• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 789
  • Last Modified:

E-mail server verification and DNS

Our exchange server is getting disconnected by other servers recently, here is an example:

554-Your access to this mail system has been rejected due to the sending MTA's f
ailure of the following host DNS verification measures:
554-1) The host PTR record doesn't exist in DNS (there's no hostname associated
with the connecting MTA's IP address)
554-  OR
554-2) A reverse DNS lookup of the connecting MTA's IP address (PTR) does not ma
tch the forward DNS lookup (A Record) of its hostname.


I've checked and my DNS and reverse appear to be working ok (mail.nativeconnections.org 69.26.192.91). I used http://mxtoolbox.com/SuperTool.aspx to check my server and get a "banner doesn't mach rDNS" error. But it does, what am I missing?
0
nac_
Asked:
nac_
1 Solution
 
Shreedhar EtteCommented:
Hi,

Refer this article:
http://www.outlookexchange.com/articles/JasonSherry/sherry_c20p1.asp

Hope this helps,
Shree
0
 
Rich WeisslerProfessional Troublemaker^h^h^h^h^hshooterCommented:
Don't know if this helps.  Hitting my local DNS servers, everything looks perfect.

However, when I point at the only server that's listed as authoritative for your domain, I get a server failed.
nativeconnections.org
        primary name server = NS17.WORLDNIC.COM

> set type=ptr
> 91.192.26.69.in-addr.arpa
Server:  ns17.worldnic.com
Address:  205.178.190.9

*** ns17.worldnic.com can't find 91.192.26.69.in-addr.arpa: Server failed

Open in new window

0
 
nac_Author Commented:
Razmus,
I've  updated my PTR with my ISP. So should this propagate to ns17.worldnic.com or do I need to do something else?
0
Transaction-level recovery for Oracle database

Veeam Explore for Oracle delivers low RTOs and RPOs with agentless transaction log backup and transaction-level recovery of Oracle databases. You can restore the database to a precise point in time, even to a specific transaction.

 
Rich WeisslerProfessional Troublemaker^h^h^h^h^hshooterCommented:
Okay, stretching my knowledge this evening.
I apologize... airband is authoritative for 192.26.69.in-addr.arpa, and it is responding with what appears to be correct information.  I assume ns17.worldnic.com is configured not to accept recursive queries.  That whole line of thought may have been erroneous.  (In other words, worldnic.com doesn't need anything else... it's not concerned with your reverse lookup.)

The default TTL on the 192.26.69.in-addr.arpa zone is a day.  How recently did you make the change?  (Default TTL on your worldnic SOA is 1 hour...)
0
 
nac_Author Commented:
I made the change about 8 hours ago with airband. Maybe I just need to wait a day.
0
 
Rich WeisslerProfessional Troublemaker^h^h^h^h^hshooterCommented:
For the sites that had a cached copy, yes.  Like I said, checking against my local servers, it all looked good.  :-)
0
 
nac_Author Commented:
The interesting thing is that www.mxtoolbox.com will report my PTR correctly (mail.nativeconnections.org) and my SMTP banner (220 mail.nativeconnections.org) but then displays "banner != rDNS".

I'll check back and report once 24 hours goes by.
0
 
Rich WeisslerProfessional Troublemaker^h^h^h^h^hshooterCommented:
I think your mail server got tired of me prodding it.  Sorry about that.
Your banner looks correct.  The next thing I was going to try was to see what it responds after a ELHO command -- it looks like it should pass:
250 <your.server.again> Hello <my.domain> <IP>, pleased to meet you.
(I've always loved how polite email servers are)
But I'm curious if that's the banner mxtoolbox.com is complaining about... 'cause the first one I see sure looks correct.
0
 
jar3817Commented:
Is this a constant problem or an intermittent one? It's possible the recipient servers are just having temporary name resolution problems. I just tried resolving both forward and reverse and it all looks good on my end too.
0
 
nac_Author Commented:
I'll looks good now. Must have been cached for the mxtoolbox site somewhere. The other e-mail server that was refusing my connection is working now too. I guess I should be more patient. Thanks for your help Razmus
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now