Tuesday, September 20, 2011

SPF & Reserve DNS Record Setup

Changed the public IP for Exchange server last night and some users have got the Undeliverable message to some recepients like the example below,
Subject: Undeliverable: Financial Statements

 Your message did not reach some or all of the intended recipients.

Subject: Financial Statements
Sent: 9/20/2011 10:07 AM

The following recipient(s) cannot be reached:

John Doe on 9/20/2011 10:07 AM
You do not have permission to send to this recipient. For
assistance, contact your system administrator.
<mail.mydomain.com #5.7.1 smtp;550 5.7.1 This system is
configured to reject mail from 66.1.1.1 [66.1.1.1] (DNS
reverse lookup failed)>

I went to  http://www.openspf.org/Tools do some tests by sending an email to spf-test@openspf.org and here is what I got in reply:
Your message did not reach some or all of the intended recipients.

       Subject:   

      Sent: 9/20/2011 10:45 AM

 The following recipient(s) cannot be reached:

       spf-test@openspf.org on 9/20/2011 10:45 AM

            You do not have permission to send to this recipient.  For assistance, contact your system administrator.

            <mail.mydomain.com #5.7.1 smtp;550 5.7.1 <spf-test@openspf.org>: Recipient address rejected: SPF Tests: Mail-From Result="none": Mail From="cc@mydomain.com" HELO name="mail.mydomain.com" HELO Result="none" Remote IP="66.1.1.1">

So I had to put the Reverse DNS back. It's been a long time since I needed to do that, and I was also confused it with SPF record which needs to be done in DNS zone hosted by provider. Here is what I actually need to do:

1. Call ISP to set up the reverse DNS record for my Exchange server. (That easy!)
2. Set up SPF records for my domain and exchange server. (See below)

Check this page for more details.

Sent a test message again to spf-test@openspf.org, then I got:
Recipient address rejected: SPF Tests: Mail-From Result="pass": Mail From="cc@mydomain.com" HELO name="mail.mydomain.com" HELO Result="pass" Remote IP="66.1.1.1">

also, sent a test message to check-auth@verifier.port25.com, the result is:

SPF check:          pass
DomainKeys check: neutral
DKIM check: neutral
Sender-ID check: pass
SpamAssassin check: ham


YAHOO!!

 

No comments:

Post a Comment

Solution: The size of the extent is less than the minimum in VMware

 I ran out the C drive space in a Windows 10 virtual machine in VMware. However, after adding additional free disk space, the "Extend&q...