Exchange and DNS

Posted on 2008-10-08
Medium Priority
Last Modified: 2012-05-05
Do I have to enter an external DNS server for exchange to use or should I us internal DNS?
Question by:Brent400
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2

Expert Comment

ID: 22674496
Internal.  Your exchange server needs to be able to see your Domain Controller.

Expert Comment

ID: 22674504
Sorry, to clarify that.  Your internal DNS server should have a forwarder set to your next-hop DNS server (ISP usually).  This is so all internal queries go to your Domain Controller and respond, and ones destined for external sites will be passed along to the external DNS server.
LVL 33

Expert Comment

ID: 22676402
Never, have your Exchange or as a matter of fact any one your internal server pointing to external DNS server - ONLY and ONLY your DNS should have forwarders set pointing to external DNS server.

Reason, your internal DNS might not have all the information in the world about DNS servers - this job gets done when you have external DNS set to respond to your queries - this is done by setting the ip address on the forwarders list.

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.


Author Comment

ID: 22681023
That's what I thought and that's the way it is configured.
I guess the problem is more on the DNS server.

My forwarders are set to and These I believe are UU.net servers. Should I be setting them to somthing else or add a few more servers? Add my ISP's?

Author Comment

ID: 22681185
The problem I'm really try to figure out is why I have a few domains that I have trouble recieving email from.
I tested an address using Smtpdiag and DNS was not resolving. I tried the Smtpdiag with the -d option and
I connected. The I tried the standard Smtpdiag with email address and /v option that failed before and it worked fine.

Did the DNS server cache the new IP from the -d option?

LVL 33

Accepted Solution

Exchange_Geek earned 750 total points
ID: 22681334
Look, it is always best to have the ISP DNS server listed in the forwarders list.

Also, if you are fighting the problem why few domains do not get emails from your server / delay in receiving emails - i would recommend change the SMTP Connector scope to use smart host and NOT DNS.

When you are entering smart host entry specify the ip address of your ISP in [ ] brackets. Simple.

Expert Comment

ID: 22683224
That should only be an issue if you were trying to send to them yes?  If you were having issues receiving from them would mean that either their SMTP server was having issues connecting to your Exchange server on port 25, or if DNS is an issue, if you run an Anti-Spam filter that has Sender Address Verification running if would not be able to resolve the senders email address.

For some testing:
On your Exchange server, open command prompt
open nslookup
type: set type=mx
type: domain.com (obviously the domain you are having issues with)
check the result (google.com      MX preference = 10, mail exchanger = smtp1.google.com)
type: exit
type: telnet <nslookup result> 25
eg: telnet smtp1.google.com 25

See if the server responds.  If this all works, then outbound SMTP shouldn't be a problem.  If it doesn't, post the response of your NSLOOKUP.


Featured Post

Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Read this checklist to learn more about the 15 things you should never include in an email signature.
After hours on line I found a solution which pointed to the inherited Active Directory permissions . You have to give/allow permissions to the "Exchange trusted subsystem" for the user in the Active Directory...
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question