OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
RE: 554 transaction failed lack of security

From: Jason Ledford (jledfordbiltmore.com)
Date: Fri Jan 11 2008 - 10:48:40 CST


I really don't know why my admins have multiple ptr's. I would imagine that one would do just fine, mail.mydomain.com.

we have several different services that run on the same ip and are routed based on port numbers, for instance, our incoming port 25 is different then our outgoing, same IP though. we have both functions split on 2 different machines.

if the ptr was just mail.mydomain.com would that probably be an appropriate fix? I only sanitzied domain names so they don't make it to the search. if you want I can email directly the domains involved if someone can help me make sense of this.

________________________________________
From: owner-postfix-userspostfix.org [owner-postfix-userspostfix.org] On Behalf Of mouss [mlist.onlyfree.fr]
Sent: Friday, January 11, 2008 10:29 AM
Cc: postfix-userspostfix.org
Subject: Re: 554 transaction failed lack of security

Jason Ledford wrote:
> I can't seem to get a response from the admins at the problem site. But after some trouble shooting it seems to be related (and I could be completely off) to my ptr records for my ip compared the domain in my outgoing emails. My ptr records for my outgoing ip address is autodiscover.mydomain.com rpc.mydomain.com and mail.mydomain.com and the address in my outgoing email is mydomain.com. Everything works as normal except for this domain. If I telnet from my outgoing mail server to this site I can do:
>

what is the purpose of putting multiple names for a single IP? give it a
single PTR.

> Helo mail.mydomain.com (or any of my ptr records work)
> Mail from:jledfordmail.mydomain.com (or any of my ptr records work)
>
> If I use mydomain.com it never works no matter what I put in for the helo. Our main site mydomain.com isn't on this ip address and so I don't think I could put a ptr on for that name at my mail server ip address.
>
> So am I completely misunderstanding ptr and email, or does this site require a matching ptr for your tld name in outgoing email?
>

without the actual names and IPs, it is hard to help you. you may have a
broken MX for the domain.