This server acts on its own: compromise stops. Everything else waits for you.
Protection posture
What this server does without being asked. Each of these is a switch somebody set; the page it names is where it is turned off again.
Server
Accounts and mailboxes this server carriesHow outbound mail ended
Delivery attempts, per recipient. Shares as well as counts, because a number of failures means nothing without the traffic it came from.
| Delivered | 828 | 96.5% |
| Deferred | 18 | 2.1% |
| Bounced | 12 | 1.4% |
Who is sending
Ordered by volume, with how their mail landed. The one worth opening is rarely the busiest — it is the busy one whose mail is not arriving.
| Sender | Messages | Recipients | Failed | Delivered |
|---|---|---|---|---|
| [email protected] | 342 | 342 | 1% | |
| [email protected] | 210 | 205 | none | |
| [email protected] | 148 | 148 | none | |
| [email protected] | 92 | 92 | 4% | |
| [email protected] | 38 | 12 | none | |
| [email protected] | 22 | 40 | none | |
| [email protected] | 11 | 11 | none |
Needs attention
Ranked by severity.
System health
Read-only checks. MailGuard stays fail-open.
Message reports
One row per message. The report id opens everything recorded about it.
| Date (UTC) | Report ID | Actions | User / IP | Events | Method / route | Message |
|---|
Email events
Page 1 of 1. Message bodies and attachments are never stored.
| Time (UTC) | Direction | Sender / Auth user | Recipient / Domain | Status | Message ID | Source | |
|---|---|---|---|---|---|---|---|
| 2026-08-23 10 messages | |||||||
| 2026-08-23 09:41 | inbound | [email protected] | [email protected] store.example.com | delivered | 1sA0mA-4kP2qd-Ra |
192.0.2.70 | Details |
| 2026-08-23 09:37 | inbound | [email protected] | [email protected] host.example.net | delivered | 1sA0dS-2mN7rs-Ea |
192.0.2.145 | Details |
| 2026-08-23 09:29 | inbound | [email protected] | [email protected] sm.example.org | delivered | 1sA0aB-8dF3wq-Sb |
192.0.2.201 | Details |
| 2026-08-23 09:22 | inbound | [email protected] | [email protected] cloud.example.com | deferred
Greylisted
451 4.7.1 Greylisted, please retry shortly
|
1sZ9wC-1gH5rt-Tc |
192.0.2.88 | Details |
| 2026-08-23 09:20 | inbound | [email protected] | [email protected] blog.example.com | delivered | 1sZ9uX-5xY7bc-Zi |
192.0.2.33 | Details |
| 2026-08-23 09:14 | inbound | [email protected] | [email protected] store.example.com | rejected
Spam refused
550 5.7.1 Message rejected: spam score 9.2
|
1sZ9pD-6jK7yu-Ud |
192.0.2.240 | Details |
| 2026-08-23 09:06 | inbound | [email protected] | [email protected] host.example.net | delivered | 1sZ9hE-3lM9za-Ve |
192.0.2.112 | Details |
| 2026-08-23 08:58 | inbound | [email protected] | [email protected] corp.example.com | delivered | 1sZ992-0hi7lm-En |
192.0.2.145 | Details |
| 2026-08-23 08:49 | inbound | [email protected] | [email protected] mail.example.net | delivered | 1sZ917-9nP1bc-Wf |
192.0.2.55 | Details |
| 2026-08-23 08:41 | inbound | [email protected] | [email protected] sm.example.org | received | 1sZ8x8-5qR3de-Xg |
192.0.2.201 | Details |
Account activity
Last 30 days · aggregated from parsed Exim metadata. Page 1 of 1.
| Account | Events▾ | Inbound | Outbound | Delivered | Failures | State | Enforcement | Last seen | ||
|---|---|---|---|---|---|---|---|---|---|---|
| storeco store.example.com | 7,520 | 980 | 6,540 | 7,180 | 141 | normal | none | 1m ago |
|
|
| blogco blog.example.com | 4,820 | 610 | 4,210 | 4,660 | 96 | normal | none | 3m ago |
|
|
| mailco mail.example.net | 3,520 | 540 | 2,980 | 3,410 | 58 | allowed | none | 2m ago |
|
|
| corpco corp.example.com | 3,380 | 1,520 | 1,860 | 3,240 | 118 | normal | none | 6m ago |
|
|
| cloudco cloud.example.com | 1,960 | 720 | 1,240 | 1,910 | 24 | normal | none | 4m ago |
|
|
| smco sm.example.org | 1,860 | 880 | 980 | 1,820 | 18 | normal | none | 9m ago |
|
|
| hostco host.example.net | 1,630 | 870 | 760 | 1,600 | 12 | normal | none | 12m ago |
|
Marking an entity protected can only ever prevent an action, never cause one. Anything that could cause one lives behind the enforcement ledger, where it carries evidence, an expiry and a reversal.
