Email Spam Tester

Email Spam Tester › Email Spam Tester for cPanel & WHM

Email Spam Tester for cPanel & WHM

A plugin for hosting providers. Your customers find it in cPanel under Email, send a real email from one of their mailboxes and get a list of what to fix, with the exact DNS record or the cPanel button next to each finding.

Version 0.1.1, 30 September 2026. Download (94 KB), SHA-256 4909ff8402b3244711bc13bac96cfc22810ee33d48f80885f87e44809572cdd0. The installation steps are at the end of this page, and the same text is INSTALL.md in the archive.

Who it is for

Companies that run cPanel & WHM servers for other people. You install it once as root, and it shows up in cPanel » Email for the packages you pick. Until you switch it on in Feature Manager, customers see nothing new.

Without it, a customer who wants to know why their mail lands in spam has to find a tester, open a mail client and send an email by hand. With it, the test is a button next to their mailboxes, and the email really leaves from your server, with its IP, its HELO name, its DKIM signature and whatever relay it goes through.

What customers get in cPanel

Test

The customer picks a mailbox and sends either the standard test email (a short personal email in English, with a text and an HTML part) or their own message. For their own message they paste a subject, the HTML and an optional plain text version, and it goes out exactly as pasted. Exim sends it like any other email from that account. About a minute later the report is on the same page with all 42 checks: SPF, DKIM, DMARC and alignment, reverse DNS and HELO, TLS, IP blocklists, SpamAssassin and Rspamd, the sender requirements Gmail and Yahoo publish, and the content. There are two scores, a technical one out of 100 and the classic 0 to 10.

"Check the folder at email providers" is ticked by default. With it, one copy of the email also goes to each of our test mailboxes, about 30 emails at 14 providers, Gmail, Outlook, Yahoo, GMX and Proton among them. At Gmail these are public test mailboxes, where anyone can see the subject, the sender name and the folder. The table fills in over up to 30 minutes and shows Inbox, Spam or Promotions for each provider. If a provider refused the email outright, the table says so and quotes what its server answered, SMTP code included, from Exim's log on your server.

Below the scores comes What to fix. Where the domain's DNS is on your server, cPanel can fix DKIM, SPF and DMARC with a button; the plugin shows the record as it is now and as it will be, and asks first. Where DNS is hosted elsewhere, the customer gets the exact record to copy, with its name, type and value. Reverse DNS and the server's own A record are in a separate group addressed to the server administrator, values filled in. A written plan from Email Spam Tester follows a few minutes after the checks, and "Check again" sends a fresh email once the records are in.

History

Every test the account has sent, newest first, with the date, the mailbox, which email it was, both scores and the folder counts. A chart shows the score from test to test. Each test lists the checks that moved since the previous test of the same domain, so a DKIM check that went from fail to pass after a fix is right there in the row. Opening a test shows its report and, per provider, what the receiving servers answered. The last 200 tests of each account are kept on your server.

Constant monitoring

A test from a mailbox shows how mail from that mailbox goes out. The classic cPanel problem sits somewhere else. A WordPress site or a contact form sends with the envelope sender user@hostname, SPF alignment breaks, and no test from a mailbox will ever show it. Monitoring does.

The invisible copy that monitoring makes leaves your server by the same path as the email, from the same IP with the same HELO and the same DKIM signature. Exim makes it for each email a monitored domain sends and delivers it to a private address that belongs to the domain, so its report describes the real path, while the email itself reaches its recipients unchanged.

The Monitoring tab shows the domain's emails as a feed. Each one has the recipient's domain (never the address), where it came from and what failed. Sources are webmail, a mail client, PHP or WordPress, and scripts that call sendmail. Above the feed sit a one-line summary of the last 24 hours and the alerts: DKIM stopped passing, SPF or DMARC failing for one source, the sending IP on a blocklist, receiving servers refusing emails. Any email opens as a technical report of its checks (the email's headers are left out), and the customer can ask for an AI plan for it.

Monitoring stays off until the administrator allows it on the server. After that, each customer switches it on for their own domains.

What you get in WHM

WHM » Plugins » Email Spam Tester is one page.

Price

Free for now, monitoring included. There is no account to create on email-spam-tester.com and nothing to pay at the moment. If that ever changes, the changelog will say so first.

Data and privacy

What leaves your server:

A test report works as it does on the site: it stays at its link and anyone with the link can open it, subject and sender included. The email itself is deleted two days after it arrives. The Gmail part of the folder check is public too, as described above, so confidential emails are better tested without it.

Monitoring copies are real correspondence, and their reports are private. Only the plugin on your server can open them, using the installation key, and there is no public link. A copy is deleted two days after it arrives and its report after 90 days. The history and the monitoring feed stay on your server.

The privacy page has the full policy.

Questions hosting providers ask

Does it change DNS by itself?

