George Theall on 30 Jul 2004 20:46:02 -0000


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] BIND zone oddity causing SendMail 451 Name server timeout errors?


On Fri, Jul 30, 2004 at 02:07:11AM -0400, kaze wrote:

> Recently needed to rush add another domain to host their email (and DNS).
> Many annoying and weird things happening with email to and from this new
> (temporarily) hosted domain, one being _some_ servers sending to it get
> error "451 example.com: Name server timeout". 

Are the servers that are getting such errors using someone else's DNS?
Who's authoritative for hostedexample.com? Perhaps control has not
(yet?) passed to you and the previous hosts DNS server is no longer
available. 

> Question: I know many mailserver do reverse lookups on incoming email to
> thwart spam, but do they also do it as part of the outgoing mail DNS lookup?

I can't imagine why they would.

> Question: Is there a better way I should structure my DNS to smooth
> everything out?
> 
> For example would I be better server to have hostedexample.com's MX be
> email.example.com. instead of email.hostedexample.com.? Should I just
> dedicate an additional IP address on the mail server for
> email.hostedexample.com. so it can have it's own reverse lookup and be
> totally separate? The reason I did it this way was to try to avoid having
> hostedexample.com's email's headers show example.com.

If you want to hide example.com, I would assign separate IP address(es)
for hostedexample.com services and run separate daemon's on those
interfaces.  Otherwise, you're liable to reveal it as part of either
incoming or outgoing mail, or both. 

George
-- 
theall@tifaware.com

Attachment: pgpBYNCLJTAjH.pgp
Description: PGP signature