# Exim Log Cheat Sheet: exigrep, exiqgrep, eximstats and Log Flags

Source: https://srvscripts.com/guides/exim-log-cheat-sheet/
Updated: 2026-10-07
Publisher: srvScripts (https://srvscripts.com/)

**Short answer:** Exim’s main log is `/var/log/exim_mainlog` on cPanel and `/var/log/exim/mainlog` on DirectAdmin. Each message line carries a two-character flag: `<=` arrival, `=>` delivery, `->` extra recipient in the same delivery, `*>` suppressed, `**` bounced and `==` deferred. Use `exigrep` to pull every line for a message, `exiqgrep` and `exiqsumm` for the queue, `eximstats` for totals and `exiwhat` for live processes.

We ran these commands on our lab servers (AlmaLinux 9.8 with cPanel & WHM 11.138, and AlmaLinux 9.8 with DirectAdmin 1.712, both on Exim 4.100.1) on 7 October 2026. Sample output below is from those runs, with addresses, hostnames and IPs masked.

## Where the Exim logs are on cPanel and DirectAdmin

Ask Exim instead of guessing; the answer is the `log_file_path` setting, where `%s` becomes main, reject or panic:

```
exim -bP log_file_path
```

| Log | cPanel (lab: /var/log/exim_%slog) | DirectAdmin (lab: /var/log/exim/%slog) |
| --- | --- | --- |
| Main log: arrivals, deliveries, defers, bounces | /var/log/exim_mainlog | /var/log/exim/mainlog |
| Reject log: refused connections and recipients, with headers | /var/log/exim_rejectlog | /var/log/exim/rejectlog |
| Panic log: configuration and serious errors | /var/log/exim_paniclog | /var/log/exim/paniclog |
| Rotated copies seen on the lab | exim_mainlog-20261007.gz (gzipped) | mainlog-20261005 (not gzipped) |
| Per-message log while a message is queued | /var/spool/exim/msglog/ | /var/spool/exim/msglog/ |

A non-empty panic log always deserves a look: `ls -l /var/log/exim_paniclog` on cPanel.

## Exim log flags:  -> *> ** ==

Every line about a specific message starts with the date, time and message ID, followed by one of these flags (from the Exim specification):

| Flag | Meaning | What to look at next |
| --- | --- | --- |
|  | Normal delivery | R= router, T= transport, H= remote host, C= remote reply |
| -> | Another recipient delivered in the same delivery | Same fields as => |
| >> | Cutthrough delivery | Rare on panel servers |
| *> | Delivery suppressed by -N (testing) | Someone ran Exim with -N |
| ** | Delivery failed, address bounced | Error text at the end of the line |
| == | Delivery deferred, temporary problem | Error text; Exim retries later |
| (= | Message fakereject | ACL used fakereject |

A message is finished when its ID logs `Completed`. Lines like `Frozen` or `Message is frozen` mean it is stuck in the queue; see our [Exim queue stuck guide](/guides/cpanel-exim-queue-stuck/).

The fields you will use most:

| Field | Meaning |
| --- | --- |
| H= | Host name and [IP]. A name in parentheses is what the client said in HELO, not verified |
| A= | Authenticator and login, for example A=dovecot_login:bob@example.com on cPanel |
| U= | Local user that submitted the message (scripts, cron, PHP mail()) |
| P= | On
