How to Configure cPanel & WHM Exim Smarthost SMTP Relay (Amazon SES & SendGrid) to Bypass IP Blacklists in Pakistan

A complete step-by-step sysadmin guide to configuring an authenticated Exim smarthost relay with Amazon SES or SendGrid on cPanel servers in Pakistan to eliminate IP reputation blocks and guarantee 100% inbox placement.

How to Configure cPanel & WHM Exim Smarthost SMTP Relay (Amazon SES & SendGrid) to Bypass IP Blacklists in Pakistan

Operating an enterprise cPanel & WHM mail server in Pakistan presents unique email deliverability challenges. Due to historic spam abuse and mismanaged dynamic IP pools by local transit providers, entire Pakistani Autonomous System Number (ASN) subnets (such as PTCL, Nayatel, and StormFiber allocations) are frequently blacklisted on global DNSBLs like Spamhaus ZEN, Barracuda, and SORBS.

Even if your dedicated cPanel server practices pristine email hygiene—with valid SPF, DKIM, DMARC, and reverse DNS (PTR) records—major mailbox providers (Gmail, Outlook 365, Yahoo) will reject your outbound mail with diagnostic codes like: 550 5.7.1 Service unavailable; Client host [x.x.x.x] blocked using Spamhaus.

The industry-standard solution is configuring Exim Smarthost Relaying. By instructing Exim to route outbound emails through a high-reputation transactional SMTP relay—such as Amazon SES, SendGrid, or Mailgun—your server completely bypasses ISP IP reputation penalties.

In this technical guide, we configure an authenticated Exim smarthost in WHM, construct per-domain routing maps, and verify delivery on enterprise Dedicated Servers and Dedicated Servers in Pakistan.


1. Smarthost Relaying Architecture

Instead of resolving the destination MX record directly, Exim encapsulates outbound mail and hands it off to the authenticated relay over an encrypted TLS channel on port 587:

[cPanel Web Host / Exim]
        |
        | 1. Intercepts outbound email from webmail or PHP mail()
        v
[Exim Router: send_via_ses]
        |
        | 2. Authenticated TLS Connection (Port 587) with SES Credentials
        v
[Amazon SES / SendGrid Cloud Relay]
        |
        | 3. High-Reputation Global Delivery (Dedicated IP Pools)
        v
[Recipient Mailbox: Gmail / Microsoft 365 / Yahoo]

2. Step-by-Step Exim Configuration in WHM

Log in to WHM as root and navigate to:
Home » Service Configuration » Exim Configuration Manager » Advanced Editor.

Section 1: AUTH Configuration

Locate the Section: AUTH textarea in the Advanced Editor. Insert your SMTP relay credentials (replace with your Amazon SES SMTP username and secret key):

ses_login:
  driver = plaintext
  public_name = LOGIN
  client_send = : AKIAIOSFODNN7EXAMPLE : wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY

[!NOTE] For SendGrid, set the username to apikey and the password to your 69-character API key string.

Section 2: ROUTERSTART Configuration

Scroll down to Section: ROUTERSTART. This defines the routing rule that captures outbound mail before standard DNS lookup routers (dnslookup):

send_via_ses:
  driver = manualroute
  domains = ! +local_domains
  senders = ! : ! *@localhost : ! *@*.local
  transport = ses_smtp
  route_list = * email-smtp.us-east-1.amazonaws.com::587
  • domains = ! +local_domains: Ensures local mail sent between accounts on the same cPanel server is delivered locally without touching the smarthost.
  • route_list = * email-smtp.us-east-1.amazonaws.com::587: Directs all external domains to Amazon SES on port 587. (For SendGrid, use smtp.sendgrid.net::587).

Section 3: TRANSPORTSTART Configuration

Locate Section: TRANSPORTSTART. This configures the actual SMTP client transport:

ses_smtp:
  driver = smtp
  port = 587
  hosts_require_auth = *
  hosts_require_tls = *
  serialize_hosts = *

Click Save at the bottom of the page. WHM will automatically compile the configuration into /etc/exim.conf and restart the Exim mail service.


3. Configuring Selective Per-Domain Smarthost Routing

In a multi-tenant shared hosting environment, you may only want specific e-commerce or corporate domains to use the paid Amazon SES relay, while allowing general accounts to send directly.

Create a domain mapping file /etc/exim_ses_domains:

touch /etc/exim_ses_domains
chmod 644 /etc/exim_ses_domains

Add the domains allowed to use the relay:

corporate.pk
clientstore.com

In the ROUTERSTART section, update send_via_ses to inspect this file:

send_via_ses_selective:
  driver = manualroute
  domains = ! +local_domains
  senders = lsearch;/etc/exim_ses_domains
  transport = ses_smtp
  route_list = * email-smtp.us-east-1.amazonaws.com::587

Now, only emails sent from identities matching /etc/exim_ses_domains will route through the relay.


4. Testing & Verifying Deliverability via CLI

To verify that Exim correctly matches the smarthost router without delivering actual test spam, run Exim’s address testing utility:

exim -bt [email protected]

Expected output confirms the router:

[email protected]
  router = send_via_ses, transport = ses_smtp
  host email-smtp.us-east-1.amazonaws.com [54.240.27.123] port=587

Now send an interactive test message with verbose debug logging:

exim -v -odq [email protected] <<EOF
From: [email protected]
To: [email protected]
Subject: Nextgen Exim Smarthost Test

This message was routed successfully through the authenticated Amazon SES smarthost.
EOF

Force the queue runner on that message:

exim -qff -v

Look for 250 Ok [Message accepted for delivery] directly from Amazon SES.

To ensure your server remains fully protected against compromised account spam floods while relaying, pair your smarthost with our guides on Custom CSF/LFD Regex Rules and cPanel ChkServd Auto-Healing.


CLEAN EMAIL REPUTATION & UNMETERED SPEED

Deploy Dedicated Bare-Metal Servers with Clean IP Subnets

Protect your brand deliverability and eliminate spam blocklist headaches. Nextgen Hosting provides dedicated bare-metal servers with pristine IP reputation ranges, PTR reverse DNS delegation, and 24/7 network NOC support in Karachi and Islamabad.