How DNSSEC impacts message delivery in Symantec Messaging Gateway?
search cancel

How DNSSEC impacts message delivery in Symantec Messaging Gateway?

book

Article ID: 398658

calendar_today

Updated On:

Products

Messaging Gateway

Issue/Introduction

Understand how enabling DNSSEC changes the way SMG interacts with DNS servers during email processing.

Resolution

 

  • Enhanced DNS Queries: SMG requests DNSSEC-specific records (RRSIG, DNSKEY) alongside standard ones.

  • Validation Behavior: SMG attempts to validate responses if DNSSEC data is present.

    • Success ➝ Message is delivered.

    • Failure ➝ Message remain in the delivery queue with the SMTP response code "421 4.4.4 [internal] domain does not resolve".

  • Non-DNSSEC Domains: If no DNSSEC data exists, SMG proceeds with standard DNS resolution.