# MailBaby Classified as rSPAM: Fix Rejections Fast

Source: https://srvscripts.com/guides/mailbaby-classified-as-rspam/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

When MailBaby refuses a message, Exim or Postfix logs the relay’s SMTP response and either bounces the message to the sender or leaves it in the queue depending on whether the code was 5xx or 4xx. The response text is specific enough to diagnose most problems in a minute if you know what each one means. This guide walks through the rejections we see most often on hosting servers, the log lines that go with them, and what to change.

In short: “classified as rSPAM” is a 5xx rejection meaning MailBaby’s content filter scored the message above its spam threshold; it is caused by a compromised account sending in bursts, a legitimate message with spammy formatting, or a newsletter…

**Short answer:** “classified as rSPAM” is a 5xx rejection meaning MailBaby’s content filter scored the message above its spam threshold; it is caused by a compromised account sending in bursts, a legitimate message with spammy formatting, or a newsletter sent to a stale list, and the score in the InterServer portal log tells you which. Fix the source rather than the relay: secure the account, clean up the template, or move the customer to a proper list-sending workflow. Other common rejections are unauthorised sender (missing SPF include or `_mailbaby` TXT record), rate-limit discards above 6,000 messages per hour, strict-forwarding errors without SRS, and 535 authentication failures.

## Find the rejection

On cPanel and DirectAdmin, search the Exim log for the relay’s responses:

```
grep -i 'relay.mailbaby.net' /var/log/exim_mainlog | grep -E ' (4|5)[0-9]{2}[ -]' | tail -50
```

On Postfix:

```
grep 'relay.mailbaby.net' /var/log/mail.log | grep -E 'status=(bounced|deferred)' | tail -50
```

Then log in to the InterServer portal and open the MailBaby log for the same time window. Each entry shows sender, recipient, subject and the spam score; that score is what you need for rSPAM cases. Logs are kept for 60 days, so this works for tickets that arrive a fortnight late.

## “classified as rSPAM”

This is a 5xx rejection meaning the content filter scored the message above the spam threshold. It is the most common rejection and almost always one of three things.

A compromised account or script is the first suspect when the rejections come in a burst from one sender address. Do not try to get the mail delivered; find the source with [the outgoing spam guide](/guides/find-source-of-outgoing-spam-cpanel/), change the password, and follow the [compromise and delisting procedure](/guides/mailbaby-compromised-account-delisting/).

A legitimate message with spammy characteristics is the second. Typical triggers are a subject in capitals, a body that is a single image, a link whose visible text differs from its target, a URL shortener, or a `From:` address that does not match the authenticated domain. The fix is on the sending side: rewrite the template, use a real from address, and link directly. Ask the customer for the exact message and look at the score; anything just over the threshold usually needs one small change.

Newsletter content to a stale list is the third. Even well-formed mail scores badly when the recipients include spam traps, and MailBaby’s model weights recent complaints against the sending address. Move the customer to a proper list-sending workflow as described in [the newsletter guide](/guides/mailbaby-newsletter-sending-limit/).

## “Sender address not authorised” and SPF failures

MailBaby verifies that the envelope sender’s domain is authorised for your account, either through `include:spf-c.mailbaby.net` in the domain’s SPF record with the origin server permitted, or through the `_mailbaby` TXT record. A brand-new domain that has not had its DNS updated fails here. Check from outside:

```
dig +short TXT example.com @1.1.1.1
dig +short TXT _mailbaby.example.com @1.1.1.1
```

If neither record is present, add one and wait for propagation. The details are in [the SPF and verification guide](/guides/mailbaby-spf-record-domain-verification/). On cPanel, setting “SPF include hosts for all domains” to `spf-c.mailbaby.net` in the Exim Basic Editor prevents this for every future domain.

## Rate limit exceeded

Above 6,000 messages per hour from one sender address, MailBaby discards the excess. On a hosting server this shows up as a customer complaint that “some” of a mailing went missing with nothing in the local log, because the relay accepted the connection and dropped the message. The portal log records the discards. Cap sending below the limit at the source: on cPanel, set `whmapi1 set_tweaksetting key=maxemailsperhour value=500` and raise per-account limits only for known bulk senders; see [our outbound limits guide](/guides/exim-outbound-mail-limits-whm/). Postfix users should set `smtp_destination_rate_delay`.

## Strict forwarding errors

Forwarded mail that keeps its original envelope sender fails SPF at the destination and, if the original was spam, gets your account flagged for relaying it. MailBaby applies strict rules to forwards and rejects those that are not SRS-rewritten or that carry a suspicious original sender. Enable SRS in the Exim configuration and route forwards through the dedicated SRS transport. [The forwarders guide](/guides/mailbaby-srs-strict-forwarding-errors/) covers both cPanel and DirectAdmin.

## Authentication failures and deferrals

A 535 response means the credentials were not accepted. Check for whitespace in the stored password, confirm the username is the bare `mbXXXXX` form without a domain, and confirm TLS is negotiated before AUTH; MailBaby refuses AUTH on an unencrypted session, which some clients report as an authentication error. `hosts_require_tls = *` in Exim or `smtp_tls_security_level = may` in Postfix fixes the second cause. Rotate the password in the InterServer portal if there is any chance it leaked.

A 4xx from the relay is temporary: the account is over its warm-up threshold, the message queue at MailBaby is busy, or your server tripped a connection rate limit. Exim retries automatically. Check the queue with `exim -bp | tail` and, on cPanel, [the queue report script](/scripts/exim-mail-queue-report/). If deferrals persist for more than an hour, open a ticket with InterServer including the queue ID and the exact response text.

## Verify

After any fix, resend the specific message rather than a generic test. On Exim: `exim -M <message-id>`; on Postfix: `postqueue -i <queue-id>`. Then confirm in the portal log that the entry shows delivered with a low score. The common pitfall is whitelisting the sender locally in SpamAssassin and assuming that changes MailBaby’s decision; the relay scores independently, and nothing on your server overrides it.

## MailBaby classified as rSPAM at a glance

**Official documentation:** [RFC 5321 (SMTP)](https://www.rfc-editor.org/rfc/rfc5321), [Linux man pages](https://man7.org/linux/man-pages/).

**Related guides:** [MailBaby with Postfix on Ubuntu/Debian as an authenticated smarthost](https://srvscripts.com/guides/postfix-mailbaby-smarthost-ubuntu-debian/) · [Whitelisting MailBaby in cPanel greylisting, CSF and SpamAssassin](https://srvscripts.com/guides/whitelist-mailbaby-cpanel/) · [Email forwarders with MailBaby: SRS, strict forwarding errors and backoffs](https://srvscripts.com/guides/mailbaby-srs-strict-forwarding-errors/).

## Frequently asked questions

### Can I whitelist a sender so MailBaby stops rejecting it as rSPAM?

No. MailBaby scores every message independently of your server’s SpamAssassin or Rspamd settings, and there is no per-sender bypass. Look at the score in the portal log and change what is triggering it: the template, the from address, the links, or the recipient list.

### How do I find the MailBaby spam score for a rejected message?

Log in to the InterServer portal and open the MailBaby log for the time window in question. Each entry shows sender, recipient, subject and the score, and logs are retained for 60 days, so late support tickets can still be diagnosed.

### Why does MailBaby return 535 authentication failed with the correct password?

Usually because the client tried AUTH before TLS was negotiated, which MailBaby refuses, or because the username includes a domain instead of the bare `mbXXXXX` form. Set `hosts_require_tls = *` in Exim or `smtp_tls_security_level = may` in Postfix and check the stored password for stray whitespace.