Why the queue is not moving
The frozen messages, grouped by what their own delivery histories say stopped them.
storeco submitted a burst well above its baseline; the receiving relay refused the surplus and Exim froze what was left.
What to check: Review store.example.com's sending pattern on the Deliverability page.
421 4.7.0 too many messages this session
Bounces, forwarder mail and system notices look identical to a spam run in a listing. Read why a message stopped before removing it.
Empty the queue
This deletes mail. Here it costs the message. Nothing else in MailGuard does — everything else freezes, throttles or moves, so being wrong costs a delay.
A queue is not a spam bucket. A deferred message is the normal state of mail waiting on greylisting or a receiving server that is briefly down, and it will deliver by itself. Frozen is what Exim has given up on, which is why it is the scope offered first.
Each is on a domain this server hosts, and no mailbox by that name exists. Nobody can log into a mailbox that was never created, so these are forged envelope senders or a script inventing them.
Sending addresses
Forged first. An address on someone else's domain is never flagged — we have no way to know whether it should be sending.
| Address | Domain | Account | Verdict | Messages▾ | State | Last seen | ||
|---|---|---|---|---|---|---|---|---|
| [email protected] blocked | blog.example.com hosted here | — | forged | 12 | blocked (SMTP) | 8m ago | ||
| [email protected] | store.example.com hosted here | storeco | real mailbox | 6,540 | sending | 2m ago | ||
| [email protected] | blog.example.com hosted here | blogco | real mailbox | 4,210 | sending | 6m ago | ||
| [email protected] | mail.example.net hosted here | mailco | real mailbox | 2,980 | sending | 4m ago | ||
| [email protected] | corp.example.com hosted here | corpco | real mailbox | 1,860 | sending | 9m ago | ||
| [email protected] | cloud.example.com hosted here | cloudco | real mailbox | 1,240 | sending | 14m ago | ||
| [email protected] | sm.example.org hosted here | smco | real mailbox | 980 | sending | 21m ago | ||
| [email protected] | host.example.net hosted here | hostco | real mailbox | 760 | sending | 33m ago | ||
| [email protected] | host.example.net hosted here | — | system | 34 | sending | 12m ago |
csf is installed and can enforce blocks on this server. Every block carries an expiry and can be lifted before it runs out.
What this server has — cPanel & WHM
1. csf — usable — in use 2. iptables — installed, not usable — csf manages the rules here; raw iptables rules are discarded on its next reload. (no expiring rules) 3. firewalld — not installedNetworks
Grouping is what makes a spread-out campaign visible. Spreading attempts across many addresses is how it stays under a per-address limit. A network here will usually outscore every single address inside it.
| Network | Owner | Addresses | Attempts | Score | Last seen |
|---|---|---|---|---|---|
203.0.113.0/24 |
🇳🇱
Example Transit BV
AS64500
|
3 | 480 | 82 | 6h ago |
Targeted mailboxes
A campaign working through real account names has a list of this server's customers. Counting refusals is the half that matters least — a thousand of them is a machine wasting its time, and one acceptance is somebody reading the mail. The fourth column is that one. One guessing generic names like "admin" is scanning at random — a different problem.
| Mailbox tried | Attempts | From addresses | Did anything get in? | Last attempt |
|---|---|---|---|---|
| support | 210 | 2 | No Refused every time; the password never matched. | 6h ago |
| admin | 180 | 3 | No Generic name — a random scan, not this server's list. | 6h ago |
| test | 90 | 1 | No All attempts refused; no session opened. | 7h ago |
Automatic blocking of failed logins
Past the threshold, an address is blocked for a day on its own record.
An address in an allowed country (none chosen yet) is never blocked automatically — that risks cutting off a customer fighting their own password. Those arrive as a notification instead, and the decision is yours here.
