Solved

Reverse DNS Configuration Exchange 2010

Posted on 2010-09-07
10
1,197 Views
Last Modified: 2012-08-14
Hello,

We recently set up our network. I must admit this is a new "land" for me. I am more a Software developer, not a Network Administrator but I had to get hands on the problem.

Some email providers, are rejecting our emails. AOL among others are complaining about server with no reverse dns. I found pretty good articles online about it but i have still some doubts and i want no chances when it comes to our live system.

This is my scenario.

I have my Domain Controller server (DC001), Exchange Server (EXC001) and i have like 10 different domains (for email addresses) like john.doe@zzzz.com, john.doe@yyyy.com, john.doe@xxxxx.com. All of them pointing to the same user in our Active Directory. My domain in the network is ATL.LOCAL

I understand i have to set an A record witm mail.????, a MX record and PTR record... but where exactly?

Should i add these records to my MAIN domain (ATL.LOCAL) or should i add one for every mail domain i am using? mail.zzzz.com, mail.yyyy.com, mail.xxxx.com. My feelins are that i have to add them to each and every domain i might be sending emails from... right?

Please, help. Thank you so much.
0
Comment
Question by:acampos
  • 3
  • 3
  • 2
  • +2
10 Comments
 
LVL 28

Accepted Solution

by:
sunnyc7 earned 400 total points
ID: 33619004
Call your ISP and ask them to setup a PTR record for your external FQDN - mail.domain.com > to your public IP

Check your present config.
www.mxtoolbox.com
enter your domain name
click smtp diagnostics

if you get - reverse DNS doesnt match SMTP banner > then call ISP.

thanks
0
 
LVL 10

Assisted Solution

by:jorlando66
jorlando66 earned 100 total points
ID: 33619005
The reverse dns should be set with your isp.  It should resolve the address that your smtp server announces itself as.  What is happening for example say your mail server announces itself as mail@yourdomain.com but the public IP that your isp hosts resolves to serverport@yourisp.com this will fail reverse dns.

Contact your ISP and have them add the rdns for you.
0
 
LVL 2

Expert Comment

by:SiborgRaider
ID: 33619008
Set these in the dns control panel of your domain name, you can ask your isp to setup a rdns for you.
0
VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

 
LVL 10

Expert Comment

by:jorlando66
ID: 33619013
lol.  I could use the ^^^^ again sunny
0
 
LVL 28

Expert Comment

by:sunnyc7
ID: 33619019
ha ha :)
0
 
LVL 7

Expert Comment

by:pr0t0c0l12
ID: 33619042
from what you are describing, you only need to create the A + MX on hte primary domain controller (if it is using DNS/DHCP on the same server). your john.doe@zzzz.com will also have to have contacts to host the different domains under his account. You would have to create contacts like john.doe@yyyy.com, and john.doe@xxxx.com.  All this settings should be applied to atl.loca. IT will be a very complicated solution but have one domain controller manage all the accounts and if they need to have access to the AD, use delegation permissions to add each AD Domain Controller to read from atl.local

Good luck.
0
 

Author Comment

by:acampos
ID: 33620470
@Sunnyc7
I went to mxtoolbox.com. I typed in like 5 of our domains. they all came back good BUT when i click on the SMTP Test i get all Green Dots except for Reverse DNS

Green - Not an open relay.
Green - 0 seconds - Good on Connection time
Yellow - 5.273 seconds - Warning on Transaction time
Red - Reverse DNS FAILED! This is a problem.
Green - OK - Reverse DNS matches SMTP Banner

@pr0t0c0l12 Thank you for your response. i think that's what i have to do. Yes, i do have one domain controller managing all the accounts. Each user has their corresponding domains assigned.

@all the people... thank you for your inputs. I am gonna try right now and i will let you know as soon as i can.

Greetings.


0
 

Author Comment

by:acampos
ID: 33621013
One more thing

Session Transcript:
HELO please-read-policy.mxtoolbox.com
250 XXXXXXX.ATL.LOCAL Hello [XX.XX.227.133] [47 ms]
MAIL FROM: <supertool@mxtoolbox.com>
250 2.1.0 Sender OK [47 ms]
RCPT TO: <test@example.com>
550 5.7.1 Unable to relay [5070 ms]
QUIT
221 2.0.0 Service closing transmission channel [47 ms]


maybe this can help a lil bit.
0
 
LVL 28

Expert Comment

by:sunnyc7
ID: 33621036
Yeah thats good > it should not be able to relay >> since your server is *not* an open relay :)
0
 

Author Comment

by:acampos
ID: 33621220
Ok. this is what i did (and i guess it will take a little bit of time before it replicates all over)

I went to my DC server.

opened up DNS
expanded SERVERNODE
expanded Forward Lookup Xones
expanded ATL.LOCAL
added a Host(A) with my MX external server IP
added a (MX) record

nothing is happening so far when i check in nxtoolbox.com but i guess it takes some time.

now remember i have a lot of other zones at the same level than my domain name ATL.LOCAL that matches most of my email domains (@yyyy.com, @xxxx.com, etc)...

ok. Is there anything else i should check in the meantime?
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

MS Outlook is a world-class email client application that is mainly used for e-communication globally.  In this article, we will discuss the basic idea about MS Outlook, its advanced features, and types of MS Outlook File formats.
Read this checklist to learn more about the 15 things you should never include in an email signature.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question