DirectAdmin ships Exim 4.100 and Dovecot 2.4 through CustomBuild, and lets you run either Rspamd or SpamAssassin as the content filter. The two are not equivalent: Rspamd is a modern, fast daemon with built-in DKIM, DMARC and rate-limiting modules, while SpamAssassin is the older Perl scanner that most administrators already know. Since 1.704 the headers that Exim adds are unified across both, so switching does not break customer mail rules. Authentication of outbound mail — DKIM, SPF and DMARC — is handled by DirectAdmin’s DNS templates and Exim configuration independently of which scanner you choose.
Table of Contents
Short answer: Use Rspamd wherever CustomBuild offers it and fall back to SpamAssassin only on platforms without rspamd packages, switching with ./build set spamd rspamd, ./build rspamd and ./build exim_conf. Turn on DKIM with da config-set dkim 1 and dkim_create.sh per domain, and put SPF and a _dmarc record in a custom dns_txt.conf template so every zone publishes them, starting DMARC at p=none.
Choosing the scanner
Rspamd is the better default on any server that has it available. It scans in milliseconds rather than seconds, learns from user actions when the Dovecot integration is enabled, and publishes a web interface with per-symbol statistics. SpamAssassin is the right choice only where Rspamd cannot be installed: AlmaLinux 10 and other RHEL 10-family systems currently have no rspamd packages in CustomBuild, so a fresh install there defaults to SpamAssassin. On those servers the sa_update cron added in 1.694 keeps the ruleset current daily.
Check what the server runs and switch if needed:
cd /usr/local/directadmin/custombuild
./build options | grep -E 'spamd|eximconf'
./build set spamd rspamd
./build set eximconf yes
./build rspamd
./build exim_conf
To go the other way, set spamd spamassassin and run ./build spamassassin followed by ./build exim_conf. The eximconf rebuild is what rewires Exim’s ACLs to the chosen scanner; forgetting it leaves Exim calling a daemon that is no longer running and mail queues with temporary errors.
Rspamd’s local overrides go in /etc/rspamd/local.d/, not in the generated files under /etc/rspamd/. For example, to relax the reject threshold on a server that prefers to tag rather than bounce, create /etc/rspamd/local.d/actions.conf with reject = 20; and add_header = 6;, then systemctl restart rspamd. Per-user thresholds are set from User Level → Spam Filters in the Evolution skin.
DKIM signing
DirectAdmin generates DKIM keys per domain and publishes the public key in the domain’s zone when the feature is on globally. Enable it and generate keys for existing domains:
da config-set dkim 1
/usr/local/directadmin/scripts/dkim_create.sh example.com
Keys are written to /etc/virtual/example.com/dkim.private.key and dkim.public.key, and Exim signs outbound mail using the selector x by default. For every domain on the server, loop over /etc/virtual/domainowners and call the script for each; new domains get keys automatically once dkim=1 is set. Domains with external DNS need the TXT record copied from User Level → DNS Management to the external provider, or signing produces a valid signature that no receiver can verify.
SPF records
DirectAdmin adds an SPF policy as a TXT record from the dns_txt.conf template; the separate SPF record type was removed in 1.694 because resolvers ignore it. The default policy authorises the server’s A record and MX and ends with ~all. If the server relays through a smarthost or customers send from a third-party service, the template needs the extra include: mechanisms. Override the template rather than the generated file:
mkdir -p /usr/local/directadmin/data/templates/custom
cp /usr/local/directadmin/data/templates/dns_txt.conf /usr/local/directadmin/data/templates/custom/
# edit the custom copy, then rewrite zones:
echo "action=rewrite&value=named" >> /usr/local/directadmin/data/task.queue
Custom templates survive updates; edits to the non-custom copy do not.
DMARC
A DMARC record tells receivers what to do when SPF and DKIM fail and where to send reports. Add a _dmarc TXT entry to the same custom dns_txt.conf template so every domain gets one:
_dmarc="v=DMARC1; p=none; rua=mailto:dmarc-reports@your-hosting-domain.net; adkim=r; aspf=r"
Start with p=none and collect reports for a few weeks. Move to p=quarantine only after confirming that all legitimate sending sources — the server, any smarthost, any newsletter tool — pass alignment. A p=reject policy pushed out server-wide without that check silently kills mail for customers who send through external services you did not know about.
Common pitfall: the hostname is not a hosted domain
Outbound mail from cron jobs, the panel itself and system notifications is sent as the server hostname. That hostname is not in /etc/virtual/domainowners, so it has no DKIM key and often no SPF record. Receivers then see unauthenticated mail from your server IP, which damages the reputation that all the customer domains depend on. Create the hostname’s zone in Admin Level → DNS Administration, add SPF and a DKIM key for it with dkim_create.sh, and confirm Exim signs it.
Verify
Send a message from a hosted domain to a mailbox you control and inspect the headers for Authentication-Results showing dkim=pass, spf=pass and dmarc=pass. From the server side:
dig +short TXT x._domainkey.example.com
dig +short TXT example.com | grep spf
dig +short TXT _dmarc.example.com
exim -bV | head -n 1
systemctl status rspamd --no-pager
Then watch the queue for a day with the Exim mail queue report; a sudden rise in deferred mail after switching scanners almost always means the exim_conf rebuild was skipped. When spam does originate from a hosted account, the approach in Finding the source of outgoing spam applies to DirectAdmin’s Exim logs as well.
DirectAdmin Rspamd at a glance

Official documentation: RFC 7489 (DMARC), RFC 7208 (SPF), RFC 6376 (DKIM).
Related guides: Configuring DirectAdmin’s Exim to relay through MailBaby · Setting a custom webmail URL and branding Roundcube 1.7 on DirectAdmin · Choosing a VPS for a cPanel or DirectAdmin server in 2026.
Frequently asked questions
Does switching from SpamAssassin to Rspamd keep users’ existing spam settings?
Mostly. The per-user thresholds set in Spam Filters are carried over because Exim’s headers have been unified since 1.704, but SpamAssassin’s Bayes training data and custom user_prefs rules do not transfer, so Rspamd starts learning afresh through its Dovecot integration.
How long does DKIM take to start working after enabling it on DirectAdmin?
Signing starts as soon as the key exists and Exim is reloaded, and receivers can verify it once the x._domainkey TXT record has propagated, which for zones hosted on the server is usually within the record’s TTL of an hour or less.
Can I undo this?
Yes. Set spamd back to the previous scanner and rebuild exim_conf, set dkim 0 with da config-set to stop signing, and remove the custom dns_txt.conf template followed by a named rewrite to drop the SPF and DMARC additions.