Addresses
Individual sources. Check the network table above before judging any one of them.
| Address | Location and owner | Class | Auth fails | Rejects | Score▾ | Last seen | Firewall | |
|---|---|---|---|---|---|---|---|---|
203.0.113.24 |
🇳🇱
Example Transit BV
vps-24.example.net datacenter
|
attacker | 480 in 24h 480 ever | 0 | 82 | 6h ago |
no rule
|
|
198.51.100.24 |
🇺🇸
Example ISP
smtp.example.com
|
clean | none in 24h 1 ever | 0 | 8 | 4m ago |
no rule
|
|
192.0.2.145 |
🇩🇪
Example Broadband
cpe-145.example.net
|
suspicious | 20 in 24h 20 ever | 2 | 44 | 25m ago |
no rule
|
|
203.0.113.51 |
🇬🇧
Example Networks
relay.example.com
|
trusted | none in 24h 0 ever | 0 | 5 | 2m ago |
no rule
|
|
198.51.100.88 |
🇫🇷
Example Cloud
mx.example.com datacenter
|
clean | none in 24h 2 ever | 0 | 10 | 8m ago |
no rule
|
|
203.0.113.12 |
🇨🇦
Example Telecom
out-12.example.net
|
clean | none in 24h 0 ever | 0 | 6 | 11m ago |
no rule
|
It arrives with the enforcement ledger, so a blocked address carries an expiry, an audit entry and a one-click reversal like every other measure — rather than becoming an entry nobody remembers adding.
A spam run is not visible one message at a time. It is one source sending more than it should, to more people than it has business knowing, with the same subject over and over — none of which survives a list sorted by time. Nothing here is a verdict: a newsletter and a spam run have the same shape, and telling them apart is your job, not this page's.
What receiving servers said
Outgoing mail that did not arrive, grouped by the reason the receiving server gave. A wrong address and a spam verdict are both a failed delivery and they want opposite responses — one is a stale list, the other is this server's reputation and applies to every message sent afterwards.
| What was said | Messages | Senders | What it means | Last seen | |
|---|---|---|---|---|---|
| Recipient unknown | 234 | 3 | The address does not exist at the receiving server — a stale list, not a reputation problem. Prune it and the number falls. | 3h ago | Who |
| Refused as spam | 96 | 2 | The receiving server judged the message spam. Unlike a bad address this follows the sending IP — it affects every message sent afterwards. | 2h ago | Who |
| Relay / policy denied | 72 | 2 | The receiving server declined to accept mail for that recipient under its own policy — often an alias that no longer forwards. | 5h ago | Who |
| Greylisted, will retry | 296 | 5 | A temporary deferral; the receiving server asked us to try again shortly. Normal, and it clears itself. | 24m ago | Who |
| Bounced after acceptance | 210 | 4 | Accepted at the door then returned later — the failure came from inside the receiving system, not from us. | 1h ago | Who |
One message, many strangers
The same subject from one address, spread across unrelated recipient domains. A newsletter looks like this and so does a hijacked signup form — something submitting a site's registration page with harvested addresses, and the site sending each of them the confirmation it was built to send. Nothing is broken into, which is why nothing else on this page finds it. Check the form before the address: suspending the sender stops the site's real mail and leaves the form open.
| Sender | Subject | Domains | Refused | What it looks like | Last seen | ||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| [email protected] | Invoice overdue — please review the attached statement | 11 | 9 (75%) | One subject to 11 unrelated recipient domains from an address with no mailbox on this server. A forged sender, or a signup form on the site being driven with harvested addresses — check the form before suspending the address. | 2h ago | ||||||||||||||||||||||||||||||||||||||||||
Show the 5 messages behind this — the most recent of 12, 14 delivery attempts in all
|
|||||||||||||||||||||||||||||||||||||||||||||||
Sources worth opening
Ordered by what the sending looks like, not by who sent most. Volume is what a mailing list and a spam run have in common, so each row says what its shape is and which figures say so.
| Sender | This address | Messages | Recipients | Subjects | Refused | Seen | ||
|---|---|---|---|---|---|---|---|---|
| [email protected] transactional 6,540 messages to 5,210 recipients across 340 subjects — one recipient per message, many subjects. The shape of an order pipeline, not a run. |
no limit
|
6,540 | 5,210 | 340 | 178 | 3m ago | Messages | |
| [email protected] broadcast 4,210 messages, 26 subjects, 3,980 recipients — few subjects to many strangers. A broadcast; a newsletter and a spam run look identical here. |
no limit
|
4,210 | 3,980 | 26 | 62 | 12m ago | Messages | |
| [email protected] transactional 2,980 machine-generated messages, one recipient each — a transactional stream of password resets and receipts. |
no limit
|
2,980 | 2,860 | 45 | 34 | 8m ago | Messages | |
| [email protected] unsigned 1,860 authenticated messages with no DKIM signature over the window — a deliverability risk, not a spam run. See the open incident. |
no limit
|
1,860 | 610 | 30 | 66 | 3h ago | Messages | |
| [email protected] monitoring 1,240 messages, 210 subjects, to 40 operator addresses — a monitoring feed, many subjects to a handful of people. |
no limit
|
1,240 | 40 | 210 | 18 | 20m ago | Messages | |
| [email protected] correspondence 980 messages, 88 subjects, 120 recipients — ordinary team correspondence, no single subject dominating. |
no limit
|
980 | 120 | 88 | 20 | 1h ago | Messages | |
| [email protected] correspondence 760 replies across 150 subjects to 240 recipients — one-to-one support mail. |
no limit
|
760 | 240 | 150 | 15 | 42m ago | Messages | |
| [email protected] system 160 cron and system notices to 3 local operator addresses — generated on this server, not customer mail. |
no limit
|
160 | 3 | 12 | 0 | 6m ago | Messages | |
| [email protected] no mailbox 12 messages, one subject, to 11 unrelated domains from an address with no mailbox on this server — forged, or a hijacked form. Already frozen. |
held
|
12 | 11 | 1 | 9 | 2h ago | Messages |
Every incident
Anything waiting for a decision is first. Contained means a measure is in force, not that the problem is over — resolving is a separate judgement, and dismissing records that the detection was wrong so the same signal stops reopening it.
