# MailBaby Plesk Webuzo Relay: Outbound Setup

Source: https://srvscripts.com/guides/mailbaby-plesk-webuzo-relay/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

Plesk and Webuzo are less common than cPanel in shared hosting but common enough on VPS fleets that a provider usually has a few of each. Both can relay outbound mail through MailBaby, and in both cases the trick is to use the panel’s own override mechanism so the setting survives updates. This guide covers Plesk Obsidian with Postfix (and the qmail equivalent), then Webuzo’s Exim configuration.

In short: On Plesk, run plesk bin mailserver –set-relay-host relay.mailbaby.net:25 and –set-relay-auth true with your mbXXXXX credentials, then add smtp_sasl_mechanism_filter = login and smtp_tls_security_level = may with postconf -e and reload…

**Short answer:** On Plesk, run `plesk bin mailserver --set-relay-host relay.mailbaby.net:25` and `--set-relay-auth true` with your `mbXXXXX` credentials, then add `smtp_sasl_mechanism_filter = login` and `smtp_tls_security_level = may` with `postconf -e` and reload Postfix; servers on qmail should switch to Postfix first because qmail cannot do STARTTLS before AUTH. On Webuzo, put a LOGIN authenticator, an authenticated TLS transport with DKIM options and a `manualroute` router in the `/etc/exim.*.pre.conf` and `.post.conf` include files, then run `exim -bV` and restart Exim. Both panels also need `include:spf-c.mailbaby.net` in each sending domain’s SPF.

## Plesk Obsidian with Postfix

Plesk exposes an “outgoing mail relay” setting in the panel at **Tools & Settings » Mail Server Settings » Outgoing mail mode**, but that page only handles unauthenticated relays on some versions. Configure it from the CLI instead, which handles authentication properly and writes the Postfix files for you:

```
plesk bin mailserver --set-relay-host relay.mailbaby.net:25
plesk bin mailserver --set-relay-auth true -relay-user mb12345 -relay-passwd 'YOUR_PASSWORD'
```

Check what Plesk wrote:

```
postconf -n | grep -E 'relayhost|smtp_sasl|smtp_tls'
```

You should see `relayhost = [relay.mailbaby.net]:25`, `smtp_sasl_auth_enable = yes` and a `smtp_sasl_password_maps` entry. Two settings that Plesk does not always set and that MailBaby needs:

```
postconf -e 'smtp_sasl_mechanism_filter = login'
postconf -e 'smtp_tls_security_level = may'
postconf -e 'smtp_sasl_security_options = noanonymous'
systemctl reload postfix
```

If `postconf -n` shows no password map at all, create `/etc/postfix/sasl_passwd` with the line `[relay.mailbaby.net]:25 mb12345:YOUR_PASSWORD`, run `postmap` on it, and add the map with `postconf -e 'smtp_sasl_password_maps = hash:/etc/postfix/sasl_passwd'`. The full Postfix explanation, including rate limiting, is in [the Postfix guide](/guides/postfix-mailbaby-smarthost-ubuntu-debian/).

Plesk manages DKIM per domain under **Mail Settings » Use DKIM spam protection system**; turn it on for every domain that sends so the signature is applied before the message reaches the relay. Plesk’s outgoing mail limits at **Tools & Settings » Outgoing Mail Control** should be set below 6,000 per hour per mailbox, because MailBaby discards excess rather than queueing it.

## Plesk with qmail

Servers still on qmail can use the same CLI commands; Plesk writes the relay into `/var/qmail/control/smtproutes` in the form `:relay.mailbaby.net:25 mb12345 YOUR_PASSWORD`. qmail’s remote delivery does not support STARTTLS without a patch, and MailBaby requires TLS before AUTH, so on qmail servers we switch to Postfix first:

```
plesk installer --select-release-current --install-component postfix
```

The switch preserves mailboxes and domains; test on a staging server if you have never done it.

## Webuzo

Webuzo uses Exim and, like DirectAdmin, rebuilds its configuration from a template. Custom settings belong in the include files Webuzo reads at startup rather than in `/etc/exim.conf`. Create three files.

