Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Reverse DNS and smart host

Posted on 2009-04-08
8
Medium Priority
?
570 Views
Last Modified: 2012-05-06
If I change Exchange from sending mail directly to using a smart host (our ISP), does that have an impact on the PTR record for Reverse DNS checks ? Would it need to be changed ? Presently, we have a PTR record to resolves to mail.mydomain.com, which is our public ip address where traffic on port 25 is forwarded to our SBS2003 Exchange server.  

I'm trying to understand how a receiving server does it's Reverse DNS check. Is it done on the ip/name of the host server (our ISP) that would send the email for us, or does it do it based on the sender's domain name.

Thanks

0
Comment
Question by:ndidomenico
  • 3
  • 3
  • 2
8 Comments
 
LVL 49

Assisted Solution

by:Akhater
Akhater earned 400 total points
ID: 24099295
The PTR check is done on the IP of the sending server so if you are using smart host it will be on your ISP's email not yours
0
 
LVL 58

Accepted Solution

by:
tigermatt earned 1600 total points
ID: 24099361

When an email server opens an SMTP session to another mail server (in other words, your server connecting to the recipient's), it will provide a HELO or EHLO header which will generally be followed by the SMTP banner configured on the SMTP Virtual Server.

It is that SMTP banner which has the PTR check performed on it, to verify the IP the server initiating the connection with has the PTR matching the FQDN provided in the HELO/EHLO.

For sending mail via the ISP's Smart Host, the server will still send a banner like this, but the ISP doesn't care about your banner and will ignore it (they will accept your message once you have proved you can use their SMTP server, usually by means of username/password authentication). When the ISP relays the message and passes it on to be delivered, the ISP's server will provide a banner and it is THAT banner which has the PTR check performed on it.

-Matt
0
 

Author Comment

by:ndidomenico
ID: 24099689
So if I'm using my ISP's smart host for sending emails, it doesn't matter whether or not we have a properly set PTR record for our domain name for Revers DNS lookup ? It would never be checked by the receiving server, since it will only do a RDNS check based on my ISP's smart host FQDN?
0
Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

 
LVL 49

Expert Comment

by:Akhater
ID: 24099704
exactly
0
 
LVL 58

Expert Comment

by:tigermatt
ID: 24099729

Correct. The ISP will ignore the PTR record because you authenticate to their server in order to relay via other means (username/password).

-Matt
0
 

Author Comment

by:ndidomenico
ID: 24099841
Ok. I think it's all clear now. Last question: how can I verify what is the HELO header and also the SMTP banner that is given out by Exchange to receiving servers ?

A Telnet session on port 25 of my Exchange server returns at the beginning:
"220 mail.mydomain.com Microsoft ESMTP MAIL Service, Version: 6.0.3790.3959 ready at  Wed, 8 Apr 2009 13:26:29 -0400"
Is this the SMTP banner ? And the name following the 220 code is what is used for the RDNS check ?

Then if I enter HELO and press enter, I get:
250 mail.mydomain.com Hello [10.0.1.100]
Is this the HELO header ?
0
 
LVL 58

Expert Comment

by:tigermatt
ID: 24100208
The SMTP banner is the part after the '220' when you initiate a telnet session to the server. Whether it is HELO/EHLO doesn't have anything to do with the header which is sent; EHLO and HELO are just two different SMTP standards, with EHLO having wider support for more features than HELO, which is very basic for basic email transfer. The SMTP banner sent for each is the same.

-Matt
0
 

Author Closing Comment

by:ndidomenico
ID: 31568117
Thanks for your help.
0

Featured Post

NFR key for Veeam Agent for Linux

Veeam is happy to provide a free NFR license for one year.  It allows for the non‑production use and valid for five workstations and two servers. Veeam Agent for Linux is a simple backup tool for your Linux installations, both on‑premises and in the public cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Are you looking for the options available for exporting EDB files to PST? You may be confused as they are different in different Exchange versions. Here, I will discuss some options available.
How to effectively resolve the number one email related issue received by helpdesks.
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
This video discusses moving either the default database or any database to a new volume.
Suggested Courses

824 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question