Account storeco (store.example.com) sent far more mail than its usual pattern within a single hour. A brief hold was placed while the spike was checked.
None needed — volume normalised and the brief hold was released.
Mail from corp.example.com is authenticated but carries no DKIM signature, which weakens deliverability and lets a receiver treat it as unverified.
Publish a DKIM selector and enable signing.
A single source hammered SMTP authentication against several mailboxes without ever succeeding. The address is now rate-limited at submission.
Monitored — the source is rate-limited at submission.
A message is moved to the mailbox's spam folder, where the person can still see it and their mail client's "not spam" button still works. Every move is recorded below and can be undone. If a judgement is wrong, the cost is that a message was in the wrong folder for a while — never that it is gone.
The trust mark
Mail from senders you have marked good arrives carrying an
X-MailGuard-Trusted header, which filters and rules can act on.
Nothing the sender wrote is altered. An earlier version put a tick at the front of the subject: it broke the sender's DKIM signature, and because a header cannot carry raw UTF-8 it reached readers as mojibake — on one real invoice thread, twice over, once per reply. Remote arrivals only; nothing outbound is touched.
Suspect inbound — spam and the doubtful only
Every row names the evidence that put it here.
Marking a sender good removes them from this page in future — unless a message arrives forged or from a known spam source, when it is shown again with its trusted mark and the doubt beside it. Nothing that starts here can block a sender: the worst outcome is the Junk folder, and restore is the way back.
| Time | From | Why it is here | To | Subject | Actions — Junk at worst, never a block | |
|---|---|---|---|---|---|---|
| 2026-08-23 09:58 UTC | [email protected] | 9 Forged sender Blocklisted source | [email protected] | Invoice overdue — please pay immediately |
|
|
| 2026-08-23 09:44 UTC | [email protected] | 7 Reply-to mismatch Bulk pattern | [email protected] | Re: your account access has been limited |
|
|
| 2026-08-23 09:15 UTC | [email protected] trusted | 6 Sudden volume | [email protected] | Fwd: shared document for review |
|
What has been moved
Every move, whether it worked or not. A failed move changed nothing.
| When | Mailbox | From | Subject | Folder | State | Undo |
|---|---|---|---|---|---|---|
| 2026-08-23 08:20 UTC | [email protected] | [email protected] | Invoice overdue — please pay immediately | Inbox → Junk | moved | |
| 2026-08-23 07:55 UTC | [email protected] | [email protected] | Refund request — your account may be compromised | Inbox → Junk | moved | |
| 2026-08-22 22:10 UTC | [email protected] | [email protected] | Your mailbox is full — verify now | Inbox → Junk | moved | |
| 2026-08-22 18:40 UTC | [email protected] | [email protected] | You have unclaimed funds waiting | Inbox → Junk | restored | restored 2026-08-22 19:15 UTC |
Sending readiness
Records read from live DNS; rates from what this server's mail actually did over 30 days. Spam rate counts mail receivers refused — the visible edge of filtering, since only the receiver sees its spam folder.
