A renewed certificate on a DirectAdmin server has to reach five consumers: the web server, Exim, Dovecot, the panel on port 2222 and, on some builds, FTP. The website is checked most often, so it is usually the mail client warning or a monitoring alert on port 993 that reveals a service is still presenting the expired certificate. The cause is nearly always that the file was updated but the process was not told, or that the service is reading a different file than expected. This guide maps the files and the fixes.
Table of Contents
Short answer: Compare the notAfter date on each port with openssl s_client against the files in /etc/exim.cert, /usr/local/directadmin/conf/cacert.pem and the user’s domain certificate. If the file is new but the port is old, restart exim, dovecot or directadmin; if the file is old, the hostname certificate did not renew or sync, so check Provisioning history and remove any cron job or symlink that still overwrites /etc/exim.cert.
Where each service reads its certificate
The web server reads per-domain certificates from the user’s SSL directory, /usr/local/directadmin/data/users/USER/domains/example.com.cert and .key, referenced in each virtual host. DirectAdmin rewrites the configuration and reloads Apache, nginx or LiteSpeed after issuance, so this layer rarely lags.
Exim and Dovecot read the server’s main certificate from /etc/exim.cert and /etc/exim.key, which are the hostname’s certificate. Mail SNI, when mail_sni=1 is set in directadmin.conf, additionally makes both daemons present a domain’s own certificate when a client connects using mail.example.com, using the same per-domain files as the web server. Check the setting:
da config-get mail_sni
The panel itself uses /usr/local/directadmin/conf/cacert.pem and cakey.pem, with an optional carootcert.pem for the chain. Pure-FTPd or ProFTPD uses /etc/pure-ftpd.pem or the path in its configuration.
From 1.710 DirectAdmin syncs a manually installed server certificate to all of these locations when it is set from Admin Level → Server TLS Certificate. Before 1.710 a manual server certificate only reached the panel and had to be copied to Exim and Dovecot by hand, which is why older notes on this subject list cp commands. On a current build those copies are unnecessary and, worse, can be overwritten at the next sync.
Compare what is on disk with what is on the wire
First establish which services are stale. Query each port and read the expiry date:
for p in 443 465 993 2222; do
echo "== $p"; openssl s_client -connect mail.example.com:$p -servername mail.example.com </dev/null 2>/dev/null | openssl x509 -noout -enddate
done
openssl s_client -connect mail.example.com:587 -starttls smtp </dev/null 2>/dev/null | openssl x509 -noout -enddate
Then check the files:
openssl x509 -in /etc/exim.cert -noout -enddate
openssl x509 -in /usr/local/directadmin/conf/cacert.pem -noout -enddate
openssl x509 -in /usr/local/directadmin/data/users/USER/domains/example.com.cert -noout -enddate
Three outcomes are possible. If the file is new and the port is old, the service needs a restart. If the file is old too, the renewal never propagated. If the file is new for the domain but the mail ports show the hostname certificate, SNI is off or the client is connecting to a hostname that does not match a hosted domain.
Restart the right service
Exim and Dovecot load certificates at start-up, and Dovecot additionally caches them per login process, so a reload is not always enough. Restart both, and restart the panel if port 2222 was stale:
systemctl restart exim
systemctl restart dovecot
systemctl restart directadmin
DirectAdmin’s own task queue normally does this after a hostname certificate is issued or synced. If it repeatedly fails to, look at /var/log/directadmin/errortaskq.log for the entry from the last renewal; a common cause is a service restart that timed out because Exim was mid-delivery, which leaves the old process running.
When the file itself is stale
If /etc/exim.cert is old, the hostname’s certificate did not renew or was not synced. The hostname is a special case in the ACME system: it must resolve to this server and be reachable on port 80, and it is issued from the Server TLS Certificate page rather than under any user. Open Provisioning history and filter for the hostname. The failure modes are the same ones described in Certificate not renewing on DirectAdmin; the most frequent for hostnames is an A record left pointing at a previous server.
Once the hostname certificate issues, DirectAdmin writes it to the panel and, on 1.710 and later, to the Exim and Dovecot paths, then queues the restarts. Confirm the write happened with the enddate check above before restarting anything.
Common pitfall: a stray manual copy or symlink
Servers that were administered before 1.710 often carry a cron job or a custom hook that copies a certificate into /etc/exim.cert, or a symlink pointing it at one user’s domain certificate. These were reasonable workarounds at the time and now fight the built-in sync: the panel writes the new hostname certificate, the old cron job writes the old one back an hour later. Check for both:
ls -l /etc/exim.cert /etc/exim.key
grep -rl 'exim.cert' /etc/cron* /usr/local/directadmin/scripts/custom/ 2>/dev/null
Remove the manual mechanism and let the panel own the files.
Verify
Re-run the port loop from above and confirm every port reports the same future notAfter date as the file on disk. Then send a message through port 587 with STARTTLS from a client that verifies certificates, and log in over IMAP on 993, because some mail clients keep a connection open and only show the fix after they reconnect. Add the mail ports to the SSL expiry check schedule so the next renewal is confirmed on all services rather than only on the website.
DirectAdmin old certificate at a glance

Official documentation: Exim documentation, Dovecot documentation, Let’s Encrypt documentation.
Related guides: KernelCare on cPanel and DirectAdmin servers: setup, verification and rollback · Enabling ModSecurity with OWASP CRS or Comodo rules on DirectAdmin and managing per-domain exclusions · Installing and tuning CSF/LFD on DirectAdmin (the DirectAdmin fork, post-1.689 defaults).
Frequently asked questions
Does mail SNI on DirectAdmin also cover Exim on port 587?
Yes. With mail_sni=1 both Exim (ports 25, 465 and 587 with STARTTLS or implicit TLS) and Dovecot (143 and 993) present the hosted domain’s certificate when the client connects using a hostname that matches a domain on the server.
How long does it take for a renewed certificate to reach Exim and Dovecot?
On 1.710 and later the sync and the queued restarts normally complete within a minute or two of the hostname certificate being issued; if the ports still show the old date after five minutes, check errortaskq.log for a failed restart.
Can I undo this?
Yes. Restarting services has no lasting effect, and a removed cron job or symlink can be recreated, although on 1.710 and later the panel’s own sync makes the manual copy unnecessary and they will fight each other if both exist.