Suped

Summary

A full circle reverse DNS check, also known as Forward-Confirmed Reverse DNS (FCrDNS), is a critical mechanism in email deliverability. It serves as a strong signal of legitimacy for sending servers, helping to prevent spoofing and reduce spam. The core of this check involves a two-step DNS lookup process to ensure that the IP address sending an email is properly associated with the hostname it claims to be from. This validation process is distinct from other checks and plays a significant role in how recipient mail servers assess the trustworthiness of incoming messages.

What email marketers say

Email marketers often grapple with the technical nuances of DNS, and FCrDNS is no exception. While they may not always understand the intricate details of the lookup process, there's a general understanding that proper reverse DNS is a good indicator of a legitimate sender. However, questions often arise regarding the specific elements checked by receivers and the impact of subtle mismatches.

Marketer view

Marketer from Email Geeks asks whether a full circle reverse DNS check involves matching the EHLO hostname with the PTR record of the connecting IP, or if it looks up the A record of the EHLO and checks that against the PTR record. They acknowledge that this is a subtle but important distinction. The marketer also highlights the complexity of coordinating the timing for changes across the MTA hostname, A record, and PTR record, suggesting potential challenges in keeping all three elements synchronized for optimal email performance. This illustrates a common practical concern for those managing email infrastructure.

05 Jun 2020 - Email Geeks

Marketer view

Marketer from Email Geeks indicates that the specific implementation of FCrDNS checks can vary significantly among different receiving mail servers. Given this variability, their advice is to err on the side of caution. It is generally recommended to assume that all possible authentication checks are being performed by receivers. This approach ensures that senders configure their DNS records comprehensively, minimizing potential deliverability issues regardless of the receiver's specific validation process.

05 Jun 2020 - Email Geeks

What the experts say

Experts in email deliverability offer a nuanced view of full circle reverse DNS checks, clarifying its precise mechanism and distinguishing it from other email authentication steps. They emphasize that while FCrDNS is important, operational realities often introduce complexities like multiple DNS records and variations in receiver implementation. Their insights often focus on practical implications and how to interpret RFC guidelines.

Expert view

Expert from Email Geeks clarifies that when a receiver performs a full circle reverse DNS check, they typically do not rely on the EHLO hostname provided by the sending server. This specific part of the email conversation is generally separate from the FCrDNS validation process. The primary focus of FCrDNS is on verifying the IP address itself through its associated DNS records, rather than the self-declared hostname. This distinction is crucial for understanding how email authenticity is established.

05 Jun 2020 - Email Geeks

Expert view

Expert from Email Geeks confirms that a full circle DNS (FCrDNS) check begins with the IP address of the connecting server. From this IP, it performs a PTR record lookup to find the associated hostname. Following this, it performs a forward A record lookup on that hostname to ensure it resolves back to the original IP address. This two-step process forms the complete 'circle' of verification.

05 Jun 2020 - Email Geeks

What the documentation says

Technical documentation and RFCs formally define and recommend Forward-Confirmed Reverse DNS (FCrDNS) as a method for IP address authentication. These documents outline the specific lookup steps and the purpose of such checks in validating sender identity and combating email abuse. While they set the standards, they also provide guidance on the interpretation of terms like 'SHOULD' versus 'MUST' when configuring systems.

Technical article

Documentation from Spiceworks Community provides a clear definition of Forward-Confirmed Reverse DNS (FCrDNS), stating that it is a networking parameter widely recognized by several other names, including full-circle reverse DNS, double-reverse DNS, and iprev. This indicates its multifaceted role and common understanding within the networking community. The core function, as highlighted, is to verify the authenticity of an IP address in relation to its claimed hostname. This foundational check is crucial for various network services, particularly email, where source validation is paramount for security and trust.

12 Feb 2023 - Spiceworks Community

Technical article

Documentation from ManageEngine OpUtils outlines the scenarios where reverse lookup zones are critically employed. These zones are primarily used by network administrators to trace the origins of incoming network traffic, which is essential for security auditing and troubleshooting. By translating IP addresses back into hostnames, administrators can identify potential sources of malicious activity or simply understand legitimate traffic patterns. This functionality underscores the importance of reverse DNS in network management and cybersecurity efforts.

25 Jan 2023 - ManageEngine OpUtils

7 resources

Start improving your email deliverability today

Get started