MX Records (Full Version)

All Forums >> [Microsoft Exchange 2003] >> General



Message


lhenriquez -> MX Records (14.Mar.2006 10:33:59 PM)

First of all G'd evening (and sorry for my bad english [image]http://forums.msexchange.org/image/s2.gif[/image] )

Ok, here is my problem:

I'm trying to set up a new Exchange server on my organization (just for testing purposes so far, i'm a newbie into exchange). So far, i can send emails (internally and externally), i can receive emails from my internal network (i can receive emails "externally", but only when stablishing a telnet connection through port 25 to my server). I can also access OWA, externally and internally.
I've forwarded ports 25, 110, 80, 443 and many other ports to my Exchange server (I'm behind a Firewall), but i can not receive emails from external addresses.

I've been working around this since a few weeks, and i'm starting to think it is a MX records problem. I created a domain at no-ip.com (unicomputos.no-ip.org) pointing towards my IP address (my external IP address, the one from my ISP). Also, i configured its MX records to point towards the domain "unicomputos.no-ip.org".

So, what do you guys think about this?, from my point of view, it should be correct, but maybe the no-ip organization has a limitation from doing this. Do you think that maybe registering a new domain (not a free one) could solve this issue?
Giv' me some ideas please, thanks in advanced.




lhenriquez -> RE: MX Records (15.Mar.2006 2:10:29 PM)

Will u guys let me die like that? [:(]




de.blackman -> RE: MX Records (15.Mar.2006 4:35:17 PM)

To test if your MX record is setup correctly and connecting to your server, go to www.checkdns.net or www.dnsstuff.com and enter your SMTP domain name. See if there are any issues. Is your domain actually called "unicomputos.no-ip.org"??




lhenriquez -> RE: MX Records (15.Mar.2006 4:44:43 PM)

quote:

ORIGINAL: de.blackman

To test if your MX record is setup correctly and connecting to your server, go to www.checkdns.net or www.dnsstuff.com and enter your SMTP domain name. See if there are any issues. Is your domain actually called "unicomputos.no-ip.org"??


Ok now, this is weird [&:]

I tested the MX records at Dnsstuff.com and these were the results:

How I am searching:
Searching for unicomputos.no-ip.org MX record at l.root-servers.net [198.32.64.12]: Got referral to TLD4.ULTRADNS.org. [took 88 ms]
Searching for unicomputos.no-ip.org MX record at TLD4.ULTRADNS.org. [199.7.67.1]: Got referral to nf2.no-ip.com. [took 9 ms]
Searching for unicomputos.no-ip.org MX record at nf2.no-ip.com. [216.66.37.12]: Timed out.  Trying again.
Searching for unicomputos.no-ip.org MX record at nf3.no-ip.com. [70.86.196.66]: Reports adsl-211-176.tricom.net. [took 38 ms]

Answer:


Domain	Type	Class	TTL	Answer	
unicomputos.no-ip.org.	MX	IN	60	adsl-211-176.tricom.net. [Preference = 10]	
unicomputos.no-ip.org.	MX	IN	60	unicomputos.no-ip.org. [Preference = 15]	
unicomputos.no-ip.org.	MX	IN	60	unicomputos.no-ip.org. [Preference = 20]	
unicomputos.no-ip.org.	MX	IN	60	unicomputos.no-ip.org. [Preference = 25]	
unicomputos.no-ip.org.	MX	IN	60	adsl-211-176.tricom.net. [Preference = 5]	
no-ip.org.	NS	IN	86400	nf2.no-ip.com.	
no-ip.org.	NS	IN	86400	nf3.no-ip.com.	
no-ip.org.	NS	IN	86400	nf1.no-ip.com.	
unicomputos.no-ip.org.	A	IN	60	200.42.211.176	
nf1.no-ip.com.	A	IN	86400	204.16.252.8	
nf2.no-ip.com.	A	IN	86400	216.66.37.12	
nf3.no-ip.com.	A	IN	86400	70.86.196.66


So, it seemed to be alright, but the test at DNS.net have failed with this error:

CheckDNS.NET is testing unicomputos.no-ip.org	


CheckDNS.NET is asking root servers about authoritative NS for domain	
  Answer from N/A: domain 'unicomputos.no-ip.org' not found


Who should I believe? [&:]


Edit 1: Well, the domain name i'm using for AD is "universaldecomputos.com", but the internet's domain name is unicomputos.no-ip.org (i already set up Exchange to send/receive from that last domain).




de.blackman -> RE: MX Records (16.Mar.2006 11:22:48 PM)

Hmmm it sounds like an ISP issue. I would recommend you contact your ISP and make sure your domain MX is registered properly.




davelew99 -> RE: MX Records (16.Mar.2006 11:27:45 PM)

Through no-ip you don't have a proper MX record, however, what can be happening is that all your mail is bouncing as a lot of servers out there block mail coming from a dynamic IP address/ADSL type IP.

