Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Mohamed_kamal
New Contributor

DNS issue

i have fortimail 200d and fortigate 200D

when i send any mail replay me postmaster is (reason: 550 *** The HELO for IP address 41.38.52.75 was '[41.38.52.75]' (valid but not recommended syntax )

i contact with senderbase team to know why added my IP to blacklist and replay me that 

To this end, we are seeing reports of HELO strings which do not match the PTR / rDNS of the IP. One of the HELO string we are seeing  “[41.38.52.75]”  which is not exact matches to the PTR of the IP 41.38.52.75  (mail.elashrygroup.com).

how to resolve ip to HELO  ? 

please  help me 

41 REPLIES 41
Bromont_FTNT
Staff
Staff

When you edit your domain (Mail Settings ---> Domains) What do you have set under Advanced --> SMTP Greeting?

Mohamed_kamal

use system host name

ede_pfau

It looks like your DNS is not set up correctly.

 

When creating a A record ('mail.bla.com  1.2.3.4') a PTR record is required for reverse lookup ('1.2.3.4 -> mail.bla.com'). The reverse zone is named '3.2.1.in-addr.arpa' and contains one PTR record for each A record in use. Could you check into that direction?


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Mohamed_kamal

A Record & PTR Record thats right 

IP 41.38.52.75

mail.elashrygroyp.com

could you check again if any error ?

emnoc
Esteemed Contributor III

Agreed you HELLO string does not match, check in your domain setup. If you  HELLO string does not match the  DNS lookup most ESA will drop the connect.

 

 

FWIW the forward and A and PTR is not  your problem in  this case. 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Mohamed_kamal

can you tell me hot to setup HELLO on my domain ?

Bromont_FTNT

Is your Fortimail set up in gateway or transparent mode?

emnoc
Esteemed Contributor III

You have a system name set for the unit in the initial configuration but for each mail-protect domain you can use the system hostname in the extended hello or set the one you want. Regardless it needs a proper  DNS entry.

 

e.g ( see under my protected domain  in this jpg )

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Mohamed_kamal

i check mark use host name

Labels
Top Kudoed Authors