Link to home
Start Free TrialLog in
Avatar of nac_
nac_Flag for United States of America

asked on

E-mail server verification and DNS

Our exchange server is getting disconnected by other servers recently, here is an example:

554-Your access to this mail system has been rejected due to the sending MTA's f
ailure of the following host DNS verification measures:
554-1) The host PTR record doesn't exist in DNS (there's no hostname associated
with the connecting MTA's IP address)
554-  OR
554-2) A reverse DNS lookup of the connecting MTA's IP address (PTR) does not ma
tch the forward DNS lookup (A Record) of its hostname.


I've checked and my DNS and reverse appear to be working ok (mail.nativeconnections.org 69.26.192.91). I used http://mxtoolbox.com/SuperTool.aspx to check my server and get a "banner doesn't mach rDNS" error. But it does, what am I missing?
Avatar of Shreedhar Ette
Shreedhar Ette
Flag of India image

Hi,

Refer this article:
http://www.outlookexchange.com/articles/JasonSherry/sherry_c20p1.asp

Hope this helps,
Shree
Avatar of Rich Weissler
Rich Weissler

Don't know if this helps.  Hitting my local DNS servers, everything looks perfect.

However, when I point at the only server that's listed as authoritative for your domain, I get a server failed.
nativeconnections.org
        primary name server = NS17.WORLDNIC.COM

> set type=ptr
> 91.192.26.69.in-addr.arpa
Server:  ns17.worldnic.com
Address:  205.178.190.9

*** ns17.worldnic.com can't find 91.192.26.69.in-addr.arpa: Server failed

Open in new window

Avatar of nac_

ASKER

Razmus,
I've  updated my PTR with my ISP. So should this propagate to ns17.worldnic.com or do I need to do something else?
ASKER CERTIFIED SOLUTION
Avatar of Rich Weissler
Rich Weissler

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of nac_

ASKER

I made the change about 8 hours ago with airband. Maybe I just need to wait a day.
For the sites that had a cached copy, yes.  Like I said, checking against my local servers, it all looked good.  :-)
Avatar of nac_

ASKER

The interesting thing is that www.mxtoolbox.com will report my PTR correctly (mail.nativeconnections.org) and my SMTP banner (220 mail.nativeconnections.org) but then displays "banner != rDNS".

I'll check back and report once 24 hours goes by.
I think your mail server got tired of me prodding it.  Sorry about that.
Your banner looks correct.  The next thing I was going to try was to see what it responds after a ELHO command -- it looks like it should pass:
250 <your.server.again> Hello <my.domain> <IP>, pleased to meet you.
(I've always loved how polite email servers are)
But I'm curious if that's the banner mxtoolbox.com is complaining about... 'cause the first one I see sure looks correct.
Is this a constant problem or an intermittent one? It's possible the recipient servers are just having temporary name resolution problems. I just tried resolving both forward and reverse and it all looks good on my end too.
Avatar of nac_

ASKER

I'll looks good now. Must have been cached for the mxtoolbox site somewhere. The other e-mail server that was refusing my connection is working now too. I guess I should be more patient. Thanks for your help Razmus