A user reports that a message they sent an hour ago never arrived, and the queue listing shows the message is gone. Where should you look next to find out what the MTA did with it?

LPIC-1 Exam 102-500, objective 108. Essential system services medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Correct The system log written for the mail syslog facility, typically /var/log/mail.log or /var/log/maillog

Correct. Every MTA logs through the mail facility, recording one entry per message with its queue id, sender, recipient and the final status such as sent, deferred or bounced. Following the queue id links all entries for one message.

Not correct /var/spool/mqueue

Wrong for a message that has left the queue. The queue directory only holds messages still awaiting delivery; once the MTA finishes with a message its queue file is removed.

Not correct /etc/aliases.db

Wrong. That is the compiled alias lookup table produced from /etc/aliases. It records how addresses are rewritten, not what happened to any particular message.

Not correct The sender's ~/dead.letter

Wrong. That file only appears when the mail user agent could not submit a message at all, so it says nothing about a message that the MTA accepted and processed.

Why

MTAs report through syslog using the mail facility, and the syslog configuration decides the file name, which is why Debian-family systems show /var/log/mail.log while Red Hat-family systems show /var/log/maillog. On systemd hosts the same records are also readable with journalctl. The queue id printed in a queue listing is the key that ties together the accept, relay and final delivery lines for a single message.

Where this comes from

Cited
manual page rsyslog.conf(5)

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 108 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Essential system services

Practise LPIC-1 Exam 102-500