A customer reports that every message they send bounces back with this line, and
/var/log/exim_mainlog shows the same thing:
Domain example.com has exceeded the max defers and failures per hour (5/5 (100%)) allowed. Message discarded.
This is cPanel's defer/fail protection, not a remote rejection. Exim has stopped accepting outbound mail from the whole domain because too many of its recent messages failed or were deferred. The block is usually right: it trips on spam runs. It also trips on legitimate senders with bad lists or broken forwarders. This article explains how the limit works, how to tell the two cases apart, and how to clear the block without hiding the cause.
How the limit is calculated
Two WHM settings under Server Configuration → Tweak Settings → Mail control the limit. A domain is blocked only when both conditions hold for the past hour:
| Setting | Default | Role |
|---|---|---|
| Maximum percentage of failed or deferred messages a domain may send per hour | Unlimited | The failure-rate ceiling |
| Number of failed or deferred messages a domain may send before protections can be triggered | 5 | The minimum count before the percentage is checked |
With the default percentage of Unlimited, the protection never fires. If you see this
error, someone (you, a previous admin, or a hardening script) set a percentage, such as
the 25 recommended in our Exim outbound throttling guide.
Per-account and per-package values override the server default. Check those before you
assume Tweak Settings is responsible:
grep -E 'MAX_DEFER_FAIL_PERCENTAGE|MAX_EMAIL_PER_HOUR' /var/cpanel/users/customer1
Two details catch people out. Deferrals count as well as hard failures, so a recipient domain that greylists or rate-limits you adds to the counter. And the block applies to the sending domain, so one broken contact form stops every mailbox on that domain.
Decision tree
Work through this in order. Don't skip to the reset.
1. Is the domain sending spam?
Check the queue and the per-sender volume first. The commands match the ones in the frozen Exim queue guide:
exim -bpc
exim -bp | awk '/^ *[0-9]+[mhd]/{print $4}' | sort | uniq -c | sort -rn | head
If the domain has hundreds or thousands of queued messages to random recipients, the
protection did its job. Suspend first, then investigate with X-Source headers. The
cleanup sequence is in Exim outbound throttling.
Do not reset the block until the source script is gone.
2. Which recipients are failing?
If the volume looks normal, pull the deferrals (==) and failures (**) for the
domain's messages from the last few hours:
exigrep '@example.com' /var/log/exim_mainlog | grep -E ' (==|\*\*) ' | tail -50
The SMTP response on each line usually tells you the cause:
| Pattern in the log | Cause | Fix |
|---|---|---|
550 5.1.1 ... does not exist repeated across many recipients | Stale mailing list or contact form with bad addresses | Clean the list, move bulk mail to a dedicated ESP |
550 5.7.26 / unauthenticated from Gmail | Forwarder relaying mail that fails SPF/DMARC | Replace the forwarder with a mailbox, or fix SPF, DKIM, and DMARC |
421 / 451 with "try again later" or "rate limited" | Remote greylisting or throttling | Usually clears by itself; slow the sender down |
Mailbox quota exceeded | Forwarding to a full remote mailbox | Remove or fix the forwarder |
retry timeout exceeded for one domain | Recipient MX is down | Wait it out; consider raising the threshold |
3. Is it one forwarder?
Forwarders to Gmail, Outlook.com, or Yahoo are the most common false positive on shared servers. Forwarded spam gets rejected by the remote provider, and those rejections count against the forwarding domain. List the domain's forwarders:
cat /etc/valiases/example.com
If most of the failures go to a single external address, removing that forwarder fixes the problem.
Clear the block
When the domain is clean and the cause is fixed, the block lifts automatically once the failure percentage for the rolling hour drops below the threshold. To clear it straight away, remove the marker file:
rm -f /var/cpanel/email_send_limits/max_deferfail_example.com
If the domain trips again within minutes, the old hour's counters are still pushing it over the limit. Clear the domain's tracking data too:
rm -rf /var/cpanel/email_send_limits/track/example.com
/scripts/restartsrv_exim
Raise the limit for one account
Some customers send a lot of mail and bounce a lot through no fault of their own, such as membership organisations with old address lists. Raise their limit instead of switching the protection off for the whole server:
whmapi1 modifyacct user=customer1 MAX_DEFER_FAIL_PERCENTAGE=50
For one domain inside an account, edit /var/cpanel/users/customer1 and rebuild the
threshold files Exim reads:
echo "MAX_DEFER_FAIL_PERCENTAGE-example.com=50" >> /var/cpanel/users/customer1
/usr/local/cpanel/scripts/updateuserdomains
Setting the server-wide percentage back to Unlimited removes the one control that stops a hacked WordPress install from sending unchecked. If you use resellers, set a ceiling in the package so the default carries over to new accounts (see WHM packages and feature lists).
How do I reset max defers and failures per hour in cPanel?+
Where is the max defers and failures setting in WHM?+
Can a cPanel user clear the defer/fail block themselves?+
Do deferred emails count towards the cPanel failure limit?+
Why does the block still apply after I deleted the max_deferfail file?+
Next steps
- Exim outbound throttling on cPanel: the full layered setup this limit belongs to.
- Clear a frozen or stuck Exim mail queue: use it when the defer/fail block left a backlog.
- cPanel per-domain outbound IPs with mailips: keep a high-bounce sender off your shared IP's reputation.
Running a fleet that needs licenses for every node? See cPanel license pricing or contact sales about volume.