| Domain | Score▴ | MX | SPF | Covers this server | DKIM | DMARC | Sent 30d | Spam rate | Reputation | Checked (UTC) | ||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| corp.example.com | 68/100 | internal | ok | covered | missing | monitoring | 1,860 | 0.4% | — | 2026-08-23 09:12:07 | ||
| host.example.net | 82/100 | internal | ok | covered | ok | monitoring | 760 | 0.3% | — | 2026-08-23 09:12:31 | ||
| sm.example.org | 85/100 | internal | ok | covered | ok | enforced | 980 | 0.2% | — | 2026-08-23 09:12:52 | ||
| store.example.com | 88/100 | internal | ok | covered | ok | monitoring | 6,540 | 0.5% | — | 2026-08-23 09:11:44 | ||
| cloud.example.com | 90/100 | internal | ok | covered | ok | enforced | 1,240 | 0.2% | — | 2026-08-23 09:13:18 | ||
| blog.example.com | 94/100 | internal | ok | covered | ok | enforced | 4,210 | 0.2% | — | 2026-08-23 09:10:59 | ||
| mail.example.net | 96/100 | internal | ok | covered | ok | enforced | 2,980 | 0.1% | — | 2026-08-23 09:13:40 |
This server's sending reputation
No record fixes a blocked address, so this is checked before anything else is worth doing. Shared by every domain on the machine.
4 of 4 checks came back clean.
Score a message
Paste the raw source and every deduction is named. Judged from the sending domain's live DNS and the message itself; no scorer can promise what one receiver's filter will do.
Send an ordinary message and this server tells you what happened to it. No headers, no copying, nothing to install.
-
Copy this subject line
MG-DEMO7Q - Send one message with it From a mailbox on the domain you are testing, to an address outside this server — your own Gmail or Outlook will do, because the answer worth having is what a real receiver did with it. The subject must be the code and nothing else; the body can say anything.
- Come back and press Look for it The code stays on this page for 60 minutes, so leaving and returning is safe.
Or paste a message's source
A domain whose MX points elsewhere, or whose DNS is served by another provider, is read-only here. MailGuard reports on it and shows the record you would need, but changes nothing — and only ever writes TXT records, so nothing it does can alter mail routing.
Sending provider
The relay your SPF records must authorise. Suggestions below build on this choice — No relay observed: this server delivers directly, so a and mx cover it.
v=spf1 a mx ~all
Automatic reads the relay from the last 30 days of real deliveries and needs no maintenance when you change provider. Fixing a choice here overrides it — for a relay about to go live, or one this build does not recognise yet.
blog.example.com all checks pass managed here 94
Mail for this domain is delivered here, so its mailboxes and sending both run on this server.
| Record | Published now | Should be |
|---|---|---|
| MX | 0 blog.example.com this server |
no change needed |
| SPF | v=spf1 a mx ~all |
no change needed |
| DKIM | selector default v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvz3nQm8Kd2sT7pXQf9wJ… |
no change needed |
| DMARC | v=DMARC1; p=quarantine; rua=mailto:[email protected] |
no change needed |
DNS provider: this server — the nameservers for this domain resolve here, so MailGuard can publish the records it recommends.
MX points at this server, so mail for this domain is received locally.
Record: v=spf1 a mx ~all — it authorises this server and closes with ~all.
Selector "default" is published.
Policy is p=quarantine, so receivers act on forged mail rather than only reporting it.
cloud.example.com all checks pass managed here 90
Mail for this domain is delivered here, so its mailboxes and sending both run on this server.
| Record | Published now | Should be |
|---|---|---|
| MX | 0 cloud.example.com this server |
no change needed |
| SPF | v=spf1 a mx ~all |
no change needed |
| DKIM | selector default v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvz3nQm8Kd2sT7pXQf9wJ… |
no change needed |
| DMARC | v=DMARC1; p=quarantine; rua=mailto:[email protected] |
no change needed |
DNS provider: this server — the nameservers for this domain resolve here, so MailGuard can publish the records it recommends.
MX points at this server, so mail for this domain is received locally.
Record: v=spf1 a mx ~all — it authorises this server and closes with ~all.
Selector "default" is published.
Policy is p=quarantine, so receivers act on forged mail rather than only reporting it.
corp.example.com 2 problems, 1 fixable managed here 68
Mail for this domain is delivered here, so its mailboxes and sending both run on this server.
| Record | Published now | Should be |
|---|---|---|
| MX | 0 corp.example.com this server |
no change needed |
| SPF | v=spf1 a mx ~all |
no change needed |
| DKIM | no signature found under the selectors commonly used — a domain may still sign under one of its own |
v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAq7Jd9mR2xP0nT4wKf1sV…
as TXT on default._domainkey.corp.example.com
|
| DMARC | v=DMARC1; p=none; rua=mailto:[email protected] |
v=DMARC1; p=quarantine; rua=mailto:[email protected]
as TXT on _dmarc.corp.example.com
|
DNS provider: this server — the nameservers for this domain resolve here, so MailGuard can publish the records it recommends.
MX points at this server, so mail for this domain is received locally.
