Solved

Reverse DNS Configuration Exchange 2010

Posted on 2010-09-07
10
1,201 Views
Last Modified: 2012-08-14
Hello,

We recently set up our network. I must admit this is a new "land" for me. I am more a Software developer, not a Network Administrator but I had to get hands on the problem.

Some email providers, are rejecting our emails. AOL among others are complaining about server with no reverse dns. I found pretty good articles online about it but i have still some doubts and i want no chances when it comes to our live system.

This is my scenario.

I have my Domain Controller server (DC001), Exchange Server (EXC001) and i have like 10 different domains (for email addresses) like john.doe@zzzz.com, john.doe@yyyy.com, john.doe@xxxxx.com. All of them pointing to the same user in our Active Directory. My domain in the network is ATL.LOCAL

I understand i have to set an A record witm mail.????, a MX record and PTR record... but where exactly?

Should i add these records to my MAIN domain (ATL.LOCAL) or should i add one for every mail domain i am using? mail.zzzz.com, mail.yyyy.com, mail.xxxx.com. My feelins are that i have to add them to each and every domain i might be sending emails from... right?

Please, help. Thank you so much.
0
Comment
Question by:acampos
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
  • 2
  • +2
10 Comments
 
LVL 28

Accepted Solution

by:
sunnyc7 earned 400 total points
ID: 33619004
Call your ISP and ask them to setup a PTR record for your external FQDN - mail.domain.com > to your public IP

Check your present config.
www.mxtoolbox.com
enter your domain name
click smtp diagnostics

if you get - reverse DNS doesnt match SMTP banner > then call ISP.

thanks
0
 
LVL 10

Assisted Solution

by:jorlando66
jorlando66 earned 100 total points
ID: 33619005
The reverse dns should be set with your isp.  It should resolve the address that your smtp server announces itself as.  What is happening for example say your mail server announces itself as mail@yourdomain.com but the public IP that your isp hosts resolves to serverport@yourisp.com this will fail reverse dns.

Contact your ISP and have them add the rdns for you.
0
 
LVL 2

Expert Comment

by:SiborgRaider
ID: 33619008
Set these in the dns control panel of your domain name, you can ask your isp to setup a rdns for you.
0
MS Dynamics Made Instantly Simpler

Make Your Microsoft Dynamics Investment Count  & Drastically Decrease Training Time by Providing Intuitive Step-By-Step WalkThru Tutorials.

 
LVL 10

Expert Comment

by:jorlando66
ID: 33619013
lol.  I could use the ^^^^ again sunny
0
 
LVL 28

Expert Comment

by:sunnyc7
ID: 33619019
ha ha :)
0
 
LVL 7

Expert Comment

by:pr0t0c0l12
ID: 33619042
from what you are describing, you only need to create the A + MX on hte primary domain controller (if it is using DNS/DHCP on the same server). your john.doe@zzzz.com will also have to have contacts to host the different domains under his account. You would have to create contacts like john.doe@yyyy.com, and john.doe@xxxx.com.  All this settings should be applied to atl.loca. IT will be a very complicated solution but have one domain controller manage all the accounts and if they need to have access to the AD, use delegation permissions to add each AD Domain Controller to read from atl.local

Good luck.
0
 

Author Comment

by:acampos
ID: 33620470
@Sunnyc7
I went to mxtoolbox.com. I typed in like 5 of our domains. they all came back good BUT when i click on the SMTP Test i get all Green Dots except for Reverse DNS

Green - Not an open relay.
Green - 0 seconds - Good on Connection time
Yellow - 5.273 seconds - Warning on Transaction time
Red - Reverse DNS FAILED! This is a problem.
Green - OK - Reverse DNS matches SMTP Banner

@pr0t0c0l12 Thank you for your response. i think that's what i have to do. Yes, i do have one domain controller managing all the accounts. Each user has their corresponding domains assigned.

@all the people... thank you for your inputs. I am gonna try right now and i will let you know as soon as i can.

Greetings.


0
 

Author Comment

by:acampos
ID: 33621013
One more thing

Session Transcript:
HELO please-read-policy.mxtoolbox.com
250 XXXXXXX.ATL.LOCAL Hello [XX.XX.227.133] [47 ms]
MAIL FROM: <supertool@mxtoolbox.com>
250 2.1.0 Sender OK [47 ms]
RCPT TO: <test@example.com>
550 5.7.1 Unable to relay [5070 ms]
QUIT
221 2.0.0 Service closing transmission channel [47 ms]


maybe this can help a lil bit.
0
 
LVL 28

Expert Comment

by:sunnyc7
ID: 33621036
Yeah thats good > it should not be able to relay >> since your server is *not* an open relay :)
0
 

Author Comment

by:acampos
ID: 33621220
Ok. this is what i did (and i guess it will take a little bit of time before it replicates all over)

I went to my DC server.

opened up DNS
expanded SERVERNODE
expanded Forward Lookup Xones
expanded ATL.LOCAL
added a Host(A) with my MX external server IP
added a (MX) record

nothing is happening so far when i check in nxtoolbox.com but i guess it takes some time.

now remember i have a lot of other zones at the same level than my domain name ATL.LOCAL that matches most of my email domains (@yyyy.com, @xxxx.com, etc)...

ok. Is there anything else i should check in the meantime?
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A procedure for exporting installed hotfix details of remote computers using powershell
Unified and professional email signatures help maintain a consistent company brand image to the outside world. This article shows how to create an email signature in Exchange Server 2010 using a transport rule and how to overcome native limitations …
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

732 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question