# MailBaby SRS and Strict Forwarding Errors: Reliable Forwarders

Source: https://srvscripts.com/guides/mailbaby-srs-strict-forwarding-errors/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

A forwarder is the one feature of shared hosting that turns your server into a relay for other people’s mail. When `info@example.com` forwards to a Gmail address, every message anyone sends to that alias, including spam, leaves your server carrying the original sender’s envelope address and arrives at Gmail from an IP that the original sender’s SPF record does not authorise. MailBaby sees the same thing and treats unrewritten forwards as a reputation risk. The result is a class of rejections that customers report as “my forwarder stopped working”. This guide explains the mechanism and the fix.

In short: MailBaby rejects forwarded mail that still carries the original sender’s envelope address, because it fails SPF downstream and lends the relay’s reputation to spam your server did not originate.

**Short answer:** MailBaby rejects forwarded mail that still carries the original sender’s envelope address, because it fails SPF downstream and lends the relay’s reputation to spam your server did not originate. Enable SRS in WHM’s Exim Basic Editor, then route forwards through a dedicated smarthost transport whose `return_path` rewrites the sender to `SRS0=...@` the forwarder’s domain, selected by a router that compares `$original_domain` with `$domain`. Filter spam before forwarding, remove catch-all forwarders, and clear a backoff by disabling the forwarder, fixing the filtering and letting clean traffic resume.

## What goes wrong

Three things happen to an unrewritten forward. The destination checks SPF against the original sender’s domain and fails, so DMARC fails too and the message is quarantined or dropped. MailBaby applies its strict forwarding rule set: a forward whose original sender scores as spam, whose sender domain is a known phishing source, or whose sender address fails basic validation is rejected with a message referring to forwarding or the recipient domain rule. And if a forwarder keeps relaying spam, MailBaby applies a backoff to the forwarding address, delaying or rejecting further forwards from it for a period.

The relay is not being difficult; it is refusing to lend its IP reputation to spam that your server did not originate. The correct response is to make forwards look like mail from your domain, which is exactly what the Sender Rewriting Scheme does.

## Enable SRS

SRS rewrites the envelope sender of a forwarded message to `SRS0=hash=timestamp=original-domain=original-local@your-domain`, so SPF is evaluated against your domain and bounces route back through your server to the original sender. On cPanel, turn it on in **WHM » Exim Configuration Manager » Basic Editor » Enable Sender Rewriting Scheme (SRS) support**, or from the shell:

```
whmapi1 set_tweaksetting key=srs value=1
/scripts/buildeximconf
systemctl restart exim
```

cPanel generates an SRS secret and defines the transport-level rewriting for its own remote transport. Because MailBaby replaces that transport with a smarthost, you need the rewriting in the smarthost transport as well.

## Route forwards through an SRS transport

The [cPanel MailBaby setup guide](/guides/mailbaby-cpanel-whm-exim-setup/) defines two transports. The router in `@POSTMAILCOUNT@` chooses between them by comparing the original recipient domain to the current one; when they differ, the message has been redirected by a forwarder:

```
mailbaby_relay:
  driver = manualroute
  domains = ! +local_domains
  transport = ${if eq{$original_domain}{$domain}{mailbaby_smtp}{mailbaby_forward_smtp}}
  route_list = * relay.mailbaby.net::25
  no_more
```

The forward transport carries the `return_path` rewrite:

```
mailbaby_forward_smtp:
  driver = smtp
  port = 25
  hosts_require_auth = *
  hosts_require_tls = *
  return_path = ${if eq{$sender_address_domain}{}{}{SRS0=${srs_encode{SRS_SECRET}{$sender_address_local_part}{$sender_address_domain}}@$original_domain}}
```

`$original_domain` is the domain of the forwarder itself, so the rewritten sender is on the customer’s domain, which is already authorised for MailBaby and already has DKIM. On DirectAdmin the equivalent router and transport are `smart_route_forward` and `auth_relay_forward` in the `.pre.conf` files; see [the DirectAdmin guide](/guides/directadmin-exim-mailbaby-relay/).

