Solved

Reverse DNS and smart host

Posted on 2009-04-08
8
520 Views
Last Modified: 2012-05-06
If I change Exchange from sending mail directly to using a smart host (our ISP), does that have an impact on the PTR record for Reverse DNS checks ? Would it need to be changed ? Presently, we have a PTR record to resolves to mail.mydomain.com, which is our public ip address where traffic on port 25 is forwarded to our SBS2003 Exchange server.  

I'm trying to understand how a receiving server does it's Reverse DNS check. Is it done on the ip/name of the host server (our ISP) that would send the email for us, or does it do it based on the sender's domain name.

Thanks

0
Comment
Question by:ndidomenico
  • 3
  • 3
  • 2
8 Comments
 
LVL 49

Assisted Solution

by:Akhater
Akhater earned 100 total points
ID: 24099295
The PTR check is done on the IP of the sending server so if you are using smart host it will be on your ISP's email not yours
0
 
LVL 58

Accepted Solution

by:
tigermatt earned 400 total points
ID: 24099361

When an email server opens an SMTP session to another mail server (in other words, your server connecting to the recipient's), it will provide a HELO or EHLO header which will generally be followed by the SMTP banner configured on the SMTP Virtual Server.

It is that SMTP banner which has the PTR check performed on it, to verify the IP the server initiating the connection with has the PTR matching the FQDN provided in the HELO/EHLO.

For sending mail via the ISP's Smart Host, the server will still send a banner like this, but the ISP doesn't care about your banner and will ignore it (they will accept your message once you have proved you can use their SMTP server, usually by means of username/password authentication). When the ISP relays the message and passes it on to be delivered, the ISP's server will provide a banner and it is THAT banner which has the PTR check performed on it.

-Matt
0
 

Author Comment

by:ndidomenico
ID: 24099689
So if I'm using my ISP's smart host for sending emails, it doesn't matter whether or not we have a properly set PTR record for our domain name for Revers DNS lookup ? It would never be checked by the receiving server, since it will only do a RDNS check based on my ISP's smart host FQDN?
0
Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 49

Expert Comment

by:Akhater
ID: 24099704
exactly
0
 
LVL 58

Expert Comment

by:tigermatt
ID: 24099729

Correct. The ISP will ignore the PTR record because you authenticate to their server in order to relay via other means (username/password).

-Matt
0
 

Author Comment

by:ndidomenico
ID: 24099841
Ok. I think it's all clear now. Last question: how can I verify what is the HELO header and also the SMTP banner that is given out by Exchange to receiving servers ?

A Telnet session on port 25 of my Exchange server returns at the beginning:
"220 mail.mydomain.com Microsoft ESMTP MAIL Service, Version: 6.0.3790.3959 ready at  Wed, 8 Apr 2009 13:26:29 -0400"
Is this the SMTP banner ? And the name following the 220 code is what is used for the RDNS check ?

Then if I enter HELO and press enter, I get:
250 mail.mydomain.com Hello [10.0.1.100]
Is this the HELO header ?
0
 
LVL 58

Expert Comment

by:tigermatt
ID: 24100208
The SMTP banner is the part after the '220' when you initiate a telnet session to the server. Whether it is HELO/EHLO doesn't have anything to do with the header which is sent; EHLO and HELO are just two different SMTP standards, with EHLO having wider support for more features than HELO, which is very basic for basic email transfer. The SMTP banner sent for each is the same.

-Matt
0
 

Author Closing Comment

by:ndidomenico
ID: 31568117
Thanks for your help.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Export Exchange Cert 5 39
exchange2007 4 20
How to log the IP address of a failed login attempt 6 30
Exchange 2010 Room mailboxes 5 32
Marketers need statistics and metrics like everybody else needs oxygen. In this article we explain how to enable marketing campaign statistics for Microsoft Exchange mail.
Find out what you should include to make the best professional email signature for your organization.
In this video we show how to create a User Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Mailb…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now