Solved

Reverse DNS and smart host

Posted on 2009-04-08
8
528 Views
Last Modified: 2012-05-06
If I change Exchange from sending mail directly to using a smart host (our ISP), does that have an impact on the PTR record for Reverse DNS checks ? Would it need to be changed ? Presently, we have a PTR record to resolves to mail.mydomain.com, which is our public ip address where traffic on port 25 is forwarded to our SBS2003 Exchange server.  

I'm trying to understand how a receiving server does it's Reverse DNS check. Is it done on the ip/name of the host server (our ISP) that would send the email for us, or does it do it based on the sender's domain name.

Thanks

0
Comment
Question by:ndidomenico
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
8 Comments
 
LVL 49

Assisted Solution

by:Akhater
Akhater earned 100 total points
ID: 24099295
The PTR check is done on the IP of the sending server so if you are using smart host it will be on your ISP's email not yours
0
 
LVL 58

Accepted Solution

by:
tigermatt earned 400 total points
ID: 24099361

When an email server opens an SMTP session to another mail server (in other words, your server connecting to the recipient's), it will provide a HELO or EHLO header which will generally be followed by the SMTP banner configured on the SMTP Virtual Server.

It is that SMTP banner which has the PTR check performed on it, to verify the IP the server initiating the connection with has the PTR matching the FQDN provided in the HELO/EHLO.

For sending mail via the ISP's Smart Host, the server will still send a banner like this, but the ISP doesn't care about your banner and will ignore it (they will accept your message once you have proved you can use their SMTP server, usually by means of username/password authentication). When the ISP relays the message and passes it on to be delivered, the ISP's server will provide a banner and it is THAT banner which has the PTR check performed on it.

-Matt
0
 

Author Comment

by:ndidomenico
ID: 24099689
So if I'm using my ISP's smart host for sending emails, it doesn't matter whether or not we have a properly set PTR record for our domain name for Revers DNS lookup ? It would never be checked by the receiving server, since it will only do a RDNS check based on my ISP's smart host FQDN?
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 49

Expert Comment

by:Akhater
ID: 24099704
exactly
0
 
LVL 58

Expert Comment

by:tigermatt
ID: 24099729

Correct. The ISP will ignore the PTR record because you authenticate to their server in order to relay via other means (username/password).

-Matt
0
 

Author Comment

by:ndidomenico
ID: 24099841
Ok. I think it's all clear now. Last question: how can I verify what is the HELO header and also the SMTP banner that is given out by Exchange to receiving servers ?

A Telnet session on port 25 of my Exchange server returns at the beginning:
"220 mail.mydomain.com Microsoft ESMTP MAIL Service, Version: 6.0.3790.3959 ready at  Wed, 8 Apr 2009 13:26:29 -0400"
Is this the SMTP banner ? And the name following the 220 code is what is used for the RDNS check ?

Then if I enter HELO and press enter, I get:
250 mail.mydomain.com Hello [10.0.1.100]
Is this the HELO header ?
0
 
LVL 58

Expert Comment

by:tigermatt
ID: 24100208
The SMTP banner is the part after the '220' when you initiate a telnet session to the server. Whether it is HELO/EHLO doesn't have anything to do with the header which is sent; EHLO and HELO are just two different SMTP standards, with EHLO having wider support for more features than HELO, which is very basic for basic email transfer. The SMTP banner sent for each is the same.

-Matt
0
 

Author Closing Comment

by:ndidomenico
ID: 31568117
Thanks for your help.
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Utilizing an array to gracefully append to a list of EmailAddresses
Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question