Operating an enterprise cPanel & WHM mail server in Pakistan presents unique email deliverability challenges. Due to historic spam abuse and mismanaged dynamic IP pools by local transit providers, entire Pakistani Autonomous System Number (ASN) subnets (such as PTCL, Nayatel, and StormFiber allocations) are frequently blacklisted on global DNSBLs like Spamhaus ZEN, Barracuda, and SORBS.
Even if your dedicated cPanel server practices pristine email hygiene—with valid SPF, DKIM, DMARC, and reverse DNS (PTR) records—major mailbox providers (Gmail, Outlook 365, Yahoo) will reject your outbound mail with diagnostic codes like:
550 5.7.1 Service unavailable; Client host [x.x.x.x] blocked using Spamhaus.
The industry-standard solution is configuring Exim Smarthost Relaying. By instructing Exim to route outbound emails through a high-reputation transactional SMTP relay—such as Amazon SES, SendGrid, or Mailgun—your server completely bypasses ISP IP reputation penalties.
In this technical guide, we configure an authenticated Exim smarthost in WHM, construct per-domain routing maps, and verify delivery on enterprise Dedicated Servers and Dedicated Servers in Pakistan.
1. Smarthost Relaying Architecture
Instead of resolving the destination MX record directly, Exim encapsulates outbound mail and hands it off to the authenticated relay over an encrypted TLS channel on port 587:
[cPanel Web Host / Exim]
|
| 1. Intercepts outbound email from webmail or PHP mail()
v
[Exim Router: send_via_ses]
|
| 2. Authenticated TLS Connection (Port 587) with SES Credentials
v
[Amazon SES / SendGrid Cloud Relay]
|
| 3. High-Reputation Global Delivery (Dedicated IP Pools)
v
[Recipient Mailbox: Gmail / Microsoft 365 / Yahoo]
2. Step-by-Step Exim Configuration in WHM
Log in to WHM as root and navigate to:
Home » Service Configuration » Exim Configuration Manager » Advanced Editor.
Section 1: AUTH Configuration
Locate the Section: AUTH textarea in the Advanced Editor. Insert your SMTP relay credentials (replace with your Amazon SES SMTP username and secret key):
ses_login:
driver = plaintext
public_name = LOGIN
client_send = : AKIAIOSFODNN7EXAMPLE : wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
[!NOTE] For SendGrid, set the username to
apikeyand the password to your 69-character API key string.
Section 2: ROUTERSTART Configuration
Scroll down to Section: ROUTERSTART. This defines the routing rule that captures outbound mail before standard DNS lookup routers (dnslookup):
send_via_ses:
driver = manualroute
domains = ! +local_domains
senders = ! : ! *@localhost : ! *@*.local
transport = ses_smtp
route_list = * email-smtp.us-east-1.amazonaws.com::587
domains = ! +local_domains: Ensures local mail sent between accounts on the same cPanel server is delivered locally without touching the smarthost.route_list = * email-smtp.us-east-1.amazonaws.com::587: Directs all external domains to Amazon SES on port 587. (For SendGrid, usesmtp.sendgrid.net::587).
Section 3: TRANSPORTSTART Configuration
Locate Section: TRANSPORTSTART. This configures the actual SMTP client transport:
ses_smtp:
driver = smtp
port = 587
hosts_require_auth = *
hosts_require_tls = *
serialize_hosts = *
Click Save at the bottom of the page. WHM will automatically compile the configuration into /etc/exim.conf and restart the Exim mail service.
3. Configuring Selective Per-Domain Smarthost Routing
In a multi-tenant shared hosting environment, you may only want specific e-commerce or corporate domains to use the paid Amazon SES relay, while allowing general accounts to send directly.
Create a domain mapping file /etc/exim_ses_domains:
touch /etc/exim_ses_domains
chmod 644 /etc/exim_ses_domains
Add the domains allowed to use the relay:
corporate.pk
clientstore.com
In the ROUTERSTART section, update send_via_ses to inspect this file:
send_via_ses_selective:
driver = manualroute
domains = ! +local_domains
senders = lsearch;/etc/exim_ses_domains
transport = ses_smtp
route_list = * email-smtp.us-east-1.amazonaws.com::587
Now, only emails sent from identities matching /etc/exim_ses_domains will route through the relay.
4. Testing & Verifying Deliverability via CLI
To verify that Exim correctly matches the smarthost router without delivering actual test spam, run Exim’s address testing utility:
exim -bt [email protected]
Expected output confirms the router:
[email protected]
router = send_via_ses, transport = ses_smtp
host email-smtp.us-east-1.amazonaws.com [54.240.27.123] port=587
Now send an interactive test message with verbose debug logging:
exim -v -odq [email protected] <<EOF
From: [email protected]
To: [email protected]
Subject: Nextgen Exim Smarthost Test
This message was routed successfully through the authenticated Amazon SES smarthost.
EOF
Force the queue runner on that message:
exim -qff -v
Look for 250 Ok [Message accepted for delivery] directly from Amazon SES.
To ensure your server remains fully protected against compromised account spam floods while relaying, pair your smarthost with our guides on Custom CSF/LFD Regex Rules and cPanel ChkServd Auto-Healing.
Deploy Dedicated Bare-Metal Servers with Clean IP Subnets
Protect your brand deliverability and eliminate spam blocklist headaches. Nextgen Hosting provides dedicated bare-metal servers with pristine IP reputation ranges, PTR reverse DNS delegation, and 24/7 network NOC support in Karachi and Islamabad.
