# DirectAdmin Rspamd vs SpamAssassin: DKIM and DMARC Setup

Source: https://srvscripts.com/guides/directadmin-rspamd-vs-spamassassin/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

DirectAdmin ships Exim 4.100 and Dovecot 2.4 through CustomBuild, and lets you run either Rspamd or SpamAssassin as the content filter. The two are not equivalent: Rspamd is a modern, fast daemon with built-in DKIM, DMARC and rate-limiting modules, while SpamAssassin is the older Perl scanner that most administrators already know. Since 1.704 the headers that Exim adds are unified across both, so switching does not break customer mail rules. Authentication of outbound mail — DKIM, SPF and DMARC — is handled by DirectAdmin’s DNS templates and Exim configuration independently of which scanner you choose.

In short: Use Rspamd wherever CustomBuild offers it and fall back to SpamAssassin only on platforms without rspamd packages, switching with ./build set spamd rspamd, ./build rspamd and ./build exim_conf.

**Short answer:** Use Rspamd wherever CustomBuild offers it and fall back to SpamAssassin only on platforms without rspamd packages, switching with `./build set spamd rspamd`, `./build rspamd` and `./build exim_conf`. Turn on DKIM with `da config-set dkim 1` and `dkim_create.sh` per domain, and put SPF and a `_dmarc` record in a custom `dns_txt.conf` template so every zone publishes them, starting DMARC at `p=none`.

## Choosing the scanner

Rspamd is the better default on any server that has it available. It scans in milliseconds rather than seconds, learns from user actions when the Dovecot integration is enabled, and publishes a web interface with per-symbol statistics. SpamAssassin is the right choice only where Rspamd cannot be installed: AlmaLinux 10 and other RHEL 10-family systems currently have no rspamd packages in CustomBuild, so a fresh install there defaults to SpamAssassin. On those servers the `sa_update` cron added in 1.694 keeps the ruleset current daily.

Check what the server runs and switch if needed:

```
cd /usr/local/directadmin/custombuild
./build options | grep -E 'spamd|eximconf'
./build set spamd rspamd
./build set eximconf yes
./build rspamd
./build exim_conf
```

To go the other way, set `spamd spamassassin` and run `./build spamassassin` followed by `./build exim_conf`. The `eximconf` rebuild is what rewires Exim’s ACLs to the chosen scanner; forgetting it leaves Exim calling a daemon that is no longer running and mail queues with temporary errors.

Rspamd’s local overrides go in `/etc/rspamd/local.d/`, not in the generated files under `/etc/rspamd/`. For example, to relax the reject threshold on a server that prefers to tag rather than bounce, create `/etc/rspamd/local.d/actions.conf` with `reject = 20;` and `add_header = 6;`, then `systemctl restart rspamd`. Per-user thresholds are set from **User Level → Spam Filters** in the Evolution skin.

## DKIM signing

DirectAdmin generates DKIM keys per domain and publishes the public key in the domain’s zone when the feature is on globally. Enable it and generate keys for existing domains:

```
da config-set dkim 1
/usr/local/directadmin/scripts/dkim_create.sh example.com
```

Keys are written to `/etc/virtual/example.com/dkim.private.key` and `dkim.public.key`, and Exim signs outbound mail using the selector `x` by default. For every domain on the server, loop over `/etc/virtual/domainowners` and call the script for each; new domains get keys automatically once `dkim=1` is set. Domains with external DNS need the TXT record copied from **User Level → DNS Management** to the external provider, or signing produces a valid signature that no receiver can verify.

## SPF records

DirectAdmin adds an SPF policy as a TXT record from the `dns_txt.conf` template; the separate `SPF` record type was removed in 1.694 because resolvers ignore it. The default policy authorises the server’s A record and MX and ends with `~all`. If the server relays through a smarthost or customers send from a third-party service, the template needs the extra `include:` mechanisms. Override the template rather than the generated file:

```
mkdir -p /usr/local/directadmin/data/templates/custom
cp /usr/local/directadmin/data/templates/dns_txt.conf /usr/local/directadmin/data/templates/custom/
# edit the custom copy, then rewrite zones:
echo "action=rewrite&value=named" >> /usr/local/directadmin/data/task.queue
```

Custom templates survive updates; edits to the non-custom copy do not.

