By default every message that leaves a cPanel server goes out on the main shared IP and
announces the server hostname in HELO. That's fine until one customer's newsletter gets the
IP listed and every other domain on the box pays for it. Exim on cPanel can bind outbound
SMTP to a different IP — and a matching HELO — per sender domain, using two plain-text
files: /etc/mailips and /etc/mailhelo.
This guide is for operators who want to isolate a high-volume or high-risk customer onto its own sending IP, or split a fleet's mail across a small IP pool. It assumes the basic deliverability work — PTR, SPF, DKIM, and DMARC — is already done for the main IP.
How cPanel picks the outbound IP
The remote_smtp transport in cPanel's Exim config sets interface and helo_data from
lookups against those two files, keyed on the sender's domain. If the domain isn't
listed, Exim falls back to the * line; if there's no * line, it uses the server's
default route IP.
Two consequences matter in practice:
- The key is the envelope sender domain, not the
From:header and not the cPanel account. A WordPress site that sends aswordpress@server1.example.comuses the hostname's mapping, not the customer's. - Bounces have an empty envelope sender, so they always go out on the
*IP.
Choose automatic or manual mode
WHM offers two mutually exclusive ways to populate the files, both under WHM » Service Configuration » Exim Configuration Manager » Basic Editor » Domains.
| Setting | What it does | Use when |
|---|---|---|
| Send mail from account's dedicated IP address | cPanel rewrites both files from account IP assignments | Every customer with a dedicated IP should send from it |
| Reference /etc/mailips for outgoing SMTP connections | Exim reads your hand-edited /etc/mailips | You need IPs that don't match web IPs, or a sending pool |
| Reference /etc/mailhelo for outgoing SMTP HELO | Exim reads your hand-edited /etc/mailhelo | Paired with the option above |
Automatic mode is the right answer for most shared hosts: assign a dedicated IP to the account in WHM » Change Site's IP Address, and its mail follows. Manual mode is for the cases where web and mail IPs should differ — for example, keeping a customer's site on the shared IP behind Cloudflare while their mail leaves from a clean address.
Bind the IP to the server first
Exim can only use an address that's configured on an interface. Add it in WHM » IP Functions » Add a New IP Address, then confirm:
ip -br addr show
/usr/local/cpanel/scripts/ipusage
If the IP isn't bound, every delivery for that domain defers with failed to bind or
Cannot assign requested address in /var/log/exim_mainlog, and the queue grows until
you notice.
Set PTR and HELO for each sending IP
Every IP you send from needs its own forward-confirmed reverse DNS, and the HELO Exim announces on that IP must match it. A mismatched pair is the most common reason a freshly dedicated IP performs worse than the shared one it replaced.
For an IP 203.0.113.50 dedicated to shop.example.org:
| Record | Where | Value |
|---|---|---|
| A | DNS for example.org | mail.shop.example.org → 203.0.113.50 |
| PTR | Your IP provider's panel | 203.0.113.50 → mail.shop.example.org |
| SPF | TXT on shop.example.org | include ip4:203.0.113.50 |
dig +short -x 203.0.113.50
dig +short mail.shop.example.org
Both lookups must return each other's value before the IP sends anything.
Write the files in manual mode
Disable Send mail from account's dedicated IP address, enable both Reference /etc/... options, and save. Then edit the files.
/etc/mailips
shop.example.org: 203.0.113.50
news.example.net: 203.0.113.51
*: 203.0.113.10
One domain: address per line. The * line is the fallback for every unlisted domain,
including bounces — point it at your main shared IP explicitly rather than relying on the
default route. IPv6 uses collapsed notation:
shop.example.org: 2001:db8:3c4d:15::50
Separate an IPv4 and an IPv6 address for the same domain with a semicolon, never a comma.
Test this on one domain before rolling it out; some older Exim configurations reject the
combined form with is not a valid IP address for the interface option.
/etc/mailhelo
shop.example.org: mail.shop.example.org
news.example.net: mail.news.example.net
*: server1.example.com
Every domain in /etc/mailips needs a matching line here. If you map the IP but forget
the HELO, the message leaves 203.0.113.50 announcing server1.example.com — a PTR
mismatch Gmail and Microsoft both penalise.
Exim reads both files at delivery time, so no restart is needed. Subdomains need their own
lines; example.org does not cover shop.example.org.
Verify outbound mail uses the new IP
Check the transport is reading the files:
exim -bP transport remote_smtp | grep -E 'interface|helo_data'
Then send a test as the mapped domain and inspect what the receiver saw:
exim -f test@shop.example.org check-auth@verifier.port25.com <<'EOF'
Subject: mailips check
probe
EOF
The port25 reply arrives within a minute and reports the connecting IP, the HELO, the PTR result, and SPF/DKIM alignment. All four should reference the dedicated IP. Watch the log for bind errors at the same time:
tail -f /var/log/exim_mainlog | grep -E 'shop.example.org|failed to bind'
Warm the IP before moving volume
A new IP with no sending history is treated as suspicious by the large mailbox providers. Moving a customer sending 50,000 messages a day onto it overnight gets them deferred at Gmail and junked at Outlook. Ramp it: start with a few hundred messages a day of transactional mail and roughly double daily while watching deferral rates. Pair this with per-domain Exim throttling so a compromised account can't burn the fresh IP in an afternoon.
If you'd rather not manage IP reputation at all, relaying through SES, SendGrid, or
Mailgun is the alternative — with a smart host, the
mailips binding only affects the hop to the relay, not what recipients see.
How do I send email from a different IP for one domain in cPanel?+
Why does cPanel keep overwriting /etc/mailips?+
Do I need to restart Exim after editing /etc/mailips?+
Why is mail still going out on the main IP after setting mailips?+
Does a dedicated sending IP cost extra on a cPanel license?+
Next steps
- Lock down authentication on each domain with the cPanel SPF, DKIM, and DMARC guide.
- Cap per-domain sending rates with Exim outbound throttling before warming a new IP.
- Check how account counts drive cost in cPanel license tiers explained, or compare options on the pricing page. For a cPanel license across a multi-IP fleet, contact sales.