How to Handle Reverse DNS Lookup for Specific IP Addresses on SMG
search cancel

How to Handle Reverse DNS Lookup for Specific IP Addresses on SMG

book

Article ID: 384488

calendar_today

Updated On:

Products

Messaging Gateway

Issue/Introduction

In some scenarios, administrators might want to bypass the reverse DNS lookup for a specific IP address when configuring their Symantec Messaging Gateway (SMG). Reverse DNS lookup is a common feature that ensures the connecting IP address resolves to a valid domain name, enhancing security by blocking suspicious or invalid connections. However, there may be cases where legitimate connections fail due to a lack of reverse DNS resolution, leading to a desire to bypass this feature for specific IPs.

Resolution

Unfortunately, it is not possible to selectively bypass reverse DNS lookup for a specific IP address on SMG. The reverse DNS lookup feature on SMG is designed to operate globally across all incoming connections. Therefore, administrators have two options to handle reverse DNS behavior:

  1. Enable Reverse DNS Lookup for All Connections Reverse DNS lookup can be enabled to reject connections from IP addresses that do not have a valid reverse DNS record. This option provides enhanced security but may block some legitimate connections if their reverse DNS configuration is incomplete or incorrect.

  2. Disable Reverse DNS Lookup Globally To disable reverse DNS lookup entirely, navigate to the following settings:

    • Go to Protocol > SMTP > Settings.

    • Uncheck the option labeled "Reject connections where no reverse DNS record exists for the connecting IP address". Disabling this setting will allow all connections, regardless of their reverse DNS status, but it may increase exposure to potentially malicious traffic.