# MailBaby cPanel Exim Setup: Reliable Router, SRS and DKIM

Source: https://srvscripts.com/guides/mailbaby-cpanel-whm-exim-setup/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

cPanel’s Exim configuration is generated from templates, so the correct way to add a smarthost is through the Advanced Editor insertion points rather than editing `/etc/exim.conf` directly. This tutorial adds a MailBaby authenticator, a router that catches every non-local domain, and two transports: one for ordinary mail and one for forwarded mail that needs SRS. It assumes you already have a MailBaby account with an `mbXXXXX` username and password from the InterServer portal.

In short: In WHM’s Exim Configuration Manager, add a plaintext LOGIN authenticator with your mbXXXXX credentials in @AUTH@, a manualroute router in @POSTMAILCOUNT@ with domains = ! +local_domains, route_list = * relay.mailbaby.net::25 and no_more…

**Short answer:** In WHM’s Exim Configuration Manager, add a `plaintext` LOGIN authenticator with your `mbXXXXX` credentials in `@AUTH@`, a `manualroute` router in `@POSTMAILCOUNT@` with `domains = ! +local_domains`, `route_list = * relay.mailbaby.net::25` and `no_more`, and two `smtp` transports in `@TRANSPORTSTART@` that set `hosts_require_auth = *`, `hosts_require_tls = *` and the `dkim_*` options, one of them rewriting `return_path` with SRS for forwards. Enable SRS and set the SPF include host to `spf-c.mailbaby.net` in the Basic Editor first, then confirm `A=mailbaby_login` and `X=TLS` in `/var/log/exim_mainlog`.

## Prepare deliverability first

Before any Exim change, open **WHM » Email » Email Deliverability** and make sure every domain that will send has a valid DKIM key and that the server’s rDNS resolves. MailBaby passes your DKIM signature through untouched, so a domain without a key will end up signed by MailBaby’s transport domain instead and display “via mailbaby.net” in some mail clients. Fix keys now:

```
whmapi1 install_dkim_private_key domain=example.com
whmapi1 enable_dkim domain=example.com
```

Then add `include:spf-c.mailbaby.net` to each domain’s SPF record, or publish the `_mailbaby` TXT verification record. Both approaches are compared in [the SPF guide](/guides/mailbaby-spf-record-domain-verification/).

## Basic editor settings

In **WHM » Service Configuration » Exim Configuration Manager » Basic Editor**, change three items:

- **Use reverse DNS for HELO**: off. The HELO should be your hostname, and MailBaby checks it against the authenticated account rather than rDNS.

- **SPF include hosts for all domains**: set to `spf-c.mailbaby.net` so cPanel-managed zones get the include automatically.

- **Enable Sender Rewriting Scheme (SRS) support**: on. Forwarders will otherwise fail SPF at the destination and MailBaby will apply its strict forwarding rules.

Save; cPanel rebuilds and restarts Exim.

## Authenticator

Switch to the **Advanced Editor** and find the `@AUTH@` section. Add a plaintext client authenticator. The username is the bare `mbXXXXX` string with no domain:

```
mailbaby_login:
  driver = plaintext
  public_name = LOGIN
  hide client_send = ": mb12345 : YOUR_PASSWORD"
```

The leading colon is intentional; LOGIN sends the username and password as two separate challenge responses. `hide` keeps the credentials out of `exim -bP` output for unprivileged users.

## Router

In the `@POSTMAILCOUNT@` insertion point, which runs after cPanel’s outbound accounting but before the `dkim_lookuphost` router, add a `manualroute` router. It matches everything that is not a local domain. On cPanel 108 and later the SRS forward detection variable is available, so the router can pick the forward transport when the message is a forward:

```
mailbaby_relay:
  driver = manualroute
  domains = ! +local_domains
  transport = ${if eq{$original_domain}{$domain}{mailbaby_smtp}{mailbaby_forward_smtp}}
  route_list = * relay.mailbaby.net::25
  no_more
```

The double colon in `route_list` separates host from port. `no_more` stops Exim falling through to the standard `lookuphost` router if the relay refuses a message, which would leak mail out via your own IP and bypass the SPF setup.