Record: v=spf1 a mx ~all — it authorises this server and closes with ~all.
No selector is published for this domain, so its mail cannot be authenticated by DKIM. Publish a selector and enable signing.
default._domainkey.corp.example.com TXT v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAq7Jd9mR2xP0nT4wKf1sV…
SPF passes for this domain, but with no DKIM in place policy is still p=none, which reports forged mail and delivers it anyway. Publish DKIM first, then move to quarantine.
host.example.net 1 problem managed here 82
Mail for this domain is delivered here, so its mailboxes and sending both run on this server.
| Record | Published now | Should be |
|---|---|---|
| MX | 0 host.example.net this server |
no change needed |
| SPF | v=spf1 a mx ~all |
no change needed |
| DKIM | selector default v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvz3nQm8Kd2sT7pXQf9wJ… |
no change needed |
| DMARC | v=DMARC1; p=none; rua=mailto:[email protected] |
v=DMARC1; p=quarantine; rua=mailto:[email protected]
as TXT on _dmarc.host.example.net
|
DNS provider: this server — the nameservers for this domain resolve here, so MailGuard can publish the records it recommends.
MX points at this server, so mail for this domain is received locally.
Record: v=spf1 a mx ~all — it authorises this server and closes with ~all.
Selector "default" is published.
SPF and DKIM both pass for this domain, so receivers can safely be asked to act on failures. Policy is still p=none, which reports forged mail and delivers it anyway. Quarantine is the next step.
mail.example.net all checks pass managed here 96
Mail for this domain is delivered here, so its mailboxes and sending both run on this server.
| Record | Published now | Should be |
|---|---|---|
| MX | 0 mail.example.net this server |
no change needed |
| SPF | v=spf1 a mx ~all |
no change needed |
| DKIM | selector default v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvz3nQm8Kd2sT7pXQf9wJ… |
no change needed |
| DMARC | v=DMARC1; p=quarantine; rua=mailto:[email protected] |
no change needed |
DNS provider: this server — the nameservers for this domain resolve here, so MailGuard can publish the records it recommends.
MX points at this server, so mail for this domain is received locally.
Record: v=spf1 a mx ~all — it authorises this server and closes with ~all.
Selector "default" is published.
Policy is p=quarantine, so receivers act on forged mail rather than only reporting it.
sm.example.org all checks pass managed here 85
Mail for this domain is delivered here, so its mailboxes and sending both run on this server.
| Record | Published now | Should be |
|---|---|---|
| MX | 0 sm.example.org this server |
no change needed |
| SPF | v=spf1 a mx ~all |
no change needed |
| DKIM | selector default v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvz3nQm8Kd2sT7pXQf9wJ… |
no change needed |
| DMARC | v=DMARC1; p=quarantine; rua=mailto:[email protected] |
no change needed |
DNS provider: this server — the nameservers for this domain resolve here, so MailGuard can publish the records it recommends.
MX points at this server, so mail for this domain is received locally.
Record: v=spf1 a mx ~all — it authorises this server and closes with ~all.
Selector "default" is published.
Policy is p=quarantine, so receivers act on forged mail rather than only reporting it.
store.example.com 1 problem managed here 88
Mail for this domain is delivered here, so its mailboxes and sending both run on this server.
| Record | Published now | Should be |
|---|---|---|
| MX | 0 store.example.com this server |
no change needed |
| SPF | v=spf1 a mx ~all |
no change needed |
| DKIM | selector default v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvz3nQm8Kd2sT7pXQf9wJ… |
no change needed |
| DMARC | v=DMARC1; p=none; rua=mailto:[email protected] |
v=DMARC1; p=quarantine; rua=mailto:[email protected]
as TXT on _dmarc.store.example.com
|
DNS provider: this server — the nameservers for this domain resolve here, so MailGuard can publish the records it recommends.
MX points at this server, so mail for this domain is received locally.
Record: v=spf1 a mx ~all — it authorises this server and closes with ~all.
Selector "default" is published.
SPF and DKIM both pass for this domain, so receivers can safely be asked to act on failures. Policy is still p=none, which reports forged mail and delivers it anyway. Quarantine is the next step.
