Solved

E-mail server verification and DNS

Posted on 2010-09-13
10
767 Views
Last Modified: 2012-06-21
Our exchange server is getting disconnected by other servers recently, here is an example:

554-Your access to this mail system has been rejected due to the sending MTA's f
ailure of the following host DNS verification measures:
554-1) The host PTR record doesn't exist in DNS (there's no hostname associated
with the connecting MTA's IP address)
554-  OR
554-2) A reverse DNS lookup of the connecting MTA's IP address (PTR) does not ma
tch the forward DNS lookup (A Record) of its hostname.


I've checked and my DNS and reverse appear to be working ok (mail.nativeconnections.org 69.26.192.91). I used http://mxtoolbox.com/SuperTool.aspx to check my server and get a "banner doesn't mach rDNS" error. But it does, what am I missing?
0
Comment
Question by:nac_
10 Comments
 
LVL 34

Expert Comment

by:Shreedhar Ette
ID: 33667814
Hi,

Refer this article:
http://www.outlookexchange.com/articles/JasonSherry/sherry_c20p1.asp

Hope this helps,
Shree
0
 
LVL 29

Expert Comment

by:Rich Weissler
ID: 33667850
Don't know if this helps.  Hitting my local DNS servers, everything looks perfect.

However, when I point at the only server that's listed as authoritative for your domain, I get a server failed.
nativeconnections.org
        primary name server = NS17.WORLDNIC.COM

> set type=ptr
> 91.192.26.69.in-addr.arpa
Server:  ns17.worldnic.com
Address:  205.178.190.9

*** ns17.worldnic.com can't find 91.192.26.69.in-addr.arpa: Server failed

Open in new window

0
 

Author Comment

by:nac_
ID: 33667903
Razmus,
I've  updated my PTR with my ISP. So should this propagate to ns17.worldnic.com or do I need to do something else?
0
 
LVL 29

Accepted Solution

by:
Rich Weissler earned 250 total points
ID: 33668023
Okay, stretching my knowledge this evening.
I apologize... airband is authoritative for 192.26.69.in-addr.arpa, and it is responding with what appears to be correct information.  I assume ns17.worldnic.com is configured not to accept recursive queries.  That whole line of thought may have been erroneous.  (In other words, worldnic.com doesn't need anything else... it's not concerned with your reverse lookup.)

The default TTL on the 192.26.69.in-addr.arpa zone is a day.  How recently did you make the change?  (Default TTL on your worldnic SOA is 1 hour...)
0
 

Author Comment

by:nac_
ID: 33668033
I made the change about 8 hours ago with airband. Maybe I just need to wait a day.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 29

Expert Comment

by:Rich Weissler
ID: 33668074
For the sites that had a cached copy, yes.  Like I said, checking against my local servers, it all looked good.  :-)
0
 

Author Comment

by:nac_
ID: 33668101
The interesting thing is that www.mxtoolbox.com will report my PTR correctly (mail.nativeconnections.org) and my SMTP banner (220 mail.nativeconnections.org) but then displays "banner != rDNS".

I'll check back and report once 24 hours goes by.
0
 
LVL 29

Expert Comment

by:Rich Weissler
ID: 33668202
I think your mail server got tired of me prodding it.  Sorry about that.
Your banner looks correct.  The next thing I was going to try was to see what it responds after a ELHO command -- it looks like it should pass:
250 <your.server.again> Hello <my.domain> <IP>, pleased to meet you.
(I've always loved how polite email servers are)
But I'm curious if that's the banner mxtoolbox.com is complaining about... 'cause the first one I see sure looks correct.
0
 
LVL 26

Expert Comment

by:jar3817
ID: 33671613
Is this a constant problem or an intermittent one? It's possible the recipient servers are just having temporary name resolution problems. I just tried resolving both forward and reverse and it all looks good on my end too.
0
 

Author Comment

by:nac_
ID: 33674220
I'll looks good now. Must have been cached for the mxtoolbox site somewhere. The other e-mail server that was refusing my connection is working now too. I guess I should be more patient. Thanks for your help Razmus
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When it comes to providing great business solutions, IBM and Microsoft are the two top companies excelling in the art. Both launch similar products aimed at a wide audience set and have a good customer satisfaction rate. Since their products are qui…
Import PST to Exchange using Power Shell new-mailboximportrequest command, you can simply import the PST file into Exchange mailbox or archived. To know How to import PST into Exchange  2013 read the complete article.
Familiarize people with the process of utilizing SQL Server views from within Microsoft Access. Microsoft Access is a very powerful client/server development tool. One of the SQL Server objects that you can interact with from within Microsoft Access…
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…

930 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now