Your customers say they never got the invoice. You sent a test email an hour ago and it still hasn't landed. Nothing bounced, nothing errored. The mail just seems to be sitting somewhere. On a cPanel server, that "somewhere" is almost always the Exim mail queue.

This guide shows you how to look inside the queue, work out why it's backed up, clear it safely, and stop it happening again. It applies to SkyServer cPanel/WHM VPS plans and any server running Exim.

Symptoms of a stuck mail queue

  • Outgoing email arrives hours late, or not at all, with no bounce message.
  • WHM's Mail Queue Manager shows hundreds or thousands of messages.
  • Webmail sends fine but recipients see nothing.
  • Your server's load climbs every few minutes when Exim runs its queue.
  • Disk usage grows steadily under /var/spool/exim.

What the queue actually is

When someone sends mail, Exim tries to deliver it right away. If the remote server says "try later," refuses the connection, or Exim can't resolve the destination, the message waits in the queue and Exim retries on a schedule. Messages that fail repeatedly eventually get a bounce and are removed after a few days.

A big queue is a symptom, not a diagnosis. You need to know what is in it before you delete anything.

Step 1: See how big the queue is

SSH in as root and run:

exim -bpc

That prints the number of messages queued. A healthy small server usually sits in the single or low double digits. Thousands means something is wrong.

To see the messages themselves:

exim -bp | head -50

Each entry shows age, size, message ID, sender, and recipient. Frozen messages are tagged *** frozen ***.

Step 2: Work out why it's backed up

Look at the sender column first. Then match what you see to the table below.

What you seeLikely causeWhere to go
Thousands from one cPanel user or one script pathHacked WordPress or a compromised form sending spamStep 3
Many <> senders to random addressesBounce backscatter from forged mailStep 4
Mixed legitimate mail all aging to one providerRemote server blocking you (blacklist or rate limit)Step 5
Everything fails with DNS or connection errorsResolver down, or outbound port 25 blockedStep 6
Messages marked frozenUndeliverable bounces Exim gave up onStep 4

Find the top senders quickly

exim -bp | exiqsumm | sort -nr | head

That groups queued mail by destination domain. If 90% of it is headed to gmail.com or one odd domain, you have your lead.

To find which account is sending, check the message headers of one item:

exim -Mvh <message-id> | grep -iE "auth_id|X-PHP-Originating-Script|X-Source"

auth_id points to a mailbox login. X-PHP-Originating-Script points to a PHP file, which means a website script is sending, not a person.

Step 3: Stop the source before you clear anything

If a hacked site is spraying mail, clearing the queue just gives you a fresh empty queue that refills in minutes. Fix the source first.

  1. Identify the account from the headers above.
  2. Suspend outgoing mail for that account in WHM under Email → Suspend or Unsuspend Outgoing Email.
  3. Scan the account (ImunifyAV, ClamAV, or manual review of recently modified PHP files).
  4. Change the cPanel, FTP and WordPress admin passwords.
  5. Update or remove the vulnerable plugin that let them in.

If the sender is a mailbox login rather than a script, the password was probably leaked. Reset it right away.

Step 4: Clear frozen and bounce messages safely

Frozen messages and null-sender bounces are the safest things to delete. Nobody is waiting on them.

Remove all frozen messages:

exiqgrep -z -i | xargs exim -Mrm

Remove all bounce messages (empty sender):

exiqgrep -i -f '^<>$' | xargs exim -Mrm

Remove everything from one spamming sender address:

exiqgrep -i -f spammer@example.com | xargs exim -Mrm

You can do the same from WHM under Email → Mail Queue Manager, which lets you filter and delete in the browser.

Don't run rm -rf /var/spool/exim/input/*. It leaves orphaned data and log entries and can corrupt the queue state. Always delete through exim -Mrm or the WHM interface.

Step 5: When legitimate mail is stuck

If the queued mail is real, don't delete it. Check why the remote server is refusing it:

exim -Mvl <message-id>

This shows the delivery log for that message. Typical remote responses:

  • 421 / 450 "try again later": temporary throttling or greylisting. Usually clears on its own.
  • 550 "blocked using Spamhaus": your server IP is blacklisted. Check the IP on the blocklist lookup tools, fix the cause, then request delisting.
  • 550 "SPF / DKIM / DMARC failed": your DNS authentication records are wrong or missing.

Once the cause is fixed, force a retry of the whole queue:

exim -qff

The -ff flag also retries frozen messages. On a big queue this can briefly spike load, so run it during a quiet hour.

Step 6: When nothing can be delivered at all

If every message fails with a DNS or connection error, test from the server:

dig gmail.com MX +short
telnet gmail-smtp-in.l.google.com 25

If DNS fails, check /etc/resolv.conf and your resolver. If DNS works but port 25 times out, outbound port 25 is being blocked at the network level. In that case you'd need to relay through an authenticated SMTP service on port 587.

Prevention

  • Set a per-domain hourly send limit in WHM (Tweak Settings → Mail → Max hourly emails per domain). A hacked site then hits a ceiling instead of sending 50,000 messages.
  • Keep WordPress core, themes and plugins updated. Most outbound spam comes from outdated plugins.
  • Publish correct SPF, DKIM and DMARC records for every sending domain.
  • Enable WHM's Mail Queue or server-notification alerts so you hear about a growing queue early.
  • Use strong, unique passwords for every mailbox.
  • Run exim -bpc in a small cron job and email yourself if the count crosses a threshold such as 200.

A simple example of that cron check:

*/15 * * * * [ $(exim -bpc) -gt 200 ] && echo "Exim queue is high" | mail -s "Mail queue alert" you@example.com

Frequently Asked Questions

Is it safe to delete the whole mail queue?

It's safe for the server but not for your customers. You'll lose any real emails waiting for delivery, and the senders won't be told. Delete frozen messages, bounces and clearly spam-sourced mail, and keep the rest.

How long does Exim keep undeliverable mail?

By default, Exim keeps retrying for about four days. After that it generates a bounce to the sender and removes the message.

Why do messages become frozen?

Exim freezes a message when it can't deliver it and can't send a bounce back either, usually because the sender address is forged or invalid. Frozen messages stay until you remove them or they time out.

Will clearing the queue fix my blacklisting?

No. Clearing the queue removes the symptom. If your IP is listed, you still have to stop the spam source, then request delisting from the blocklist operator.

Can I check the queue without SSH?

Yes. In WHM, open Email → Mail Queue Manager to view, filter, deliver or delete messages from the browser.