Panellicense

Send cPanel mail from a per-domain IP with mailips and mailhelo

Pin outbound Exim mail to a specific IP and HELO per domain on cPanel using /etc/mailips and /etc/mailhelo — the WHM toggles, file syntax, PTR rules, and how to verify it.

cPAll cPanel articlesTutorials & how-tos7 min readUpdated 2026-10-05
eximmailipsmailhelodeliverabilitydedicated-ipwhm
schema: HowToschema: FAQPageschema: BreadcrumbList

By default every message that leaves a cPanel server goes out on the main shared IP and announces the server hostname in HELO. That's fine until one customer's newsletter gets the IP listed and every other domain on the box pays for it. Exim on cPanel can bind outbound SMTP to a different IP — and a matching HELO — per sender domain, using two plain-text files: /etc/mailips and /etc/mailhelo.

This guide is for operators who want to isolate a high-volume or high-risk customer onto its own sending IP, or split a fleet's mail across a small IP pool. It assumes the basic deliverability work — PTR, SPF, DKIM, and DMARC — is already done for the main IP.

How cPanel picks the outbound IP

The remote_smtp transport in cPanel's Exim config sets interface and helo_data from lookups against those two files, keyed on the sender's domain. If the domain isn't listed, Exim falls back to the * line; if there's no * line, it uses the server's default route IP.

Two consequences matter in practice:

  • The key is the envelope sender domain, not the From: header and not the cPanel account. A WordPress site that sends as wordpress@server1.example.com uses the hostname's mapping, not the customer's.
  • Bounces have an empty envelope sender, so they always go out on the * IP.

Choose automatic or manual mode

WHM offers two mutually exclusive ways to populate the files, both under WHM » Service Configuration » Exim Configuration Manager » Basic Editor » Domains.

SettingWhat it doesUse when
Send mail from account's dedicated IP addresscPanel rewrites both files from account IP assignmentsEvery customer with a dedicated IP should send from it
Reference /etc/mailips for outgoing SMTP connectionsExim reads your hand-edited /etc/mailipsYou need IPs that don't match web IPs, or a sending pool
Reference /etc/mailhelo for outgoing SMTP HELOExim reads your hand-edited /etc/mailheloPaired with the option above

Automatic mode is the right answer for most shared hosts: assign a dedicated IP to the account in WHM » Change Site's IP Address, and its mail follows. Manual mode is for the cases where web and mail IPs should differ — for example, keeping a customer's site on the shared IP behind Cloudflare while their mail leaves from a clean address.

Bind the IP to the server first

Exim can only use an address that's configured on an interface. Add it in WHM » IP Functions » Add a New IP Address, then confirm:

ip -br addr show
/usr/local/cpanel/scripts/ipusage

If the IP isn't bound, every delivery for that domain defers with failed to bind or Cannot assign requested address in /var/log/exim_mainlog, and the queue grows until you notice.

Set PTR and HELO for each sending IP

Every IP you send from needs its own forward-confirmed reverse DNS, and the HELO Exim announces on that IP must match it. A mismatched pair is the most common reason a freshly dedicated IP performs worse than the shared one it replaced.

For an IP 203.0.113.50 dedicated to shop.example.org:

RecordWhereValue
ADNS for example.orgmail.shop.example.org → 203.0.113.50
PTRYour IP provider's panel203.0.113.50 → mail.shop.example.org
SPFTXT on shop.example.orginclude ip4:203.0.113.50
dig +short -x 203.0.113.50
dig +short mail.shop.example.org

Both lookups must return each other's value before the IP sends anything.

Write the files in manual mode

Disable Send mail from account's dedicated IP address, enable both Reference /etc/... options, and save. Then edit the files.

/etc/mailips

shop.example.org: 203.0.113.50
news.example.net: 203.0.113.51
*: 203.0.113.10

One domain: address per line. The * line is the fallback for every unlisted domain, including bounces — point it at your main shared IP explicitly rather than relying on the default route. IPv6 uses collapsed notation:

shop.example.org: 2001:db8:3c4d:15::50

Separate an IPv4 and an IPv6 address for the same domain with a semicolon, never a comma. Test this on one domain before rolling it out; some older Exim configurations reject the combined form with is not a valid IP address for the interface option.

/etc/mailhelo

shop.example.org: mail.shop.example.org
news.example.net: mail.news.example.net
*: server1.example.com

Every domain in /etc/mailips needs a matching line here. If you map the IP but forget the HELO, the message leaves 203.0.113.50 announcing server1.example.com — a PTR mismatch Gmail and Microsoft both penalise.