No. A record changes only when the customer presses the button next to a finding and confirms the before and after, and only where your server hosts the domain's DNS. The SPF and DMARC buttons only create a record that is missing. An existing one is shown merged, for the customer to copy by hand, and a button never replaces it. The DKIM button can replace a record that does not match the server's key, but only if there is exactly one. Every change goes into the account's log and into one under /var/cpanel/email_spam_tester/ that only root can edit, together with the record DNS served before it.

My server relays outgoing mail through a smarthost. Does it still work?

It should, but I haven't tested it behind a smarthost yet. The test email leaves the way all mail from the account leaves, so the report shows the relay's IP and name, because that is what receivers see. Fixing its reverse DNS or getting it off a blocklist is then a job for whoever runs the relay. One thing gets lost. The reasons a provider gives for refusing an email come from Exim's log on your server, and with a relay that log only has the relay's answer. An email the relay accepted and a provider refused later may show up as "Not received". Monitoring copies go through the relay as well.

Does monitoring affect deliverability?

The customer's email goes out as before, unchanged, and its recipients see nothing, since the copy is a separate delivery to our address. What it does touch is the hourly sending limit. Each copy counts once against the domain's "max emails per hour", so a domain close to its limit hits it sooner, by at most 20 emails an hour with the default setting. Past that number of copies in an hour, emails go out without one.

Does the folder check count against the hourly limit too?

Yes, it sends about 30 emails. Before it starts, the plugin checks how many emails the domain has left this hour and tells the customer if that is not enough.

What has been tested live?

cPanel & WHM 134 or newer is supported; so far I have tested it live on 138 (11.138) on Ubuntu 24.04. That covers the install and an upgrade, registration, the feature switch, tests with and without the folder check, the history, and monitoring of emails from all four sources. Not tested live yet are the other operating systems, CloudLinux with CageFS, the DKIM, SPF and DMARC buttons (the test server's DNS is hosted elsewhere), a server that relays through a smarthost, and switching monitoring off for the whole server, which has only had a dry run. If you run the plugin on one of those, I'd like to hear how it went.

Install, step by step

This guide assumes you have root on the server and have not used WHM plugins before. Every command below is meant to be copied and pasted as it is.

1. What you need

You can check both connections before installing. The first command should print a line that starts with 220, the second should print 200:

timeout 10 bash -c 'exec 3<>/dev/tcp/t.email-spam-tester.com/25 && head -1 <&3'
curl -s -o /dev/null -w '%{http_code}\n' https://email-spam-tester.com/health

2. Install

Log in over SSH as root and run these commands one by one.

Go to root's home directory, where the plugin will live:

cd /root

Download the archive and its checksum. Nothing is printed when it works:

curl -fsSLO https://email-spam-tester.com/cpanel/latest.tar.gz
curl -fsSLO https://email-spam-tester.com/cpanel/latest.tar.gz.sha256

Check that the download is intact. You should see latest.tar.gz: OK. If you see FAILED, download again and do not continue:

sha256sum -c latest.tar.gz.sha256

Unpack it into /root/email-spam-tester-cpanel. Again nothing is printed:

mkdir -p email-spam-tester-cpanel
tar -xzf latest.tar.gz -C email-spam-tester-cpanel --strip-components=1

Run the installer. It checks every file first, then copies them into place:

cd /root/email-spam-tester-cpanel && ./install.sh

You should see Checking Perl syntax…, Root module…, cPanel pages…, a few lines from cPanel's own plugin installer, Switching the feature off in all feature lists… and WHM page…. The last lines should be:

Installed. Next: WHM » Plugins » Email Spam Tester » Register this server.
Customers do not see it yet: turn on email_spam_tester in WHM » Feature Manager
for the feature lists (packages) that should have it.

Keep the /root/email-spam-tester-cpanel directory. Upgrades and uninstall.sh run from it.

3. Register the server in WHM

  1. Log in to WHM as root.
  2. In the left menu, open Plugins and click Email Spam Tester.
  3. The Registration box says "Not registered". The admin email field below it is optional.
  4. Click Register this server.

A green line appears at the top, "Registered. Installation #…", and the box now shows Status: Registered, with the installation number and the start of the key. Registration sends the server's hostname, the cPanel version, the plugin version, the number of accounts and the email if you gave one. The key is kept in /var/cpanel/email_spam_tester/config.json, readable by root only.

On the same page you can change the daily limits: 20 tests per account and 500 per server by default.

4. Turn it on for customers

After the install nobody sees the plugin. You choose which packages get it.

  1. Find out which feature list your packages use: WHM » Packages » Edit a Package, pick a package, and look at the Feature List field. On many servers it is default.
  2. Open WHM » Packages » Feature Manager.
  3. Under Manage feature list, select that list and click Edit.
  4. Find Email Spam Tester in the list (your browser's Find helps if the list is long), tick its checkbox and click Save.
  5. Repeat for every feature list that should have it.