## DMARC

A DMARC record tells receivers what to do when SPF and DKIM fail and where to send reports. Add a `_dmarc` TXT entry to the same custom `dns_txt.conf` template so every domain gets one:

```
_dmarc="v=DMARC1; p=none; rua=mailto:dmarc-reports@your-hosting-domain.net; adkim=r; aspf=r"
```

Start with `p=none` and collect reports for a few weeks. Move to `p=quarantine` only after confirming that all legitimate sending sources — the server, any smarthost, any newsletter tool — pass alignment. A `p=reject` policy pushed out server-wide without that check silently kills mail for customers who send through external services you did not know about.

## Common pitfall: the hostname is not a hosted domain

Outbound mail from cron jobs, the panel itself and system notifications is sent as the server hostname. That hostname is not in `/etc/virtual/domainowners`, so it has no DKIM key and often no SPF record. Receivers then see unauthenticated mail from your server IP, which damages the reputation that all the customer domains depend on. Create the hostname’s zone in **Admin Level → DNS Administration**, add SPF and a DKIM key for it with `dkim_create.sh`, and confirm Exim signs it.

## Verify

Send a message from a hosted domain to a mailbox you control and inspect the headers for `Authentication-Results` showing `dkim=pass`, `spf=pass` and `dmarc=pass`. From the server side:

```
dig +short TXT x._domainkey.example.com
dig +short TXT example.com | grep spf
dig +short TXT _dmarc.example.com
exim -bV | head -n 1
systemctl status rspamd --no-pager
```

Then watch the queue for a day with the [Exim mail queue report](/scripts/exim-mail-queue-report/); a sudden rise in deferred mail after switching scanners almost always means the `exim_conf` rebuild was skipped. When spam does originate from a hosted account, the approach in [Finding the source of outgoing spam](/guides/find-source-of-outgoing-spam-cpanel/) applies to DirectAdmin’s Exim logs as well.

## DirectAdmin Rspamd at a glance

**Official documentation:** [RFC 7489 (DMARC)](https://www.rfc-editor.org/rfc/rfc7489), [RFC 7208 (SPF)](https://www.rfc-editor.org/rfc/rfc7208), [RFC 6376 (DKIM)](https://www.rfc-editor.org/rfc/rfc6376).

**Related guides:** [Configuring DirectAdmin’s Exim to relay through MailBaby](https://srvscripts.com/guides/directadmin-exim-mailbaby-relay/) · [Setting a custom webmail URL and branding Roundcube 1.7 on DirectAdmin](https://srvscripts.com/guides/directadmin-roundcube-branding-webmail/) · [Choosing a VPS for a cPanel or DirectAdmin server in 2026](https://srvscripts.com/guides/best-vps-for-cpanel-directadmin-server/).

## Frequently asked questions

### Does switching from SpamAssassin to Rspamd keep users’ existing spam settings?

Mostly. The per-user thresholds set in Spam Filters are carried over because Exim’s headers have been unified since 1.704, but SpamAssassin’s Bayes training data and custom `user_prefs` rules do not transfer, so Rspamd starts learning afresh through its Dovecot integration.

### How long does DKIM take to start working after enabling it on DirectAdmin?

Signing starts as soon as the key exists and Exim is reloaded, and receivers can verify it once the `x._domainkey` TXT record has propagated, which for zones hosted on the server is usually within the record’s TTL of an hour or less.

### Can I undo this?

Yes. Set `spamd` back to the previous scanner and rebuild `exim_conf`, set `dkim 0` with `da config-set` to stop signing, and remove the custom `dns_txt.conf` template followed by a `named` rewrite to drop the SPF and DMARC additions.