Exim reads both files at delivery time, so no restart is needed. Subdomains need their own lines; example.org does not cover shop.example.org.

Verify outbound mail uses the new IP

Check the transport is reading the files:

exim -bP transport remote_smtp | grep -E 'interface|helo_data'

Then send a test as the mapped domain and inspect what the receiver saw:

exim -f test@shop.example.org check-auth@verifier.port25.com <<'EOF'
Subject: mailips check

probe
EOF

The port25 reply arrives within a minute and reports the connecting IP, the HELO, the PTR result, and SPF/DKIM alignment. All four should reference the dedicated IP. Watch the log for bind errors at the same time:

tail -f /var/log/exim_mainlog | grep -E 'shop.example.org|failed to bind'

Warm the IP before moving volume

A new IP with no sending history is treated as suspicious by the large mailbox providers. Moving a customer sending 50,000 messages a day onto it overnight gets them deferred at Gmail and junked at Outlook. Ramp it: start with a few hundred messages a day of transactional mail and roughly double daily while watching deferral rates. Pair this with per-domain Exim throttling so a compromised account can't burn the fresh IP in an afternoon.

If you'd rather not manage IP reputation at all, relaying through SES, SendGrid, or Mailgun is the alternative — with a smart host, the mailips binding only affects the hop to the relay, not what recipients see.

How do I send email from a different IP for one domain in cPanel?+
Bind the IP to the server, disable 'Send mail from account's dedicated IP address' in Exim Configuration Manager, enable the 'Reference /etc/mailips' and 'Reference /etc/mailhelo' options, then add a 'domain: IP' line to /etc/mailips and a 'domain: hostname' line to /etc/mailhelo.
Why does cPanel keep overwriting /etc/mailips?+
The 'Send mail from account's dedicated IP address' option is enabled. In that mode cPanel regenerates /etc/mailips and /etc/mailhelo from account IP assignments, discarding manual edits. Turn it off before editing the files by hand.
Do I need to restart Exim after editing /etc/mailips?+
No. Exim performs the lookups at delivery time, so changes apply to the next message. Messages already in the queue pick up the new mapping on their next retry.
Why is mail still going out on the main IP after setting mailips?+
The lookup keys on the envelope sender domain. Scripts sending as user@hostname, mail from accounts with no matching line, and bounces all use the '*' fallback. Check the envelope sender in /var/log/exim_mainlog and add a line for that exact domain.
Does a dedicated sending IP cost extra on a cPanel license?+
No. cPanel licensing counts accounts, not IP addresses, so adding sending IPs doesn't change your license tier. The IPs themselves are billed by your network or hosting provider.

Next steps

how to
Exim outbound throttling on cPanel: stop spam before blacklisting
Layered Exim limits, per-account caps, and queue triage on cPanel so one compromised WordPress install can't bury your server's IP on Spamhaus by lunchtime.
8 min read
how to
Route cPanel outbound mail via SES, SendGrid, or Mailgun
Configure a smart host in Exim so every outbound message from cPanel is relayed through SES, SendGrid, or Mailgun — with per-domain overrides and the gotchas that bite resellers.
8 min read
how to
Change a cPanel WHM hostname without breaking license, mail, or SSL
A clean WHM hostname change takes 15 minutes if you do it in order. The mistakes that cost an afternoon — broken services SSL, license re-checks, mail HELO mismatches, and rDNS — all in one playbook.
8 min read
how to
cPanel account suspension: WHM workflow, automation, and unsuspension
How cPanel suspension actually works under the hood, the WHM and API workflows, custom reasons and pages, and the gotchas that bite when you unsuspend an account.
10 min read
how to
Email deliverability on cPanel: SPF, DKIM, DMARC, MTA-STS
A 2026 deliverability checklist for cPanel operators — reverse DNS, SPF, DKIM, DMARC enforcement, and MTA-STS, with the exact records and where cPanel still expects you to do it by hand.
6 min read
how to
cPanel greylisting: enable, tune, and stop mail delays
Turn on cPGreyList to cut inbound spam without sending legitimate mail to limbo — initial deferral, trusted hosts, SPF bypass, and a decision tree for the "email deferred" complaints.
8 min read
Switch in an afternoon

Switch from your current reseller — free.

We migrate active cPanel, Plesk, LiteSpeed and CloudLinux licenses from any reseller. We prorate the first month so you never pay twice, and your customers see zero downtime during the swap.