Creating a proper Reverse DNS for two email servers

Posted on 2006-06-01
Last Modified: 2010-03-19

I have one front end server and one backend server.

My A Record to is pointing to IP address = xx.xx.28 . This is the Frontend Server.
I asked my DNS provider to create a PTR record for the reverse DNS. The did it.

However, I receive my emails thru the IP 28 in the FrontEnd server and relay Everything to the BackEnd server. I Send all my emails using the BackEnd server, which is in IP xx.xx.30.

After a couple of weeks, I started receiving errors because the IP "30" did not have a PTR record. I asked again the DNS provider to create a PTR record for IP 30 and they did.

NOW, I am receiving the following error:

 Relaying denied. IP name possibly forged

Do I have to create an A record pointing to my BackEnd Server ?  I don't want to open the Firewall for my BackEnd server to receive emails. It is a security risk I am not willing to take.

Question by:rgomez101

    Accepted Solution

    Creating an A record does not equal opening your firewall.
    Creating an A record allows the mail servers to verify fwd and rev DNS.
    This is just a simple method to somewhat check the veracity of the email.

    If the denial is from external mail servers it sounds as though you will need the A record for the BE server.

    Author Comment

    Thank you. So

    For every mail server we need an A record and a PTR record ?

    What if I am using 3 or 4 servers for the same domain ?  4 A Records and 4 PTR records ?

    LVL 26

    Assisted Solution

    "IP name possibly forged"

    You'll get this when the PTR record and the A record don't match. Meaning you do a reverse lookup on the ip and get the name...then do a forward lookup on that name and you should get the same ip you started with. If not some email software will bark at you saying there was a forgery.

    Just make sure you have matching reverse and forward (PTR and A) records for all your mail server ip addresses.
    LVL 26

    Expert Comment

    "What if I am using 3 or 4 servers for the same domain ?  4 A Records and 4 PTR records ?"

    The names of the mail servers are completely separate from the domain name associated with the email it is sending out.

    You can have 50 email servers serving the "" domain name:

    Each server will have its own name and each need and A and PTR record.

    Author Comment

    Thank you very much.

    This really answer my question. For the readers, you can have many A records and many PTR records for the same the Domain, but the first one will take priority 1 and so on.


    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Free Trending Threat Insights Every Day

    Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

    Some time ago I was asked to set up a web portal PC to put at our entrance. When customers arrive, they could see a webpage 'promoting' our company. So I tried to set up a windows 7 PC as a kiosk PC.......... I will spare you all the annoyances I…
    Occasionally you run into the website or two that will not resolve properly using your own DNS servers.  Some people simply set up global forwarders for their DNS server.  I don’t recommend doing this because it can cause problems resolving addresse…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
    Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

    759 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    10 Experts available now in Live!

    Get 1:1 Help Now