This guide assumes reverse DNS (PTR) records is already deployed and passing. It covers what breaks at scale and how mature teams operate it.
Edge cases that break a working setup#
- Generic PTRs like 203-0-113-10.provider.net.
- HELO names that do not match the PTR.
- Mail forwarded through mailing lists or personal forwarders, which alters headers and content.
- Acquisitions and rebrands that introduce domains nobody audited.
- Vendors silently changing their sending infrastructure.
Operating it as infrastructure#
- Assign an owner for each sending domain and each vendor relationship.
- Put DNS records under version control or a change-review process.
- Alert on authentication pass rate drops and reputation changes, not just outages.
- Run a quarterly audit against the setup steps below.
- Document runbooks for the three most common failures.
Reference: the baseline setup#
- Ask your hosting or ESP provider to set a PTR for each sending IP.
- Use a hostname under your domain (mail1.example.com) rather than the provider's generic name.
- Create the matching A record so forward and reverse agree.
- Use the same hostname in the SMTP HELO/EHLO banner.
Frequently asked questions#
Can I set PTR records in my own DNS?
No. PTRs live in the IP owner's reverse zone. Your hosting provider or ESP sets them, though some offer self-service.