Prompt
How do I search email logs to debug delivery issues?
Latest observation
Oct 4, 2026
OpenAI APIWeb search: off
To debug email delivery issues, you usually search mail logs for the message as it moves through your system. The exact commands depend on your mail server, but the general approach is the same.
1) Identify key details from the message
Try to get any of these:
- Sender address
- Recipient address
- Timestamp
- Subject
- Message ID or queue ID
- Sending IP if applicable
The queue ID / message ID is the most useful.
2) Search the logs
On Linux mail servers
Common log locations:
/var/log/mail.log/var/log/maillog/var/log/exim/mainlog/var/log/maillog*or rotated logs likemail.log.1
Useful commands
Search by recipient or sender
grep "user@example.com" /var/log/mail.log
Search by queue ID
If you have a queue ID like A1B2C3D4E5:
grep "A1B2C3D4E5" /var/log/mail.log
Search across rotated/compressed logs
zgrep "user@example.com" /var/log/mail.log*
Follow new log entries live
tail -f /var/log/mail.log
3) What to look for
Typical log entries show:
- Accepted message: received by the mail server
- Relay/route attempts: where it tried to send it
- Delivery success: accepted by destination server
- Deferred: temporary failure, will retry
- Bounced/rejected: permanent failure
Common error clues:
deferred: retry laterhost not found: DNS problemconnection timed out: network/remote server issuerejected: policy/spam/authentication issuerelay access denied: server is not allowed to forwardspf,dkim,dmarc: authentication-related failures
4) If using Postfix
You can also inspect the queue:
mailq
postqueue -p
And search logs for a queue ID:
grep "status=" /var/log/mail.log | grep "queued_id"
Example delivery line:
status=sent (250 2.0.0 Ok: queued as ...)
Example failure:
status=deferred (host mail.example.com[1.2.3.4] said: 451 ... )
5) If using Exim
Useful commands:
exim -bp
Then search:
grep "message-id-or-queue-id" /var/log/exim/mainlog
6) If using systemd journal
Some systems log to journald instead of files:
journalctl -u postfix
journalctl -u exim4
journalctl -u dovecot
Follow live:
journalctl -u postfix -f
7) Practical debugging workflow
- Find the message in logs using sender, recipient, or queue ID.
- Trace:
- received
- queued
- attempted delivery
- success/failure
- Note the exact SMTP response code and error text.
- Check related systems:
- DNS/MX records
- spam filtering
- SPF/DKIM/DMARC
- outbound IP reputation
- recipient server rejects
If you tell me what mail system you’re using (Postfix, Exim, Exchange, Gmail/Workspace, etc.) and what detail you have from the message, I can give you exact search commands.