## Transports

In `@TRANSPORTSTART@`, define the two transports. The first is the normal path with local DKIM signing:

```
mailbaby_smtp:
  driver = smtp
  port = 25
  hosts_require_auth = *
  hosts_require_tls = *
  tls_tempfail_tryclear = false
  dkim_domain = ${perl{get_dkim_domain}}
  dkim_selector = default
  dkim_private_key = ${if exists{/var/cpanel/domain_keys/private/${dkim_domain}}{/var/cpanel/domain_keys/private/${dkim_domain}}{0}}
  dkim_canon = relaxed
  headers_add = X-AuthUser: ${if def:authenticated_id{$authenticated_id}{$sender_ident}}
```

The second is identical except that it rewrites the envelope sender using SRS so that forwarded mail carries a return path on your domain:

```
mailbaby_forward_smtp:
  driver = smtp
  port = 25
  hosts_require_auth = *
  hosts_require_tls = *
  tls_tempfail_tryclear = false
  return_path = ${if eq{$sender_address_domain}{}{}{SRS0=${srs_encode{SRS_SECRET}{$sender_address_local_part}{$sender_address_domain}}@$original_domain}}
  dkim_domain = ${perl{get_dkim_domain}}
  dkim_selector = default
  dkim_private_key = ${if exists{/var/cpanel/domain_keys/private/${dkim_domain}}{/var/cpanel/domain_keys/private/${dkim_domain}}{0}}
```

`SRS_SECRET` refers to the secret cPanel defines when SRS is enabled; check the generated `/etc/exim.conf` for the exact macro name on your build. `hosts_require_auth = *` and `hosts_require_tls = *` are the two lines that matter for security: MailBaby refuses unauthenticated or unencrypted submission, and without these Exim would happily try plain delivery and fail with an unhelpful error. Keeping the `X-AuthUser` header preserves cPanel’s ability to trace which account generated a message when you are [hunting the source of spam](/guides/find-source-of-outgoing-spam-cpanel/).

Save the editor. cPanel validates the configuration and restarts Exim.

## Greylisting and firewall

Bounces and rSPAM rejections come back from MailBaby’s network. Whitelist it in cPanel greylisting so return traffic is not delayed:

```
whmapi1 create_cpgreylist_trusted_host ip='162.220.160.0/28'
```

Add the same range to `/etc/csf/csf.allow` if your firewall rate-limits inbound SMTP. See [the whitelisting guide](/guides/whitelist-mailbaby-cpanel/) for the SpamAssassin side.

## Verify

Send a test message and watch the log:

```
echo "relay test" | mail -s "MailBaby test" you@example.org
tail -f /var/log/exim_mainlog
```

A successful line shows `H=relay.mailbaby.net [IP]:25 X=TLS1.3:... A=mailbaby_login`. The `A=` field confirms authentication happened; `X=` confirms TLS. Then read the received message’s headers for `dkim=pass` on your domain and `spf=pass`. The common pitfall is a copied password with trailing whitespace inside the `client_send` string; the log then shows `535 authentication failed` and the message sits in the queue. Run `exim -bV` after any edit to catch syntax errors before restarting, and remember that cPanel regenerates the configuration on upgrade, so keep your snippets in the Advanced Editor rather than in `/etc/exim.conf`.

Diagram: Exim relays outbound mail to MailBaby with SMTP auth; MailBaby filters and delivers. SPF must include the relay.

## MailBaby cPanel at a glance

**Official documentation:** [Exim documentation](https://www.exim.org/docs.html), [RFC 6376 (DKIM)](https://www.rfc-editor.org/rfc/rfc6376), [cPanel & WHM documentation](https://docs.cpanel.net/).

**Related guides:** [Warm up a new mail server IP or sending domain without landing in spam](https://srvscripts.com/guides/warm-up-new-mail-server-ip-domain/) · [Whitelisting MailBaby in cPanel greylisting, CSF and SpamAssassin](https://srvscripts.com/guides/whitelist-mailbaby-cpanel/) · [Email forwarders with MailBaby: SRS, strict forwarding errors and backoffs](https://srvscripts.com/guides/mailbaby-srs-strict-forwarding-errors/).

## Frequently asked questions

### Will cPanel updates overwrite my MailBaby Exim configuration?

Not if the snippets live in the Advanced Editor insertion points (`@AUTH@`, `@POSTMAILCOUNT@`, `@TRANSPORTSTART@`), which cPanel preserves in `/etc/exim.conf.local` and re-applies when it regenerates `/etc/exim.conf`. Anything edited directly in `/etc/exim.conf` is lost on the next rebuild.

### Does MailBaby need port 25, 587 or 465 from a cPanel server?

The examples use `relay.mailbaby.net::25` with STARTTLS enforced by `hosts_require_tls = *`. If your provider blocks outbound port 25, change the port in both the router’s `route_list` and the transports’ `port` option to the alternative submission port MailBaby publishes for your account.

### Why does Exim log “535 authentication failed” to relay.mailbaby.net?

The usual causes are trailing whitespace inside the `client_send` string, a username with a domain appended instead of the bare `mbXXXXX`, or TLS not being negotiated before AUTH. Check the authenticator line character by character and confirm `X=TLS` appears in the log entry for the attempt.
