Panellicense

Fix "exceeded the max defers and failures per hour" on cPanel

Why Exim discards a cPanel domain's outgoing mail with "max defers and failures per hour", how to find the bouncing recipients, and when to reset the block safely.

cPAll cPanel articlesTroubleshooting6 min readUpdated 2026-10-07
schema: TechArticleschema: FAQPageschema: BreadcrumbList

A customer reports that every message they send bounces back with this line, and /var/log/exim_mainlog shows the same thing:

Domain example.com has exceeded the max defers and failures per hour (5/5 (100%)) allowed.  Message discarded.

This is cPanel's defer/fail protection, not a remote rejection. Exim has stopped accepting outbound mail from the whole domain because too many of its recent messages failed or were deferred. The block is usually right: it trips on spam runs. It also trips on legitimate senders with bad lists or broken forwarders. This article explains how the limit works, how to tell the two cases apart, and how to clear the block without hiding the cause.

How the limit is calculated

Two WHM settings under Server Configuration → Tweak Settings → Mail control the limit. A domain is blocked only when both conditions hold for the past hour:

SettingDefaultRole
Maximum percentage of failed or deferred messages a domain may send per hourUnlimitedThe failure-rate ceiling
Number of failed or deferred messages a domain may send before protections can be triggered5The minimum count before the percentage is checked

With the default percentage of Unlimited, the protection never fires. If you see this error, someone (you, a previous admin, or a hardening script) set a percentage, such as the 25 recommended in our Exim outbound throttling guide. Per-account and per-package values override the server default. Check those before you assume Tweak Settings is responsible:

grep -E 'MAX_DEFER_FAIL_PERCENTAGE|MAX_EMAIL_PER_HOUR' /var/cpanel/users/customer1

Two details catch people out. Deferrals count as well as hard failures, so a recipient domain that greylists or rate-limits you adds to the counter. And the block applies to the sending domain, so one broken contact form stops every mailbox on that domain.

Decision tree

Work through this in order. Don't skip to the reset.

1. Is the domain sending spam?

Check the queue and the per-sender volume first. The commands match the ones in the frozen Exim queue guide:

exim -bpc
exim -bp | awk '/^ *[0-9]+[mhd]/{print $4}' | sort | uniq -c | sort -rn | head

If the domain has hundreds or thousands of queued messages to random recipients, the protection did its job. Suspend first, then investigate with X-Source headers. The cleanup sequence is in Exim outbound throttling. Do not reset the block until the source script is gone.

2. Which recipients are failing?

If the volume looks normal, pull the deferrals (==) and failures (**) for the domain's messages from the last few hours:

exigrep '@example.com' /var/log/exim_mainlog | grep -E ' (==|\*\*) ' | tail -50

The SMTP response on each line usually tells you the cause:

Pattern in the logCauseFix
550 5.1.1 ... does not exist repeated across many recipientsStale mailing list or contact form with bad addressesClean the list, move bulk mail to a dedicated ESP
550 5.7.26 / unauthenticated from GmailForwarder relaying mail that fails SPF/DMARCReplace the forwarder with a mailbox, or fix SPF, DKIM, and DMARC
421 / 451 with "try again later" or "rate limited"Remote greylisting or throttlingUsually clears by itself; slow the sender down
Mailbox quota exceededForwarding to a full remote mailboxRemove or fix the forwarder
retry timeout exceeded for one domainRecipient MX is downWait it out; consider raising the threshold

3. Is it one forwarder?

Forwarders to Gmail, Outlook.com, or Yahoo are the most common false positive on shared servers. Forwarded spam gets rejected by the remote provider, and those rejections count against the forwarding domain. List the domain's forwarders:

cat /etc/valiases/example.com

If most of the failures go to a single external address, removing that forwarder fixes the problem.