Bounces to the SRS address arrive at your server, Exim decodes them and delivers them to the original sender. That is a further reason the forwarder’s domain must accept inbound mail on this server; a domain with external MX cannot terminate SRS bounces here.

## Reduce what gets forwarded

SRS fixes authentication but does not stop spam from being forwarded, and MailBaby’s backoff is triggered by volume of bad content, not by SPF. Filter before you forward:

- Enable SpamAssassin for the account and set “Delete or move messages scored above” in **cPanel » Spam Filters** so high-scoring mail never reaches the forwarder.

- In **WHM » Exim Configuration Manager » Basic**, turn on **Reject mail at SMTP time based on SpamAssassin score** with a conservative threshold, or configure the equivalent in Rspamd on DirectAdmin.

- Turn on cPanel greylisting for the domain; it drops the majority of botnet spam before content filtering runs.

- Ask customers with catch-all forwarders to remove them. A catch-all that forwards everything sent to any address at the domain is the single worst pattern and MailBaby’s backoff will hit it first.

## Clearing a backoff

When a forwarding address has been backed off, the portal log shows the rejections and the relay’s SMTP response names the address. Stop the flow first: disable the forwarder in **cPanel » Forwarders** or remove it with `uapi --user=USER Email delete_forwarder address=info@example.com forwarder=dest@gmail.com`. Fix the filtering as above, re-enable the forwarder, and let the backoff expire; it clears on its own once clean traffic resumes. If the customer needs it working immediately, open a ticket with InterServer quoting the forwarding address and what you changed.

## Verify

Send a message from an external mailbox to the forwarder and inspect the copy that arrives at the destination. The `Return-Path:` header should begin `SRS0=` and end with the forwarder’s domain, and `Authentication-Results:` should show `spf=pass` for that domain. In `/var/log/exim_mainlog` the delivery line should show `T=mailbaby_forward_smtp`. The common pitfall is enabling SRS in the Basic Editor and assuming that covers the smarthost: cPanel only applies SRS in its own `remote_smtp` transport, so if the log shows `T=mailbaby_smtp` for a forward, the router condition is not selecting the forward transport and the return path is still the original sender.

## MailBaby SRS at a glance

**Official documentation:** [cPanel & WHM documentation](https://docs.cpanel.net/), [RFC 5321 (SMTP)](https://www.rfc-editor.org/rfc/rfc5321), [Linux man pages](https://man7.org/linux/man-pages/).

**Related guides:** [Warm up a new mail server IP or sending domain without landing in spam](https://srvscripts.com/guides/warm-up-new-mail-server-ip-domain/) · [Setting up MailBaby with cPanel/WHM Exim: router, transport, SRS and DKIM](https://srvscripts.com/guides/mailbaby-cpanel-whm-exim-setup/) · [Whitelisting MailBaby in cPanel greylisting, CSF and SpamAssassin](https://srvscripts.com/guides/whitelist-mailbaby-cpanel/).

## Frequently asked questions

### Does enabling SRS in WHM fix MailBaby forwarding errors on its own?

No. cPanel only applies SRS inside its own `remote_smtp` transport, and the MailBaby smarthost replaces that transport. The `return_path` rewrite must be added to the forward transport you define in the Advanced Editor, and the router must select it when `$original_domain` differs from `$domain`.

### Why does a forwarder to Gmail fail SPF or land in spam?

An unrewritten forward arrives at Gmail from your IP with the original sender’s envelope domain, whose SPF record does not authorise your server, so SPF and DMARC fail. SRS rewrites the envelope sender to the forwarder’s own domain so SPF is evaluated against a record that includes the relay.

### How long does a MailBaby forwarding backoff last?

It clears on its own once clean traffic resumes from the forwarding address; there is no fixed timer. Disable the forwarder, fix the spam filtering, re-enable it, and if the customer cannot wait, open a ticket with InterServer quoting the address and the changes you made.
