451 4.1.8 Possibly forged hostname

We have a problem with only one domain when sender send emails to this domain we receive this error

Last Error: 451 4.1.8 Possibly forged hostname for

What should i do ?

On http://mxtoolbox.com/ everything is ok (green)

Connecting to

220 mail.ville.blainville.qc.ca Microsoft ESMTP MAIL Service ready at Mon, 3 Nov 2014 11:41:53 -0500 [624 ms]
EHLO MXTB-PWS3.mxtoolbox.com
250-mail.ville.blainville.qc.ca Hello []
250-SIZE 36700160
250 CHUNKING [671 ms]
MAIL FROM: <supertool@mxtoolbox.com>
250 2.1.0 Sender OK [671 ms]
RCPT TO: <test@example.com>
550 5.7.1 Unable to relay [5678 ms]

MXTB-PWS3v2 8268ms

I don't know why it's listing because my exchange server mail.ville.blainville.qc.ca is for

Thanks for helping me
Who is Participating?
ReneD100Connect With a Mentor Commented:
If the .70 would point to the DMZ (thus on an internal IP address) I should be able to connect on port 25 on the .70 address and that does not work - only .67. I am personally not familiar with the CheckPoint Firewall, but maybe it has multiple IP addresses defined and .67 is linking to your Exchange?
Seth SimmonsSr. Systems AdministratorCommented:
is .70 your gateway or some anti-spam appliance?
jfguenetAuthor Commented:
It's my checkpoint firewall with antispam it it
Easily manage email signatures in Office 365

Managing email signatures in Office 365 can be a challenging task if you don't have the right tool. CodeTwo Email Signatures for Office 365 will help you implement a unified email signature look, no matter what email client is used by users. Test it for free!

Seth SimmonsSr. Systems AdministratorCommented:
if the mail is going through the firewall (as if exchange is using the firewall as smarthost) then the message would appear as if it was coming from the firewall on .70

if you send a message from there to a gmail address and look at the headers, i'm guessing it shows .70 as received from?
jfguenetAuthor Commented:

Received: from mail.ville.blainville.qc.ca ([])
It's a little strange setup then though, because incoming mail would go to .67, (that's where the mx points to). So if your exchange smarthost is pointing to .70 that means you're scanning all outgoing messages for spam, but not the incoming ones...
.70 shows vpn?
vpn.ville.blainville.qc.ca []
jfguenetAuthor Commented:
It's a checkpoint fw with antispam on it

We are scanning incoming mails arriving to it (check screenshot) is a NAT for our exchange server in our network is our main ip address for the checkpoint firewall
Seth SimmonsConnect With a Mentor Sr. Systems AdministratorCommented:
are you required to scan outgoing messages?  any reason why exchange doesn't connect directly?

the remote system is receiving from .70 thought the PTR points to .67 which would cause issues like this; PTR should match the sending address

also noticed no SPF record for your domain; something else you want to consider as some remote systems will drop if missing

jfguenetAuthor Commented:
Thanks i had two object in my checkpoint fw

One object with a static nat of and one object with not nat.

I deleted the second one and now everything is fine and no more error message.  If i checked the headers now i see instead of

Thanks you guys

Seth: Do you have a good link to configure SPF record for my exchange 2013 on my domain Windows 2012

Thanks !
All Courses

From novice to tech pro — start learning today.