
Email rejection logs that mention Bad HELO, Invalid HELO, or HELO name does not resolve usually point to one issue. Your server introduces itself with the wrong name.
This SMTP HELO/EHLO hostname fix tutorial shows how to set a proper mail hostname on a VPS, confirm it resolves in DNS, and verify the SMTP handshake end-to-end.
You’re aiming for a stable FQDN (for example, mail.example.com) with working forward DNS that matches your server identity.
Avoid localhost and generic provider hostnames. Many receivers treat those as a red flag.
What you’re fixing (and how to confirm it’s the HELO/EHLO problem)
Receiving mail servers may reject or downgrade mail when the HELO/EHLO string looks wrong. These are the usual triggers:
- HELO says
localhostor a bare hostname with no domain. - HELO is an IP address (some servers reject that outright).
- HELO name has no A/AAAA record (forward DNS missing).
- HELO name resolves, but points elsewhere (wrong record, wrong IP, or wrong interface).
Pull a real bounce and read the SMTP reason line-by-line.
On Postfix, you’ll typically find it in:
sudo tail -n 200 /var/log/mail.log
sudo grep -iE 'helo|ehlo|reject|bounce' /var/log/mail.log | tail -n 50
On Exim (common with cPanel), check:
sudo tail -n 200 /var/log/exim_mainlog
sudo grep -iE 'helo|ehlo|reject' /var/log/exim_mainlog | tail -n 50
If the message includes HELO command rejected, invalid HELO, HELO name does not resolve, or a HELO-related policy violation, you’re in the right place.
Prerequisites: choose a mail hostname that won’t cause trouble
Use a dedicated hostname for SMTP, ideally under the same domain you send from. Typical choices:
mail.example.com(recommended)smtp.example.com(fine if that’s your convention)
A few rules prevent avoidable back-and-forth:
- Use an FQDN (it must contain at least one dot).
- Only use a name you control in DNS.
- Point it to the public IPv4 of your VPS (and IPv6 if you actually send over v6).
If you’re starting fresh and want full control over hostname, rDNS, and firewall rules, a HostMyCode VPS is a straightforward base to build on.
Step 1 — Set the system hostname correctly (Ubuntu/Debian and RHEL-family)
Most MTAs take their default identity from the OS hostname. Set the hostname to the FQDN you picked.
sudo hostnamectl set-hostname mail.example.com
hostnamectl
hostname -f
Expected output: hostname -f returns mail.example.com.
If it returns something else (or errors), correct /etc/hosts next.
Fix /etc/hosts so hostname -f behaves
Edit /etc/hosts and map your FQDN to a loopback entry. Do not map it to the public IP.
sudo nano /etc/hosts
A safe, widely used layout looks like this:
127.0.0.1 localhost
127.0.1.1 mail.example.com mail
# If you have IPv6 enabled
::1 localhost ip6-localhost ip6-loopback
This layout avoids edge cases where services bind or identify themselves incorrectly because of a bad hosts file.
Step 2 — Create forward DNS for the mail hostname (A/AAAA)
“HELO name does not resolve” usually means the receiver looked up your HELO name and got no answer.
- Create an A record for
mail.example.com→ your VPS IPv4. - If you use IPv6 for mail, create an AAAA record as well.
If DNS is managed outside your registrar, confirm you’re editing the authoritative zone.
Don’t edit a parked or duplicated copy.
If you want everything under one roof, you can manage registrations and DNS via HostMyCode Domains.
Verify DNS from the server
sudo apt-get update && sudo apt-get install -y dnsutils || true
dig +short mail.example.com A
dig +short mail.example.com AAAA
Expected: both commands return your server’s public IP(s).
If they return nothing, stop and fix DNS first. Many policy checks will fail until this resolves cleanly.
Step 3 — Confirm what your server is actually saying in EHLO
Don’t guess. Connect to your SMTP service and read the banner and EHLO response.
For port 25 (server-to-server):
nc -v 127.0.0.1 25
You should get a banner similar to:
220 mail.example.com ESMTP Postfix
Then enter:
EHLO test
Expected: the response includes mail.example.com and a normal list of extensions.
For submission ports with TLS (closer to how clients send), use OpenSSL:
openssl s_client -starttls smtp -connect 127.0.0.1:587 -crlf -quiet
Then run:
EHLO test
Step 4 — Fix HELO/EHLO identity in Postfix (Ubuntu/Debian/RHEL)
In Postfix, myhostname is the core identity value. Set it explicitly instead of relying on defaults.
sudo postconf -e 'myhostname = mail.example.com'
sudo postconf -e 'mydomain = example.com'
Next, choose what you want the SMTP banner to show.
The least surprising option is to keep it consistent with myhostname:
sudo postconf -e 'smtpd_banner = $myhostname ESMTP'
Reload Postfix, then confirm the active values:
sudo systemctl reload postfix
sudo postconf myhostname mydomain smtpd_banner | sed 's/^/POSTFIX: /'
Optional: enforce a clean HELO name for outbound relaying
If you relay through a smart host (or apps send through localhost), Postfix still uses the same hostname in most setups.
If you must force the EHLO name specifically when Postfix acts as an SMTP client, set:
sudo postconf -e 'smtp_helo_name = mail.example.com'
sudo systemctl reload postfix
Skip smtp_helo_name unless you have a specific requirement.
For most VPS mail setups, setting myhostname is enough.
