cPanel’s Exim configuration is generated from templates, so the correct way to add a smarthost is through the Advanced Editor insertion points rather than editing /etc/exim.conf directly. This tutorial adds a MailBaby authenticator, a router that catches every non-local domain, and two transports: one for ordinary mail and one for forwarded mail that needs SRS. It assumes you already have a MailBaby account with an mbXXXXX username and password from the InterServer portal.
Table of Contents
Short answer: In WHM’s Exim Configuration Manager, add a plaintext LOGIN authenticator with your mbXXXXX credentials in @AUTH@, a manualroute router in @POSTMAILCOUNT@ with domains = ! +local_domains, route_list = * relay.mailbaby.net::25 and no_more, and two smtp transports in @TRANSPORTSTART@ that set hosts_require_auth = *, hosts_require_tls = * and the dkim_* options, one of them rewriting return_path with SRS for forwards. Enable SRS and set the SPF include host to spf-c.mailbaby.net in the Basic Editor first, then confirm A=mailbaby_login and X=TLS in /var/log/exim_mainlog.
Prepare deliverability first
Before any Exim change, open WHM » Email » Email Deliverability and make sure every domain that will send has a valid DKIM key and that the server’s rDNS resolves. MailBaby passes your DKIM signature through untouched, so a domain without a key will end up signed by MailBaby’s transport domain instead and display “via mailbaby.net” in some mail clients. Fix keys now:
whmapi1 install_dkim_private_key domain=example.com
whmapi1 enable_dkim domain=example.com
Then add include:spf-c.mailbaby.net to each domain’s SPF record, or publish the _mailbaby TXT verification record. Both approaches are compared in the SPF guide.
Basic editor settings
In WHM » Service Configuration » Exim Configuration Manager » Basic Editor, change three items:
- Use reverse DNS for HELO: off. The HELO should be your hostname, and MailBaby checks it against the authenticated account rather than rDNS.
- SPF include hosts for all domains: set to
spf-c.mailbaby.netso cPanel-managed zones get the include automatically. - Enable Sender Rewriting Scheme (SRS) support: on. Forwarders will otherwise fail SPF at the destination and MailBaby will apply its strict forwarding rules.
Save; cPanel rebuilds and restarts Exim.
Authenticator
Switch to the Advanced Editor and find the @AUTH@ section. Add a plaintext client authenticator. The username is the bare mbXXXXX string with no domain:
mailbaby_login:
driver = plaintext
public_name = LOGIN
hide client_send = ": mb12345 : YOUR_PASSWORD"
The leading colon is intentional; LOGIN sends the username and password as two separate challenge responses. hide keeps the credentials out of exim -bP output for unprivileged users.
Router
In the @POSTMAILCOUNT@ insertion point, which runs after cPanel’s outbound accounting but before the dkim_lookuphost router, add a manualroute router. It matches everything that is not a local domain. On cPanel 108 and later the SRS forward detection variable is available, so the router can pick the forward transport when the message is a forward:
mailbaby_relay:
driver = manualroute
domains = ! +local_domains
transport = ${if eq{$original_domain}{$domain}{mailbaby_smtp}{mailbaby_forward_smtp}}
route_list = * relay.mailbaby.net::25
no_more
The double colon in route_list separates host from port. no_more stops Exim falling through to the standard lookuphost router if the relay refuses a message, which would leak mail out via your own IP and bypass the SPF setup.
