Skip to main content
Mohamed_kamal
New Member
September 26, 2016
Question

DNS issue

  • September 26, 2016
  • 2 replies
  • 40055 views

i have fortimail 200d and fortigate 200D

when i send any mail replay me postmaster is (reason: 550 *** The HELO for IP address 41.38.52.75 was '[41.38.52.75]' (valid but not recommended syntax )

i contact with senderbase team to know why added my IP to blacklist and replay me that 

To this end, we are seeing reports of HELO strings which do not match the PTR / rDNS of the IP. One of the HELO string we are seeing  “[41.38.52.75]”  which is not exact matches to the PTR of the IP 41.38.52.75  (mail.elashrygroup.com).

how to resolve ip to HELO  ? 

please  help me 

    2 replies

    Bromont_FTNT
    Staff
    Staff
    September 26, 2016

    When you edit your domain (Mail Settings ---> Domains) What do you have set under Advanced --> SMTP Greeting?

    Mohamed_kamal
    New Member
    September 26, 2016

    use system host name

    emnoc
    New Member
    September 27, 2016

    HELLO ( pun intended  )

    yes bu it MATCH your system-hostname of the  device doing the HELO?

     

    SOCKET1:~ kfelix$ host 41.38.52.75 75.52.38.41.in-addr.arpa domain name pointer mail.elashrygroup.com. SOCKET1:~ kfelix$ host -t a mail.elashrygroup.com. mail.elashrygroup.com has address 41.38.52.75 SOCKET1:~ kfelix$  

    DNS is one thing, but if the string in EHLO/HELO does not matched,  it looks like a forged SMTP connection  and  any ESA or MX-gw could drop the  connections.

     

     

    Ken

     

     

    Mohamed_kamal
    New Member
    September 27, 2016
    First whats wrong on dns ? how to match HELO on my system host ae ?
    emnoc
    New Member
    September 27, 2016

     

    1st does the cli   get system status | grep ostname

     

    does it match your above DNS name  { mail.elashrygroup.com } ? ( yes or no )

     

    2nd if no, than you need to set the "system" name in your protect domain as listed earlier when you start the thread

     

    3rd re-test

     

    4th monitor the FML logs for errors