cPanel Exim Outgoing Sender Rate Limits & Compromised Account Defense in Pakistan

Configure cPanel Exim RATELIMIT_MAIL rules, automated outbound throttling, and compromised mailbox isolation to safeguard server IP reputation in Pakistan.

cPanel Exim Outgoing Sender Rate Limits & Compromised Account Defense in Pakistan

Web hosting providers and enterprise organizations in Pakistan face constant cyber threats targeting corporate email accounts. Weak passwords, phishing campaigns, or compromised employee workstations frequently result in stolen email credentials. Within minutes of a breach, automated botnets hijack the authenticated SMTP account to blast tens of thousands of spam or phishing emails through the server’s Exim MTA.

By the time human administrators discover the breach, the server’s public IPv4 address has landed on major international spam blacklists (Spamhaus SBL/XBL, SURBL, Barracuda, SpamCop). Legitimate business correspondence to Gmail, Microsoft 365, and Pakistani financial institutions bounces instantly with 554 5.7.1 Service unavailable; Client host blocked.

Operating enterprise email fleets on bare-metal Dedicated Servers provides dedicated, clean IP subnets, but maintaining a pristine sender reputation requires aggressive, automated outgoing rate limiting and real-time compromised account isolation within Exim.


The Anatomy of an Outbound Spam Attack

When an authenticated email account is compromised:

  1. The Breach: Attackers authenticate via SMTP over port 587/465 using valid credentials ([email protected]).
  2. The Burst: The spam script dispatches 50 to 200 concurrent threads, pumping 5,000+ emails per minute through Exim’s outgoing spool.
  3. The Consequence: Without hard per-sender rate limits, Exim queues every message in /var/spool/exim/input/. Recipient MTAs throttle the server IP, leading to massive mail queue build-ups and widespread reputation blacklisting.
Compromised Mailbox ([email protected])
               │
               ▼ (Attempts 10,000 Outbound Spam/Hour)
   [Exim Outgoing ACL Filter]
               │
   ┌───────────┴───────────┐
   ▼                       ▼
Under 200/hr Cap         Exceeds 200/hr Threshold
(Legitimate Business)    ──► [AUTO-BLOCK SENDER]
                               - Freeze Outbound Queue
                               - Lock Mailbox Password
                               - Alert Admin via Telegram/Email

Step 1: Enforcing Hourly Domain & Mailbox Limits in WHM

cPanel provides baseline outbound email limits, but they must be configured defensively.

In WHM > Service Configuration > Mailserver Configuration and Tweak Settings:

  1. Max hourly emails per domain: Set to 200 or 300 (adjust per corporate volume).
  2. Count recipient count towards hourly limit: Enable (On). (Prevents an account from evading limits by sending 1 email with 1,000 BCC addresses).
  3. Action when limit is reached: Set to Hold outgoing mail or Fail outgoing mail.

Apply via the cPanel command-line interface:

# Set global default hourly limit per cPanel account to 250
whmapi1 set_tweaksetting key=maxemailsperhour value=250

# Enable recipient counting toward limits
whmapi1 set_tweaksetting key=count_recipients_towards_ratelimit value=1

Set custom per-domain overrides for high-volume corporate clients in /var/cpanel/maxemailsperhour/:

# Grant elevated quota to verified high-volume transactional domain
echo "1500" > /var/cpanel/maxemailsperhour/verifieddomain.pk

Step 2: Advanced Exim ACL Rate Limiting by Authenticated User

Domain-wide limits can still allow a single compromised mailbox to consume the domain’s entire hourly quota. We must enforce granular per-mailbox limits using Exim ACL rules.

Add a custom ACL rule in /etc/exim.conf.local under the custom_begin_mail section:

# /etc/exim.conf.local - Granular Per-Mailbox Rate Limiting

check_mail:
  # Enforce strict 100 emails per 15 minutes per authenticated user
  deny
    authenticated = *
    ratelimit     = 100 / 15m / strict / $authenticated_id
    message       = Authenticated account $authenticated_id has exceeded outbound sending limits (100 msgs/15m). Please contact support.
    log_message   = RATELIMIT_EXCEEDED: $authenticated_id sending too rapidly ($sender_rate msgs / $sender_rate_period)

  # Enforce 30 recipients per single message to stop mass BCC spam
  deny
    authenticated = *
    condition     = ${if >{$recipients_count}{30}{yes}{no}}
    message       = Maximum recipient limit per message exceeded (Max 30).

Rebuild and reload the Exim service:

/scripts/buildeximconf
/scripts/restartsrv_exim

Step 3: Automated Detection & Isolation Script

Deploy an automated bash monitor /usr/local/bin/isolate_spammer.sh run every 5 minutes via cron. It scans Exim’s log for compromised accounts and automatically suspends outbound access:

#!/bin/bash
# /usr/local/bin/isolate_spammer.sh - Auto-quarantine compromised cPanel mailboxes

THRESHOLD=300
LOGFILE="/var/log/exim_mainlog"
TIMEFRAME="1 hour ago"

# Extract authenticated senders exceeding THRESHOLD within the last hour
grep -E "A=(fixed_plain|dovecot_login|dovecot_plain):" $LOGFILE | \
  awk -F'A=' '{print $2}' | awk '{print $1}' | \
  sed 's/.*://' | sort | uniq -c | sort -nr | \
  while read count user; do
    if [ "$count" -gt "$THRESHOLD" ] && [ -n "$user" ]; then
      echo "[ALERT] Compromised account detected: $user sent $count emails!"
      
      # Suspend outgoing email for the specific mailbox via WHM API
      u_account=$(echo $user | cut -d'@' -f2)
      whmapi1 suspend_outgoing_email user=$u_account
      
      # Alert systems administrator
      echo "Suspended outgoing mail for $user ($count msgs). Immediate password reset required." | \
        mail -s "CRITICAL: Outbound Spam Isolated on $HOSTNAME ($user)" [email protected]
    fi
done

Make executable and register with crontab:

chmod +x /usr/local/bin/isolate_spammer.sh
(crontab -l 2>/dev/null; echo "*/5 * * * * /usr/local/bin/isolate_spammer.sh >/dev/null 2>&1") | crontab -

Auditing Exim Queue Health in Real Time

Inspect live queue volume and isolate frozen spam chunks:

# Count total messages queued in Exim
exim -bpc

# Inspect top sender domains in active queue
exim -bp | exiqsumm | head -n 15

# Purge frozen spam messages from compromised accounts instantly
exiqgrep -z -i | xargs -r exim -Mrm

Hosting enterprise mail services on bare-metal Dedicated Servers in Pakistan ensures low-latency domestic delivery, clean IP subnets, and proactive security shields that protect corporate email reputation across global inboxes.


Defend Your Email Reputation with NextGen Dedicated Servers

Protect your corporate domains against IP blacklisting and compromised accounts. Deploy enterprise cPanel mail clusters with automated rate limiting and dedicated IP pools in Pakistan.

Explore Pakistan Dedicated Servers