Every outcome, in a table
One message is counted once, under the furthest it got. A message that arrived for one person and is held for another is counted as arrived.
| What happened | Messages | Share | From a website | What that means |
|---|---|---|---|---|
| Arrived | 17,903 | 95.5% | 3,893 | The message reached the address it was sent to. |
| Stayed on this server | 46 | 0.2% | — | Handed to a mailbox on this machine. It never went out. |
| You are holding it | 42 | 0.2% | — | Stopped here on purpose. It is waiting and can still be sent or deleted. |
| Still waiting | 8 | <0.1% | 1 | Accepted, and no attempt to send it has finished yet. |
| They asked us to wait | 296 | 1.6% | 30 | The receiving server said "not now". The server keeps trying on its own. |
| Refused as spam | 286 | 1.5% | 180 | The receiver rejected it and said it looked like spam. |
| Refused for another reason | 149 | 0.8% | 20 | Rejected for something else — usually a wrong address or a full mailbox. |
| Deleted here | 12 | <0.1% | 3 | A filter on this server threw it away. It never left. |
| Went to a program, not a person | 0 | 0% | — | Handed to a file, a pipe or an automatic reply on this machine. |
Of the messages refused as spam, 180 came from a program on one of your sites rather than from somebody's email program. That is the figure worth acting on: a person sending refused mail is a conversation, a website doing it is usually a site somebody broke into. Script Activity names the file and the account.
Mail you are holding
Holding stops sending only. Mail arriving for these accounts is untouched, and held mail waits rather than being lost.
| Account | Held since |
|---|---|
| [email protected] | 2026-08-23 09:03 UTC the figures above cover the chosen period, which may start before this |
Released or dropped from Actions.
How many times the server tried
A message to four people is one message and four attempts. This is what the server actually did.
| What happened | Attempts |
|---|---|
| delivered | 17,950 |
| held | 6,300 |
| deferred | 2,480 |
| refused spam | 286 |
| refused other | 149 |
| queued | 60 |
These count every try, including retries of messages that arrived before the period began — which is why a few held messages can appear here in their thousands while the table above counts only messages from this period.
Print the page and choose "Save as PDF". Everything below is laid out for paper: the navigation and the buttons go, panels are kept whole across page breaks, table headings repeat on each page and the charts print at the printer's resolution rather than the screen's. Narrow the report first — by period, domain or address — and what you print is what you chose.
When it happened
Counted by the hour over a day, or by the day over a month. A total says how much; only this says when — and "seven thousand of them between two and four on a Tuesday morning" is a different fact from the same seven thousand spread over a week.
Busiest hour: 11:00 — 1,008 messages counted across the day, 92 in the busiest hour, 9% of the period.
How it ended
Every delivery attempt in the period by what became of it, refusals named by the reason the receiving server gave rather than lumped together as failures.
- Delivered17,90895.2%
- Rejected4022.1%
- Deferred2961.6%
- Bounced2101.1%
Scheduled reports
Generated on their own and kept as files; mailed too when addresses are given. Leave the addresses empty and the file is the whole point — a report on disk needs no mail server to be useful.
| Report | Frequency | Recipients | State | Last run | Next run | |
|---|---|---|---|---|---|---|
| Weekly outgoing summary | weekly | [email protected], [email protected] | active | 2026-08-18 06:00 | 2026-08-25 06:00 |
|
| Monthly deliverability | monthly | file only | paused | 2026-08-01 06:00 | — |
|
What the last runs actually produced — the file is verifiable, the mail line says what this host accepted, not what arrived.
| When (UTC) | Type | State | File | Outcome |
|---|---|---|---|---|
| 2026-08-18 06:00:12 | outgoing_summary | completed | mailguard-2026-08-18-outgoing.csv.gz | submission accepted for 2 recipients |
| 2026-08-01 06:00:09 | deliverability | completed | mailguard-2026-08-01-deliverability.csv.gz | file only — no recipients |
Server summary
Last 30 daysOperations
Every deletion, block and stop this installation has made, with what it acted on.
| When (UTC) | Operation | Scope | By | Considered | Affected | Failed | Outcome | Detail |
|---|---|---|---|---|---|---|---|---|
| 2026-08-23 09:03:12 | queue_hold |
store.example.com | policy | 1 | 1 | 0 | Held 1 message — suspected spam, score 7.8 | Open |
| 2026-08-23 08:15:40 | rate_limit |
203.0.113.24 | auth-guard | 480 | 1 | 0 | Rate-limited source at submission after 480 failed auths | Open |
| 2026-08-23 07:42:05 | queue_release |
store.example.com | operator | 1 | 1 | 0 | Released held message after review | Open |
| 2026-08-22 22:10:33 | freeze |
corp.example.com | system | 3 | 3 | 0 | Froze 3 undeliverable messages in the queue | Open |
The archive
Months moved out of the database to keep it small, kept in full and readable here. Read-only. Nothing on this page deletes or moves an archive — the maintenance sweep owns them.
Nothing has been archived yet. A month is moved out once it is old enough that keeping it in the working database costs more than it is worth, and until then every report on this page is reading the live data.