Authenticator, in `/etc/exim.authenticators.post.conf`:

```
mailbaby_login:
  driver = plaintext
  public_name = LOGIN
  hide client_send = ": mb12345 : YOUR_PASSWORD"
```

Transport, in `/etc/exim.transports.pre.conf`:

```
mailbaby_smtp:
  driver = smtp
  port = 25
  hosts_require_auth = *
  hosts_require_tls = *
  tls_tempfail_tryclear = false
  dkim_domain = ${lc:${domain:$h_from:}}
  dkim_selector = default
  dkim_private_key = ${if exists{/etc/exim/dkim/${dkim_domain}.key}{/etc/exim/dkim/${dkim_domain}.key}{0}}
```

Router, in `/etc/exim.routers.pre.conf`:

```
mailbaby_route:
  driver = manualroute
  domains = ! +local_domains
  transport = mailbaby_smtp
  route_list = * relay.mailbaby.net::25
  no_more
```

Adjust the DKIM key path to wherever your Webuzo build stores keys; check with `ls /etc/exim/dkim` or the domain’s Email settings page. If the include files are not picked up, confirm the `.include_if_exists` lines are present in the generated configuration with `grep -n include_if_exists /etc/exim.conf`; some builds use `/etc/exim/` rather than `/etc/`. Then:

```
exim -bV
systemctl restart exim
```

## DNS for both panels

Every sending domain needs `include:spf-c.mailbaby.net` in its SPF record, with the server’s IP still authorised, or the `_mailbaby.<domain>` TXT ownership record. Plesk’s DNS template can add the include to every zone at **Tools & Settings » DNS Template**; Webuzo requires editing each zone. The two methods are compared in [the SPF guide](/guides/mailbaby-spf-record-domain-verification/).

## Verify

On Plesk, send from a mailbox and read the log:

```
tail -f /var/log/maillog
```

Look for `relay=relay.mailbaby.net[IP]:25` and `status=sent`. On Webuzo, `tail -f /var/log/exim_mainlog` should show `T=mailbaby_smtp` with `A=mailbaby_login` and an `X=TLS` field. In both cases, open the received message and confirm `spf=pass` and `dkim=pass` on your domain. The common pitfall on Plesk is a password containing shell metacharacters passed unquoted to `plesk bin`; the panel stores a truncated string and the log shows `535 authentication failed`. Wrap the password in single quotes, or set it through the panel interface and re-check `postconf -n`.

## MailBaby Plesk Webuzo at a glance

**Official documentation:** [RFC 5321 (SMTP)](https://www.rfc-editor.org/rfc/rfc5321), [Linux man pages](https://man7.org/linux/man-pages/).

**Related guides:** [MailBaby DKIM transport signing explained: why some mail shows “via mailbaby.net”](https://srvscripts.com/guides/mailbaby-dkim-transport-signing/) · [Sending WordPress email through MailBaby: SMTP plugin setup and testing](https://srvscripts.com/guides/wordpress-mailbaby-smtp-plugin/) · [What is MailBaby? Outbound SMTP relay pricing, limits and how it works](https://srvscripts.com/guides/what-is-mailbaby-outbound-smtp-relay/).

## Frequently asked questions

### Does Plesk’s Outgoing mail mode page support an authenticated MailBaby relay?

Not reliably; on some versions the panel page only configures unauthenticated relays. Use `plesk bin mailserver --set-relay-host` and `--set-relay-auth`, then check `postconf -n` for `relayhost`, `smtp_sasl_auth_enable` and a password map, and add the mechanism filter and TLS settings by hand.

### Can Plesk with qmail relay through MailBaby?

Only with a patched qmail, because stock qmail remote delivery has no STARTTLS and MailBaby requires TLS before AUTH. The practical route is to switch the Plesk mail server component to Postfix with `plesk installer`, which preserves mailboxes and domains, and then configure the relay there.

### Will Webuzo updates overwrite the MailBaby Exim settings?

No, as long as they live in `/etc/exim.authenticators.post.conf`, `/etc/exim.transports.pre.conf` and `/etc/exim.routers.pre.conf` rather than in `/etc/exim.conf`. If the includes stop working after an update, check `grep -n include_if_exists /etc/exim.conf`, since some builds read the files from `/etc/exim/` instead.
