Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Mohamed_kamal
New Contributor

DNS issue

i have fortimail 200d and fortigate 200D

when i send any mail replay me postmaster is (reason: 550 *** The HELO for IP address 41.38.52.75 was '[41.38.52.75]' (valid but not recommended syntax )

i contact with senderbase team to know why added my IP to blacklist and replay me that 

To this end, we are seeing reports of HELO strings which do not match the PTR / rDNS of the IP. One of the HELO string we are seeing  “[41.38.52.75]”  which is not exact matches to the PTR of the IP 41.38.52.75  (mail.elashrygroup.com).

how to resolve ip to HELO  ? 

please  help me 

41 REPLIES 41
Mohamed_kamal

yes dns is mail.elashrygroup.com and no error logs if spf record is wrong making this error or no i need to match HELO or resolve ip to HELO name
Bromont_FTNT

for the telnet test try:

exe telnet  alt1.gmail-smtp-in.l.google.com:25

 

then type 

ehlo mail.elashrygroup.com

Mohamed_kamal

parsing error
emnoc
Esteemed Contributor III

This t-shooting 101, but here  the 2x types of hello ( normal and extended  aka EHLO )

 

Your hostname present needs to match  DNS. if that matches, than you can go down the list of the next items;

 

 

[ul]
  • SPF
  • greylisting issues
  • are your BLACKLISTED [/ul]

    http://socpuppet.blogspot...ng-blocked-on-rbl.html

     

     

     

  • PCNSE 

    NSE 

    StrongSwan  

    PCNSE NSE StrongSwan
    emnoc
    Esteemed Contributor III

    FWIW, your not on any  common RBLs

     

    http://www.anti-abuse.org/multi-rbl-check-results/?host=mail.elashrygroup.com

     

     

    PCNSE 

    NSE 

    StrongSwan  

    PCNSE NSE StrongSwan
    Mohamed_kamal

    how to create best spf record ? another question : how to make mta match HELO ? i'm not blacklisting and greylist
    Mohamed_kamal

    how to create best SPF record ?

    Bromont_FTNT

    SPF record is a TXT entry in DNS for your domain. 

     

    According to your config your MTA helo/ehlo looks ok.... 

     

    Are you sure you can't run:

    exec telnet  alt1.gmail-smtp-in.l.google.com:25

    and:

    ehlo mail.elashrygroup.com

     

    Would like to see the results of the above command.

    Mohamed_kamal

    gmail is 

    421 service not available (connection refused, too many connections)
     
    Entering interactive mode. Type CTRL-D to exit.
    Connection closed.
     
    Connection status to alt1.gmail-smtp-in.l.google.com port 25:
    	Connecting to remote host succeeded.

    Mohamed_kamal

    421 error  appeared with mails  at tab mail queue 

     

    Labels
    Top Kudoed Authors