|Situation||Spam domains will often not have a proper A/MX record configured on their DNS. Proofpoint performs additional checks to stop this type of email. If you are not receiving messages from a legitimate domain with incorrectly configured DNS records, this may be the reason.|
|Solution||This article provides an overview of what the Inbound Sender DNS check option will test for, as well as how to enable/disable the option from the Company Spam Settings.|
What is inbound Sender DNS check?
The Inbound sender DNS check option provides an additional layer of protection against spam and helps ensure that inbound messages that might not have a destination to bounce to are not allowed in. The proper step to address this is to get the sender to properly format their messages (i.e. fix the sender's domain to have a proper A/MX record), but the specific reason this feature was implemented was to allow a way to have such messages be delivered.
What checks does it perform?
Specifically, Inbound sender DNS check is a little used option that essentially turns on the sender domain validity DNS checks we perform on Inbound email. This involves two checks.
- Whether the sender domain has MX records. In other words, a check whether the email is "bounceable" and able to be returned to a sender should it be necessary later. Our MTA structure states that the request will get rejected if the MAIL FROM domain has:
- No DNS A or MX record, or
- A malformed MX record such as a record with a zero-length MX hostname.
- Whether the sender domain doesn't contain MX records pointing to private or reserved IP ranges like 10.0.0.0/8, 127.0.0.0/8 etc. If the email creator designs a recipient address that will get bounced, and configures the sender domain MX possibly under his control with an IP address of an internal network resource, the email can be made to flow outside of its intended course (or sit stuck in an internal queue and not be able to go anywhere)
How to enable/disable
- Go to Company Settings > Spam.
- Uncheck/Check the box labeled Inbound Sender DNS Check.
- Click Save at the bottom of the page.
If you want to apply this change to all users, make sure to check the option Update spam detection settings above for all existing user accounts before clicking save.