I recommend you use your ISPs SMTP server (in Exchange server you can set this up so all mail is routed via your chosen SMTP instead of using its own)




davelew99 -> RE: MX Records (16.Mar.2006 11:29:31 PM)

And in your no-ip control panal, under MX records, simply put in your no-ip address as the first one (unicomputos.no-ip.org was it?) This will route all mail to your server




lhenriquez -> RE: MX Records (17.Mar.2006 1:35:24 PM)

quote:

ORIGINAL: davelew99

Through no-ip you don't have a proper MX record, however, what can be happening is that all your mail is bouncing as a lot of servers out there block mail coming from a dynamic IP address/ADSL type IP.


I have a fixed internet IP address anyway, could this affect?

quote:

ORIGINAL: davelew99

I recommend you use your ISPs SMTP server (in Exchange server you can set this up so all mail is routed via your chosen SMTP instead of using its own)


You mean through: Exchange system manager=>Connectors=>Internet mail SMTP connector; then properties and setting the "Forward all mail through this connector to the following smart host" option?




davelew99 -> RE: MX Records (17.Mar.2006 2:54:44 PM)

SMTP routing....yes...he says, it is somthing like that but a google, or a search on this forum should confirm it, my exchange server is dead at the moment so i can't check for you.

Although you have a static IP it is not neccesscerily on the 'safe' list held by many ISPs, if you route all your outgoing traffic via your ISPs SMTP server then you avoid this issue anyway.

Just make sure you set up your MX on no-ip.

And as an aside since you have a static IP, i recommend buying a simple .uk domain name - around £6 for two years if you shop about (123 Reg are good)




lhenriquez -> RE: MX Records (20.Mar.2006 3:15:58 PM)

Ok, these are the updates:

I finally decided into buying a "real" domain name (unicomputosonline.com) at BusinessPremium.com.
I've edited both the A record and MX Record: The A record now is pointing to my Internet public IP address, and the MX Record is pointing towards the name "unicomputosonline.com".(at this point, i don't even know if this is correct [&:] )

So, i sent so test emails to the address administrator@unicomputosonline.com, but it returned the email with the following error:
 
"Reason: Remote host said: 553 sorry, relaying denied from your location "

Later on, i tried to sent an email from my Hotmail account, but it returned it with another error, saying it could not deliver the message to the recipient.

Sent another from my gmail account and it returned this:

Technical details of permanent failure:
PERM_FAILURE: SMTP Error (state 9): 553 sorry, that domain isn't in my list of allowed rcpthosts (#5.7.1)



I tried to send another test email from dnsstuff.com, here is the error it returned:
Trying to connect to all mailservers:

  unicomputosonline.com. - 200.42.211.176  [Could not connect: Could not connect to mail server (timed out).]
[Note that if your mailserver takes over 30 seconds to respond, our test will timeout, even though real mailservers will wait longer]

 
Also, i tested the whole domain at dnsreport.com and it could not connect to my mail server either.
What am i missing here?...i'll try yet another test, but this time i'll separate my exchange server from the firewall.

What do u guys think about these errors?




davelew99 -> RE: MX Records (20.Mar.2006 4:40:51 PM)

When your exchange server recieves mail - presumable its set up to eg admin@youraddy.no-ip.com and it goes OK i'll take *@youraddy.no-ip.com and processes it (we hope) but now this is happening -


Your exchange server is getting mail to admin@unicomputosonline.com and its going "WTF? i'm not relaying that!"

In essence what you have to do is change the domain(s) that your exchange server is operating on to your new .com domain




lhenriquez -> RE: MX Records (20.Mar.2006 5:02:05 PM)

quote:

ORIGINAL: davelew99

When your exchange server recieves mail - presumable its set up to eg admin@youraddy.no-ip.com and it goes OK i'll take *@youraddy.no-ip.com and processes it (we hope) but now this is happening -


Your exchange server is getting mail to admin@unicomputosonline.com and its going "WTF? i'm not relaying that!"