Step 5 — Fix HELO/EHLO identity in Exim (cPanel/WHM and stand-alone)
On cPanel servers, WHM manages Exim configuration. Direct edits usually get overwritten.
On cPanel/WHM:
- In WHM, go to Networking Setup → Change Hostname, set
mail.example.com. - Then go to Service Configuration → Exim Configuration Manager.
- Confirm the “Primary Hostname” matches your chosen FQDN.
If you’re hardening a WHM box at the same time, pair deliverability work with panel security.
This guide on enabling OWASP CRS in WHM is a solid next step.
Stand-alone Exim (non-cPanel) depends on packaging.
On Debian/Ubuntu, a common file is /etc/exim4/update-exim4.conf.conf. Set:
dc_other_hostnames='mail.example.com'
Then rebuild and reload:
sudo update-exim4.conf
sudo systemctl reload exim4
If you’re unsure which Exim build you’re running, check:
exim -bV | head
Step 6 — Make sure HELO resolves to the correct IP (and not a private address)
Some receivers verify that your HELO name resolves to the same IP you send from.
It’s strict, but common in enterprise filtering.
From the VPS, confirm the DNS answer and your public IP match:
dig +short mail.example.com A
curl -4s https://ifconfig.me ; echo
If these don’t match, fix the A record or correct your NAT/public IP mapping.
On multi-IP servers, you may also need to ensure your MTA uses the right source address for outbound SMTP.
Step 7 — Test a full outbound SMTP conversation (realistic verification)
The fastest “real” test is sending to a mailbox you control on another provider and reviewing the headers.
From the VPS, swaks makes this easy.
sudo apt-get update && sudo apt-get install -y swaks || true
swaks --to you@external-domain.com --from test@example.com --server 127.0.0.1 \
--ehlo mail.example.com
If you send via submission with auth (587), use:
swaks --to you@external-domain.com --from test@example.com --server 127.0.0.1:587 \
--auth LOGIN --auth-user 'user@example.com' --auth-password 'YOURPASS' \
--tls --ehlo mail.example.com
In the received message, inspect headers for:
- Received: lines showing
mail.example.comas the sending host - Return-Path behaving as expected
Common “Bad HELO” pitfalls (quick fixes)
- Using the root domain as HELO (
example.com) while your SMTP host ismail.example.com. Use the mail host FQDN. - AAAA record exists but IPv6 isn’t actually routed. If receivers try IPv6 and it fails, you may get penalized. Either fix IPv6 routing/firewall or remove AAAA until it’s ready.
- Cloud security groups blocking outbound 25. A perfect HELO doesn’t matter if mail can’t leave. Test with
nc -vz gmail-smtp-in.l.google.com 25(or another host that accepts port 25). - Misleading hostname on shared hosting. Shared hosting often limits control over HELO/banners. If deliverability is a priority, run mail on a VPS you control.
Related checks that usually matter alongside HELO
HELO is only one part of sender identity. These checks often show up in the same incident:
- SPF/DKIM/DMARC alignment: if you haven’t set them, start there before chasing edge cases. Use this email deliverability setup guide for a clean baseline.
- Queue health: a stuck queue can mimic deliverability problems. Follow this mail queue troubleshooting tutorial to clear backlogs safely.
- Reverse DNS (rDNS): it’s not the same as HELO, but many receivers check both. If rejections continue after the HELO fix, PTR/rDNS is a common next target.
Operational checklist: lock the fix in so it doesn’t regress
- Document the chosen mail hostname (
mail.example.com) in your runbook. - Keep an A record (and AAAA only if you truly support IPv6 SMTP).
- After OS upgrades or control panel updates, re-check:
hostname -f, SMTP banner, and EHLO response. - Monitor mail logs for
HELOrejections weekly.
If you want visibility without building a full SIEM, daily summaries help a lot.
This Logwatch setup tutorial shows a lightweight approach.
Summary: what “good” looks like after this tutorial
After you’re done, your server should:
- Present
mail.example.com(or your chosen FQDN) in the SMTP banner and EHLO response - Have working forward DNS for that hostname
- Avoid
localhost, private names, and IP-based HELO strings - Stop generating “Bad HELO” bounces from strict receivers
For production mail, consistency wins.
You’ll get the most predictable results on infrastructure where you control hostname, DNS, and outbound rules—exactly what managed VPS hosting is designed for.
If your mail runs on a server you can’t fully control, HELO and deliverability fixes turn into trial and error. A VPS lets you set the hostname, DNS, and security policies once—and keep them stable.
Start with a HostMyCode VPS, or hand it off with managed VPS hosting if you want a tighter operational safety net.
FAQ
Do I need reverse DNS (PTR) for HELO to pass?
Not always. HELO checks usually focus on forward DNS for the name you present. Many receivers validate rDNS separately, so you may need both for reliable acceptance.
Should my HELO name match my From address domain?
It doesn’t have to match exactly. What matters is a stable FQDN you control and can keep consistent. Alignment is more important for SPF/DKIM/DMARC than for HELO itself.
Why does my HELO revert after reboot or updates?
Most of the time, either the OS hostname is wrong (hostname -f) or a control panel overwrites MTA settings.
Fix the hostname at the OS level, then use the supported panel settings (WHM for cPanel).
What if my HELO resolves, but some servers still reject it?
Confirm the A record points to the same public IP you send from. Then verify SPF/DKIM/DMARC.
If mail is backing up, also check your queue and confirm outbound port 25 connectivity.