email deliverability with clean, dedicated IP pools. Nextgen Hosting provides high-performance bare-metal dedicated servers with clean /28 and /27 IPv4 allocations, custom PTR reverse DNS delegation, and 24/7 network NOC support in Karachi and Islamabad.