In essence what you have to do is change the domain(s) that your exchange server is operating on to your new .com domain

Are talking about my AD's domain?

If you're talking about changing that through Exchange System Manager, I've already done that.

PS: Another thing i've seen since i made this change of domain name, is that emails are bouncing so much faster (hehehe)...i mean, when i was using the "no-ip" domain, it took hours to returne the error mssg, but now, it is an 1 minute matter.




de.blackman -> RE: MX Records (20.Mar.2006 5:37:26 PM)

So you have changed your recipient policy on the exchange organization to accept mail for unicomputosonline.com and your users are getting stamped with this address?




lhenriquez -> RE: MX Records (20.Mar.2006 6:02:26 PM)

quote:

ORIGINAL: de.blackman

So you have changed your recipient policy on the exchange organization to accept mail for unicomputosonline.com and your users are getting stamped with this address?

That's correct.




lhenriquez -> RE: MX Records (22.Mar.2006 3:21:03 PM)

Hi guys, it's me again.

So, Finally tested my domain (unicomputosonline.com) at DNSReport and still getting this error:

ERROR: I could not complete a connection to any of your mailservers!

mail.unicomputosonline.com: Timed out [Last data sent: [Did not connect]]
unicomputosonline.com: Timed out [Last data sent: [Did not connect]]
adsl-211-176.tricom.net: Timed out [Last data sent: [Did not connect]]

If this is a timeout problem, note that the DNS report only waits about 40 seconds for responses, so your mail may work fine in this case but you will need to use testing tools specifically designed for such situations.

 
As I said at the beginning of this post, i can telnet my exchange server through port 25. No i have a question: Is it possible to telnet the server even though my ISP is blocking port 25?......So far, i'm not really sure about my ISP blocking incoming SMTP traffic, i' ve just sent an email asking them about this issue.

The thing is that my server is unreachable for some reason, is there something else i could try to solve this? (Forge about my firewall, i already tried forwarding SMTP port and getting rid of it at the last chance)

Tanks[:(]




de.blackman -> RE: MX Records (22.Mar.2006 3:47:37 PM)

Any antivirus/ISA server in the picture? From your firewall, is the IP for the MX pointing straight to the Exchange server?




lhenriquez -> RE: MX Records (22.Mar.2006 3:55:37 PM)

quote:

ORIGINAL: de.blackman

Any antivirus/ISA server in the picture? From your firewall, is the IP for the MX pointing straight to the Exchange server?


No antivirus, nor ISA Server.

Ok, the records are configured as it follows:

unicomputosonline.com pointing to my external IP (200.42.211.176), which is configured in the firewall (but I also configured it once straight in the server, to discard any Firewall  problem)==> Port 25 redirecting to the local (LAN) IP address of my exchange server....just a simple NAT, i shouldn't be this hard[:(]




de.blackman -> RE: MX Records (22.Mar.2006 4:04:25 PM)

I would recommend deleting that NATing for port 25 and recreating it. I can successfully telnet to the IP on port 80 without an issue but port 25 is not connecting. www.checkdns.net shows your IP to be correct but it could be the firewall rule.




lhenriquez -> RE: MX Records (22.Mar.2006 5:21:37 PM)

quote:

ORIGINAL: de.blackman

1- I would recommend deleting that NATing for port 25 and recreating it.
2- I can successfully telnet to the IP on port 80 without an issue but port 25 is not connecting. www.checkdns.net shows your IP to be correct but it could be the firewall rule.


1- I already did that, but nothing [:(]

2- This confuses me the most: according to checkdns.net, my domain's port 25 is unaccessible...but hey, try it by urself using a command prompt: telnet unicomputosonline.com 25 .........it worked!! [&:]

And as i said before, i also tried without the firewall, it didn't work either.




Xguru -> RE: MX Records (22.Mar.2006 7:00:27 PM)

Issue is with the firewall or anything sitting before Exchange....

As blackman suggested you may want to recreate the NAT external ip >> internal IP forward to Exchange IP.

Port NAT any to any

XGURU




Page: [1] 2   next >   >>