Transports
In @TRANSPORTSTART@, define the two transports. The first is the normal path with local DKIM signing:
mailbaby_smtp:
driver = smtp
port = 25
hosts_require_auth = *
hosts_require_tls = *
tls_tempfail_tryclear = false
dkim_domain = ${perl{get_dkim_domain}}
dkim_selector = default
dkim_private_key = ${if exists{/var/cpanel/domain_keys/private/${dkim_domain}}{/var/cpanel/domain_keys/private/${dkim_domain}}{0}}
dkim_canon = relaxed
headers_add = X-AuthUser: ${if def:authenticated_id{$authenticated_id}{$sender_ident}}
The second is identical except that it rewrites the envelope sender using SRS so that forwarded mail carries a return path on your domain:
mailbaby_forward_smtp:
driver = smtp
port = 25
hosts_require_auth = *
hosts_require_tls = *
tls_tempfail_tryclear = false
return_path = ${if eq{$sender_address_domain}{}{}{SRS0=${srs_encode{SRS_SECRET}{$sender_address_local_part}{$sender_address_domain}}@$original_domain}}
dkim_domain = ${perl{get_dkim_domain}}
dkim_selector = default
dkim_private_key = ${if exists{/var/cpanel/domain_keys/private/${dkim_domain}}{/var/cpanel/domain_keys/private/${dkim_domain}}{0}}
SRS_SECRET refers to the secret cPanel defines when SRS is enabled; check the generated /etc/exim.conf for the exact macro name on your build. hosts_require_auth = * and hosts_require_tls = * are the two lines that matter for security: MailBaby refuses unauthenticated or unencrypted submission, and without these Exim would happily try plain delivery and fail with an unhelpful error. Keeping the X-AuthUser header preserves cPanel’s ability to trace which account generated a message when you are hunting the source of spam.
Save the editor. cPanel validates the configuration and restarts Exim.
Greylisting and firewall
Bounces and rSPAM rejections come back from MailBaby’s network. Whitelist it in cPanel greylisting so return traffic is not delayed:
whmapi1 create_cpgreylist_trusted_host ip='162.220.160.0/28'
Add the same range to /etc/csf/csf.allow if your firewall rate-limits inbound SMTP. See the whitelisting guide for the SpamAssassin side.
Verify
Send a test message and watch the log:
echo "relay test" | mail -s "MailBaby test" you@example.org
tail -f /var/log/exim_mainlog
A successful line shows H=relay.mailbaby.net [IP]:25 X=TLS1.3:... A=mailbaby_login. The A= field confirms authentication happened; X= confirms TLS. Then read the received message’s headers for dkim=pass on your domain and spf=pass. The common pitfall is a copied password with trailing whitespace inside the client_send string; the log then shows 535 authentication failed and the message sits in the queue. Run exim -bV after any edit to catch syntax errors before restarting, and remember that cPanel regenerates the configuration on upgrade, so keep your snippets in the Advanced Editor rather than in /etc/exim.conf.
MailBaby cPanel at a glance

Official documentation: Exim documentation, RFC 6376 (DKIM), cPanel & WHM documentation.
Related guides: Warm up a new mail server IP or sending domain without landing in spam · Whitelisting MailBaby in cPanel greylisting, CSF and SpamAssassin · Email forwarders with MailBaby: SRS, strict forwarding errors and backoffs.
Frequently asked questions
Will cPanel updates overwrite my MailBaby Exim configuration?
Not if the snippets live in the Advanced Editor insertion points (@AUTH@, @POSTMAILCOUNT@, @TRANSPORTSTART@), which cPanel preserves in /etc/exim.conf.local and re-applies when it regenerates /etc/exim.conf. Anything edited directly in /etc/exim.conf is lost on the next rebuild.
Does MailBaby need port 25, 587 or 465 from a cPanel server?
The examples use relay.mailbaby.net::25 with STARTTLS enforced by hosts_require_tls = *. If your provider blocks outbound port 25, change the port in both the router’s route_list and the transports’ port option to the alternative submission port MailBaby publishes for your account.
Why does Exim log “535 authentication failed” to relay.mailbaby.net?
The usual causes are trailing whitespace inside the client_send string, a username with a domain appended instead of the bare mbXXXXX, or TLS not being negotiated before AUTH. Check the authenticator line character by character and confirm X=TLS appears in the log entry for the attempt.