Clear the block

When the domain is clean and the cause is fixed, the block lifts automatically once the failure percentage for the rolling hour drops below the threshold. To clear it straight away, remove the marker file:

rm -f /var/cpanel/email_send_limits/max_deferfail_example.com

If the domain trips again within minutes, the old hour's counters are still pushing it over the limit. Clear the domain's tracking data too:

rm -rf /var/cpanel/email_send_limits/track/example.com
/scripts/restartsrv_exim

Raise the limit for one account

Some customers send a lot of mail and bounce a lot through no fault of their own, such as membership organisations with old address lists. Raise their limit instead of switching the protection off for the whole server:

whmapi1 modifyacct user=customer1 MAX_DEFER_FAIL_PERCENTAGE=50

For one domain inside an account, edit /var/cpanel/users/customer1 and rebuild the threshold files Exim reads:

echo "MAX_DEFER_FAIL_PERCENTAGE-example.com=50" >> /var/cpanel/users/customer1
/usr/local/cpanel/scripts/updateuserdomains

Setting the server-wide percentage back to Unlimited removes the one control that stops a hacked WordPress install from sending unchecked. If you use resellers, set a ceiling in the package so the default carries over to new accounts (see WHM packages and feature lists).

How do I reset max defers and failures per hour in cPanel?+
As root, delete /var/cpanel/email_send_limits/max_deferfail_<domain>. If the domain trips again immediately, also remove /var/cpanel/email_send_limits/track/<domain> and restart Exim. Fix the cause first, or the block returns within the hour.
Where is the max defers and failures setting in WHM?+
WHM → Server Configuration → Tweak Settings → Mail → 'Maximum percentage of failed or deferred messages a domain may send per hour'. Per-account values are set in Modify an Account or in the package, and they override the server default.
Can a cPanel user clear the defer/fail block themselves?+
No. The marker files are root-owned, so on shared hosting the user must wait for the hourly percentage to fall or ask the host. They can speed this up by fixing bad forwarders and stopping sends to invalid addresses.
Do deferred emails count towards the cPanel failure limit?+
Yes. Temporary 4xx deferrals, including remote greylisting and rate limiting, count alongside permanent 5xx failures. A large send to a provider that throttles you can trip the limit even when every address is valid.
Why does the block still apply after I deleted the max_deferfail file?+
Exim recalculates from the tracking data for the rolling hour. If the failures are still in /var/cpanel/email_send_limits/track/<domain>, the next message trips the block again. Clear that directory or wait an hour.

Next steps

Running a fleet that needs licenses for every node? See cPanel license pricing or contact sales about volume.

troubleshoot
Clear a frozen or stuck Exim mail queue on cPanel
A decision tree for a cPanel Exim queue that won't drain — tell frozen from deferred, find the compromised account, and clear messages without nuking real mail.
5 min read
troubleshoot
Rspamd on cPanel: what's actually supported in 2026
cPanel & WHM has no native Rspamd integration — here's what the built-in stack actually is, why community Rspamd-on-Exim setups are risky, and when switching panels is the real answer.
5 min read
how to
cPanel greylisting: enable, tune, and stop mail delays
Turn on cPGreyList to cut inbound spam without sending legitimate mail to limbo — initial deferral, trusted hosts, SPF bypass, and a decision tree for the "email deferred" complaints.
8 min read
how to
Tune Apache SpamAssassin on cPanel without losing mail
The WHM and cPanel settings that actually move the needle on inbound spam — threshold scoring, Spam Box vs auto-delete, SMTP-time rejection, and per-test scoring — without silently eating legitimate mail.
7 min read
troubleshoot
Fix cPanel account creation blocked by the license limit
WHM won't create new accounts and the error mentions your license? You've hit the account cap on your cPanel tier. How to confirm it, count accounts correctly, and clear it.
4 min read
troubleshoot
Fix cPanel update failures: upcp exit 256, blockers, locks
The upcp failure email tells you almost nothing. Here is the order to check things — update log, package stage, blockers, disk space, and stale locks.
5 min read
Switch in an afternoon

Switch from your current reseller — free.

We migrate active cPanel, Plesk, LiteSpeed and CloudLinux licenses from any reseller. We prorate the first month so you never pay twice, and your customers see zero downtime during the swap.