Customers on those packages now see Email Spam Tester in cPanel, in the Email section. Remember to tick it in feature lists you create later as well.

5. Send the first test as a customer

Log in to cPanel as one of those customers. From WHM you can use Account Information » List Accounts and the cPanel icon next to the account.

  1. Open Email » Email Spam Tester. The page has three tabs: Test, History and Monitoring.
  2. On the Test tab, pick a mailbox. If the account has none, create one in Email » Email Accounts first.
  3. Leave Standard test email selected, and leave Check the folder at email providers ticked.
  4. Click Send test.

The page shows what it is doing: checking DNS records, sending, waiting for the email to arrive. About a minute later the report appears. It has two scores, a technical one out of 100 and the classic 0 to 10, and under them What to fix. That list gives a button where cPanel can fix a record on this server, the exact record to copy where DNS is hosted elsewhere, and reverse DNS values for you as the server administrator. Below come all the checks. Where the email landed fills in over the next 30 minutes with Inbox, Spam or Promotions for each mail provider, and the provider's answer when it refused the email. A written plan follows a few minutes after the checks.

The folder check sends about 30 emails. If the domain's hourly sending limit does not have room for them, the page says so before sending anything.

6. Constant monitoring (optional)

With monitoring on for a domain, Exim sends an invisible copy of every email the domain sends to a private address at Email Spam Tester, and the customer sees a technical report of each email. Recipients see nothing. Each copy counts once against the domain's hourly sending limit, at most 20 copies an hour by default.

  1. In WHM » Plugins » Email Spam Tester, find the Constant monitoring box and click Allow constant monitoring on this server. The plugin checks your Exim configuration, adds its rule, rebuilds and restarts Exim, and puts everything back if any step fails. When it works you see "Constant monitoring is allowed on this server: the Exim rule is in, Exim was rebuilt and restarted." and the box shows the rule as Active.
  2. The customer opens the Monitoring tab in cPanel, clicks Turn on next to a domain and confirms. Emails sent after that appear in the tab within a minute or two.

To stop it for the whole server, click Disable monitoring on the whole server in the same box.

7. Upgrade

Download and unpack the new version over the old one, then run the installer again:

cd /root
curl -fsSLO https://email-spam-tester.com/cpanel/latest.tar.gz
curl -fsSLO https://email-spam-tester.com/cpanel/latest.tar.gz.sha256
sha256sum -c latest.tar.gz.sha256
tar -xzf latest.tar.gz -C email-spam-tester-cpanel --strip-components=1
cd /root/email-spam-tester-cpanel && ./install.sh

It should end with "Updated. The registration, limits and feature settings are unchanged." If monitoring is allowed, the installer also brings the Exim rule up to date.

8. Uninstall

cd /root/email-spam-tester-cpanel && ./uninstall.sh

This takes the monitoring rule out of Exim, switches monitoring off for every domain, and removes the plugin from cPanel and WHM. It ends with "Removed. The key is kept in /var/cpanel/email_spam_tester (use --purge to delete it)." Run ./uninstall.sh --purge instead to delete the key as well.

DNS records are never touched, including the ones customers created with the plugin's buttons.

9. If something went wrong

Customers do not see the icon. The feature is off in their package's feature list. Go through step 4 again, and check which feature list their package really uses.

The page says "The server administrator has not activated Email Spam Tester in WHM yet". The server is not registered. Do step 3.

Registration fails. The red message at the top of the WHM page says why. Most often the server cannot reach email-spam-tester.com over HTTPS: run the curl check from step 1, which has to print 200, and look at the firewall rules for outgoing traffic.

The test says the message has not arrived in 3 minutes. The email is stuck in the queue or was refused. Run the port 25 check from step 1. If it prints nothing or times out, your provider blocks outgoing port 25: ask them to open it, or send mail through a relay. To see what Exim did with the email:

grep 't.email-spam-tester.com' /var/log/exim_mainlog | tail -5

The customer can also look in Email » Track Delivery for the mailbox.

Pages on cpanel.<domain> sometimes fail with a 502 error. This is Apache's proxy for cPanel's service subdomains, and it hits every cPanel page, not only this plugin. The direct address https://<domain>:2083 is not affected. To fix it, open WHM » Service Configuration » Apache Configuration » Include Editor, choose Pre VirtualHost Include for all versions, add these lines and save:

<IfModule setenvif_module>
    SetEnvIfNoCase Host "^(cpanel|webmail|whm|webdisk|cpcalendars|cpcontacts)\." proxy-nokeepalive=1 proxy-initial-not-pooled=1
</IfModule>

Then apply it:

apachectl configtest && /scripts/rebuildhttpdconf && /scripts/restartsrv_httpd

10. Support

Write to hi@email-spam-tester.com. Include the output of ./install.sh if the install failed, or the report link if a test looks wrong. More about the plugin is at https://email-spam-tester.com/cpanel-integration/.