# Dovecot Sieve Filters Roundcube: Mail Rules on cPanel

Source: https://srvscripts.com/guides/dovecot-sieve-filters-roundcube-cpanel/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

For years cPanel’s mailbox filtering was handled by Exim at delivery time, configured through the cPanel Email Filters interface and stored in `.cpanel/filter` files. cPanel & WHM 132, released in October 2025, upgraded Dovecot to 2.4 and added Sieve, the standard server-side filtering language, together with the managesieve plugin in Roundcube so users can write filters from webmail. Sieve filters run inside Dovecot’s local delivery agent, support vacation replies, flag and folder actions, and are portable between servers. This guide covers enabling Sieve, using it from Roundcube, and the interaction with the older Exim-based filters.

In short: On cPanel 132 or later, enable Sieve and the managesieve listener in WHM → Service Configuration → Mailserver Configuration, confirm port 4190 is listening, and users can then build filters under Settings → Filters in Roundcube, which…

**Short answer:** On cPanel 132 or later, enable Sieve and the managesieve listener in WHM → Service Configuration → Mailserver Configuration, confirm port 4190 is listening, and users can then build filters under Settings → Filters in Roundcube, which writes and activates the script immediately. Sieve runs in Dovecot after any legacy Exim filters, so the two coexist, and administrators can inspect or activate scripts with `doveadm sieve`.

## How Sieve fits into cPanel’s mail flow

Exim accepts a message, runs the account-level and user-level Exim filters if any exist, then hands the message to Dovecot’s LMTP or LDA for delivery. Dovecot 2.4 with the Sieve plugin evaluates the user’s active Sieve script at that point and executes its actions: file into a folder, add a flag, redirect, discard, or send a vacation response. Sieve therefore runs after the legacy filters, and the two can coexist. Cleaner, though, is to move users to Sieve and leave the legacy filters for the rare rules that need Exim-level features.

Scripts are stored per mailbox under the mail account’s home, typically `/home/<user>/mail/<domain>/<account>/sieve/`, with a symlink `.dovecot.sieve` pointing at the active script, and Roundcube talks to the managesieve service on port 4190 on localhost to read and write them.

## Enable Sieve and the Roundcube plugin

On 132 and later the Dovecot Sieve plugin is installed with the server. Check that the managesieve service is enabled in WHM → Service Configuration → Mailserver Configuration; the option to enable Sieve and the managesieve listener appears there, alongside the protocols list. From the shell:

```
whmapi1 get_service_config service=dovecot --output=json | grep -i sieve
doveconf -n | grep -iE 'sieve|managesieve'
ss -ltnp | grep 4190
```

The `doveconf` output should show the `sieve` plugin in the LDA and LMTP protocol sections and a `managesieve` listener. If the listener is missing, enable it in Mailserver Configuration and restart Dovecot with `/scripts/restartsrv_dovecot`.

Roundcube’s managesieve plugin is enabled by default once Sieve is available; if the Filters entry is missing from Roundcube’s Settings, check the plugin list in `/usr/local/cpanel/base/3rdparty/roundcube/config/config.inc.php` and make sure `managesieve` is included. Do not edit that file directly on a production server; use `/var/cpanel/roundcube/config.inc.php` for overrides, which survives cPanel updates, and restart cpsrvd.

## Create a filter in Roundcube

Log into webmail, choose Roundcube, and open Settings → Filters. Create a new filter set if none exists; the first set becomes active. Add a filter, give it a name, define the condition (for example, the header `From` contains `newsletter@`) and the action (move to the folder `Newsletters`). Save. Roundcube writes the Sieve script and activates it through managesieve immediately; there is no delivery restart needed.

The generated script for that filter is short and readable:

```
require ["fileinto"];
if header :contains "from" "newsletter@"
{
    fileinto "Newsletters";
}
```

Users can also enable the raw editor in the Filters view to write Sieve by hand, which is useful for `vacation` responses with custom periods, for regular expressions, and for combining conditions with `allof` and `anyof`.

Vacation replies deserve a note. cPanel’s own autoresponders are still Exim-based and continue to work; a user who sets both an autoresponder and a Sieve vacation rule will send two replies. Pick one.

## Manage scripts from the server

Administrators can inspect or fix a user’s scripts directly, which is handy when a rule loops or a folder was renamed:

```
ls -la /home/customer/mail/example.com/alice/sieve/
cat /home/customer/mail/example.com/alice/sieve/roundcube.sieve
doveadm sieve list -u alice@example.com
doveadm sieve activate -u alice@example.com roundcube
```

To compile a script and check for syntax errors without activating it, use `sievec /path/to/script.sieve`. Errors are also logged in `/var/log/maillog` at delivery time, prefixed with `sieve:`. A script that fails to compile is skipped and the message is delivered to the inbox, so a broken filter never loses mail.

Legacy cPanel filters remain in cPanel → Email → Email Filters and `.cpanel/filter`. A sensible policy for a shared server is to leave them in place for existing users and steer new users to Roundcube’s Filters, which are visible in any Sieve-capable client, not only webmail.

## Verify

Send a test message that matches the rule and watch it arrive in the target folder. On the server, follow the delivery:

```
grep -i 'sieve' /var/log/maillog | tail -n 5
doveadm mailbox list -u alice@example.com | grep Newsletters
```

The log shows the script being executed and the `fileinto` action. If the message landed in the inbox instead, check that the folder exists and that the script is the active one.

## Common pitfall

The most frequent problem is a filter that references a folder that does not exist or was renamed after the filter was written. Dovecot 2.4 will create the folder if the `fileinto :create` extension is used, but Roundcube’s generated scripts do not always add it, so the action fails and the mail stays in the inbox. Create the folder first, or edit the rule after any folder rename. The second is the double-response issue mentioned above, where a Sieve vacation rule and a cPanel autoresponder both fire. When a user complains about duplicate out-of-office replies, that is where to look.

## Dovecot Sieve filters Roundcube at a glance

**Official documentation:** [Dovecot documentation](https://doc.dovecot.org/), [cPanel & WHM documentation](https://docs.cpanel.net/), [RFC 5321 (SMTP)](https://www.rfc-editor.org/rfc/rfc5321).

**Related guides:** [Roundcube “database error” and webmail login loops on cPanel](https://srvscripts.com/guides/roundcube-database-error-login-loop/) · [Dovecot 2.4 upgrade broke mail logins: password-hash resets and client settings](https://srvscripts.com/guides/dovecot-2-4-mail-login-failed-cpanel/) · [Exim outbound mail limits in WHM: hourly caps, X-Source tracking and “nobody” restrictions that stop spam runs](https://srvscripts.com/guides/exim-outbound-mail-limits-whm/).

## Frequently asked questions

### Does Sieve filtering on cPanel also work with mail clients other than Roundcube?

Yes. The scripts live on the server and run at delivery, so they apply to every client; any client or plugin that speaks managesieve, such as Thunderbird with its Sieve add-on, can edit the same filter sets over port 4190.

### How long does a new Sieve filter take to become active?

Immediately. Roundcube uploads and activates the script through managesieve when the filter is saved, so the next message delivered to the mailbox is already evaluated against it with no Dovecot restart.

### Can I undo this?

Yes. Filters can be deleted or the filter set deactivated in Roundcube, `doveadm sieve deactivate -u user@example.com` disables the active script from the shell, and the managesieve service can be turned off again in Mailserver Configuration without affecting the legacy cPanel filters.
