cPanel Exim Sender Rewriting Scheme (SRS) for SPF Email Forwarding

Fix SPF email forwarding delivery rejections to Gmail, Yahoo, and Microsoft 365 on cPanel & WHM. Implement native Exim Sender Rewriting Scheme (SRS) in Pakistan.

cPanel Exim Sender Rewriting Scheme (SRS) for SPF Email Forwarding

Email forwarding has long been a core convenience for web hosting customers across Pakistan: an employee receives emails at [email protected] and forwards them automatically to their personal gmail.com or corporate outlook.com mailbox. However, in today’s strictly enforced email authentication ecosystem, standard mail forwarding without envelope manipulation is virtually dead on arrival.

When an external sender (e.g., [email protected]) sends an email to [email protected], the originating sender’s domain SPF record authorizes only the bank’s IP addresses. If your cPanel server blindly forwards that raw email to Gmail, Google checks the incoming connection IP (your Dedicated Server in Pakistan), verifies that your IP is not authorized in bank.com’s SPF record, and rejects the message with 550 5.7.26 SPF check failed or relegates it to spam.

The solution is the Sender Rewriting Scheme (SRS). By rewriting the envelope sender address (MAIL FROM:) while preserving the human-visible From: header, cPanel’s MTA (Exim) aligns the SPF envelope check with your server’s authorized domain, ensuring 100% forwarding deliverability.


How Sender Rewriting Scheme (SRS) Works

SRS solves the SPF forwarding paradox by encapsulating the original envelope sender inside a uniquely signed cryptographic string belonging to your local forwarding host:

1. Original Email Inbound:
   MAIL FROM: <[email protected]>
   RCPT TO:   <[email protected]>
   From:      "Client Name" <[email protected]>

2. Standard (Broken) Forwarding Outbound:
   MAIL FROM: <[email protected]>            <-- Checks bank.com SPF against your IP -> FAIL!
   RCPT TO:   <[email protected]>

3. SRS (Corrected) Forwarding Outbound:
   MAIL FROM: <[email protected]>  <-- Checks business.pk SPF -> PASS!
   RCPT TO:   <[email protected]>
   From:      "Client Name" <[email protected]>            <-- End-user sees original sender

Anatomical Structure of an SRS Address:

  • SRS0: Indicates a forward-hop SRS rewrite.
  • HHH: A base64-encoded HMAC-SHA1 cryptographic hash verifying that the address was minted by your server (preventing your mail server from becoming an open relay for bounced spam).
  • TT: A 2-character timestamp indicating the expiration window of the forwarded bounce token (typically 21 days).
  • bank.com: The original sender domain.
  • sender: The original mailbox username.
  • @business.pk: Your server’s authenticated domain, whose SPF record explicitly authorizes your server’s outbound IP address.

If Gmail subsequently bounces the forwarded email, the bounce notification travels to [email protected]. Exim verifies the cryptographic HMAC token, extracts [email protected], and delivers the bounce notification back to the true originator.


Step-by-Step: Enabling SRS in cPanel & WHM

cPanel natively bundles support for SRS via compiled Exim modules.

Step 1: Enable SRS via WHM Interface

  1. Log into WHM as root.
  2. Navigate to Service Configuration >> Exim Configuration Manager.
  3. Under the Basic Editor, select the Mail tab.
  4. Locate the setting Enable Sender Rewriting Scheme (SRS) Support.
  5. Set this option to On.
  6. Scroll down and click Save.

WHM will recompile the Exim runtime configuration /etc/exim.conf and restart the mail service.


Verifying and Hardening SRS in /etc/exim.conf.local

For system administrators operating multi-tenant environments on a Dedicated Server, inspect the underlying Exim configuration to ensure secrets and HMAC keys are properly isolated.

1. Verify SRS Secret Key Generation

Exim uses a shared cryptographic secret stored at /etc/exim_srs.secret to sign outgoing rewritten envelopes. Verify this file exists and contains high-entropy randomness:

ls -la /etc/exim_srs.secret
# Ensure permissions are strictly locked to mailnull/mail
# -rw------- 1 mailnull mail 32 Oct  4 18:00 /etc/exim_srs.secret

If the secret file is missing or corrupted, generate a 256-bit cryptographic secret:

openssl rand -hex 16 > /etc/exim_srs.secret
chown mailnull:mail /etc/exim_srs.secret
chmod 0600 /etc/exim_srs.secret
/usr/local/cpanel/scripts/restartsrv_exim

2. Inspecting the Exim Router Directives

When SRS is enabled, cPanel injects specialized routers into /etc/exim.conf:

# Inbound Bounce De-rewriting Router
srs_bounce_router:
  driver = redirect
  data = ${srs_dbounce:$local_part@$domain}
  domains = ! +local_domains
  no_verify

# Outbound Transport Forwarding Rewriting
srs_forward_router:
  driver = dnslookup
  domains = ! +local_domains
  transport = srs_smtp
  ignore_target_hosts = 0.0.0.0 : 127.0.0.0/8
  no_more

Live Testing & Delivery Diagnostics

From an external email account (or using a testing mailbox on a remote Cloud VPS), send an email to a forwarded cPanel mailbox:

  1. Send an email from [email protected] to [email protected].
  2. Tail the active Exim main log on your cPanel server:
tail -f /var/log/exim_mainlog | grep -E "SRS|Completed"

Diagnostic Delivery Log:

2026-10-05 00:22:15 1sX8zK-0004L2-1Q <= [email protected] H=mail.remote.com [198.51.100.24]:43210 P=esmtps X=TLS1.3 S=3421 [email protected]
2026-10-05 00:22:16 1sX8zK-0004L2-1Q => [email protected] <[email protected]> R=srs_forward_router T=remote_smtp H=gmail-smtp-in.l.google.com [142.250.153.26]:25 X=TLS1.3 CV=yes DN="*.google.com" K C="250 2.0.0 OK 1728087736 s12-20020a1709067b0c00b00a68d0e5f24asi2381989ejw.12 - gsmtp"
2026-10-05 00:22:16 1sX8zK-0004L2-1Q Completed
  1. Open the forwarded message inside Gmail and click Show Original.

Forwarding Deliverability Comparison Matrix

Email Authentication Mechanism Raw Forwarding (No SRS) With Exim SRS Enabled
SPF Evaluation FAIL (Softfail or Hardfail) PASS (Evaluated against forwarder IP)
DKIM Evaluation PASS (If body untouched) PASS (Body unmodified; header preserved)
DMARC Evaluation FAIL (If SPF strict & DKIM broken) PASS (Valid SPF alignment on forwarder)
Bounces & NDRs Lost or dropped by upstream Cryptographically verified & routed to sender
Spam Reputation Impact Severe (Your IP marked as spam source) Clean (Authorized forwarder footprint)

For further technical mail server optimizations, review our guides on cPanel Exim Multi-IP Outbound Rotation and cPanel Exim Smarthost SMTP Relay Setup.

High-Deliverability Mail Hosting
Deploy Dedicated Bare-Metal Servers Tuned for Enterprise Email

Protect your transactional deliverability, eliminate forwarding bounces, and scale corporate cPanel mail fleets with clean IP ranges, automated rDNS/PTR, and high-performance server hosting in Pakistan.