Theme
Pick one to see it now. Saving makes it this server's default for anyone who has not chosen their own — a browser that has keeps its choice, so this restyles the people who never expressed a preference, not everybody.
Density, corners and motion
Not a theme — these multiply against whichever one is chosen. Pressing a choice applies it to this browser immediately and keeps it there. Saving makes it the server's default for anyone who has not chosen.
Collection
The switch and the systemd timer change together. A flag without its timer is how a server reads "enabled" while nothing runs.
Storage, enrichment and the interface
Where things live
Update, policy, country and compromise settings live on their own pages, beside the things they govern.
Sender identity
How mail actually left this server in the last 30 days.
As user@demo-host
or as the customer's own [email protected].
Behind the hostname identity — system mail here is expected; a customer's script here should be sending as its own domain instead:
| Sender | Messages 30d | Last seen |
|---|---|---|
| root@demo-host | 1,180 | 2m ago |
| cron@demo-host | 120 | 8m ago |
Currently in force: user@demo-host (no rewrite — native behaviour) — read from the generated Exim configuration, not from a stored preference. A mailer that already sends as its own domain is never touched; the rewrite only applies to mail that would have left as user@demo-host.
Identity on forwarded mail
Mail this server passes on for someone elseA forwarder re-sends a message somebody else wrote. By default this server keeps their envelope sender, so the receiving side sees this server sending as a domain that never listed it, fails the sender check, and refuses — usually recorded as spam, because that is the bucket refusals land in. The message was fine; the identity on it was not this server's to use.
Rewriting replaces only the envelope sender with a local, reversible address. The
From: header and the reply button still show whoever wrote the message, and
bounces come back here and are decoded to the original sender.
No forwarders are configured on this server, so nothing here applies until one is.
Currently in force: original sender kept — read back from the generated Exim configuration, not from a stored preference. Mail this server originates is never touched; this applies only to what it forwards.
Exim configuration backups
Every change this product makes to Exim is preceded by a snapshot of every file it can write. Any of them can be put back at any time. Taken automatically — there is no way to change Exim here without one.
| Taken | Before | Files | Version | Restore |
|---|---|---|---|---|
| 18 hours ago exim-20260822-2231 | Before applying sender identity | 6 | 1.0 | |
| 3 weeks ago exim-20260801-0904 kept permanently | Before MailGuard first changed Exim The earliest configuration on record here. On a server MailGuard was only just installed on, that is the state before it changed anything; on one it has been running on, it is simply the oldest snapshot there is. | 6 | 1.0 |
A restore writes back every file the snapshot holds and removes any this product manages that the snapshot did not have — otherwise a rule added afterwards would stay in force and the restore would report success while being partial. The state you leave is saved first, so a restore is itself reversible; the checksums are verified before a byte is written; and if Exim refuses the restored configuration it is undone and the previous one rebuilt.
Snapshots live in /opt/mailguard/var/exim-backups
and are readable without this interface, which matters on the day the interface is what
broke. 10 are kept, plus the first one permanently.
Alerts
Where this server tells you it is under attack. Raised automatically for a compromised sending origin, a surge of refusals against this server's own normal, a mailbox being guessed at, and any mail stopped without you asking.
Environment
Detected automatically; override in configuration if wrong.
Runtime checks
MailGuard stays fail-open: mail flows even when these fail.
Enforcement capability
What this host can actually execute, probed rather than assumed. Unavailable rungs are skipped by the engine — they are not failures.
Driver detection
Every driver scores itself; the highest wins.
IP enrichment
Country and network ownership for the IP watch page.
Paths and tools
Resolved for this environment.
Content scan for locally submitted mail
A rehearsal: it scores and records, and acts on nothing. Mail from a PHP script or a cron job never opens an SMTP session, so the ACL carrying the spam check does not run for it. This scores that traffic so you can see what a real check would have caught before deciding whether to allow one.
This server
The same survey the installer runs. So what is reported here and what was reported at install cannot disagree. Re-read on every load: a package update can remove an extension that was there yesterday.
This server’s license
The license is bound to this server’s IP and hardware fingerprint, and every check is verified against a key built into the plugin — a key from another server, or an edited state file, is refused. Your key was emailed on purchase and is on your account under “My Licenses”.
Active key on this server:
MS-2026-DEMO-••••-••••
Activate a different key
Module
This module ships in the installed MailGuard plugin. This interactive sandbox showcases the populated screens below.
Explore: Email Flow · Reports · Deliverability · Incidents · Spam Detection · Senders · IP Watch · Mail Queue · Statistics · Mail DNS