Open DNS Server Q

We have a number of W2003 servers and host our own DNS.  I went to and ran a report on it.  It indicated a FAIL message:

ERROR:  One or more of your name servers reports that is is an open DNS server.  Blah, blah, blah.

To corrent this problem, it instructed me to go into the DNS server manager and check the advanced option "Disable Recursion" so I did.

The entire Exchange outbound queue stalled saying it couldn't resolve DNS for any of the domains it was trying to send to.  I'm confused by this.  The exchange server is also a secondary DNS server for the domain.  The AD master roles and primary DNS are held by a server inside the firewall.  The server's TCP/IP properties specify the master and another secondary (not itself) for its DNS servers.

Why would this Exchange server not be able to resolve DNS queries when recursion is disabled and why is this a good idea?

Who is Participating?
> "why would DNS reports tell me to disable recursion in the first place"

It's a best practice for smaller networks and/or corporate networks to streamline/minimize network traffic - your ISP's DNS servers are there for a reason.
Is your DNS server configured with a forwarder?  If not, after you disabled recursion you would no longer be able to resolve any DNS records other than those hosted on your local server.  DNS requires either recursion or a forwarder to be able to resolve non-local queries - a forwarder is more efficient if you have one available, as the DNS server will simply send a query to the forwarder for anything that it can't resolve locally.
tomrwilsonAuthor Commented:
Thanks for the reply.

Yes, I'm using two forwarder addresses supplied by our ISP.  All that makes sense, I'm just curious, why would DNS reports tell me to disable recursion in the first place?  Is it possible to emply recursion without the DNS server being considered "open"?
tomrwilsonAuthor Commented:
Oh crap, my forwarders are unreachable.  That explains it.  I'll be back.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.