IronPort DNS Hard Error Lookup (Emails Bouncing)

Hi,
One of our clients running Cisco IronPort ESA is having a challenge sending mails to some local domains (e.g. recipient.co.ke - sample non-existent domain) and keeps getting the error below:
#< #5.0.0 smtp; 5.1.2 - Bad destination host 'DNS Hard Error looking up recipient.co.ke (MX): NXDomain' (delivery attempts: 0)> #SMTP#
Mails to other domains such as gmail.com & yahoo.com are working just fine.
Doing a dnsflush on the ESA temporarily solves the problem but it keeps recurring. Note that the client is able to receive mails from the same domains they can't send to.
The ESA appliance is able to do nslookups to the same domains.
Has anybody else experienced this challenge and how did you solve it?
Regards,
Emmon.

Check whether you're using a local DNS server or already on root dns server.
VIA GUI
GUI > Network > DNS
Click on the radio button to use internet root DNS servers.
VIA CLI:
C370.lab> dnsconfig
Currently using the local DNS cache servers:
1. Priority: 0 1.1.1.8
Choose the operation you want to perform:
- NEW - Add a new server.
- EDIT - Edit a server.
- DELETE - Remove a server.
- SETUP - Configure general settings.
[]> delete
Do you want to delete a local DNS cache server or an alternate domain server?
1. Delete a local DNS cache server.
2. Delete an alternate domain server.
[]> 1
Currently using the local DNS cache servers:
1. Priority: 0 1.1.1.8
Enter the number of the server you wish to remove.
[]> 1
Note: You have removed the last local nameserver entry. DNS will now use the
Internet root servers.
Currently using the Internet root DNS servers.
No alternate authoritative servers configured.
Choose the operation you want to perform:
- NEW - Add a new server.
- SETUP - Configure general settings.
Then commit the changes if you decide to move to Root DNS.
To check the domain's DNS records (or in your case MX records)
Use the command line.
CLI > nslookup xxx.co.jp mx
It will show you results if any DNS records can be found.
C370.lab> nslookup cisco.com mx
MX=alln-mx-01.cisco.com PREF=10 TTL=1d
MX=rcdn-mx-01.cisco.com PREF=20 TTL=1d
MX=aer-mx-01.cisco.com PREF=30 TTL=1d

Similar Messages

  • Critical: LDAP: query DNS result DNS Hard Error looking up e

    I am not having any luck when trying to connect to all 3 of our LDAP Servers...I get this error in the logs:
    Critical: LDAP: query DNS result DNS Hard Error looking up MyServer.Mydomain.com (A): NXDomain
    It is open through our Firewalls. I don't even see the Test Query reach our Firewalls...any suggestions what I am doing wrong?
    We were using Surfcontrol and it worked fine... :?:

    In Surfcontrol I put the IP without the DN and the query returns all the users.
    In IronPort when I put the IP without the DN and do an Accept query using my email address in the Recipient Address I get the above error.

  • DNS refused Error in Failover cluster !!!

    Cluster network name resource 'Cluster Name' failed registration of one or more associated DNS name(s) for the following reason:
    DNS operation refused.
    Ensure that the network adapters associated with dependent IP address resources are configured with at least one accessible DNS server.
    Not sure, What is the issue here? All of a sudden getting error in my cluster. My DNS settings are looks OK.

    Hi Karthikeyan R – FGS,
    Could you offer us your cluster event ID and original error message, or you can enable the DNS debug log and filter your cluster VIP to get the DNS register error. Please confirm
    you are using the enough permission account when you create your cluster, the detail permission require you can refer the following KB:
    The related KB:
    Using server debug logging options
    http://technet.microsoft.com/en-us/library/cc776361(v=ws.10).aspx
    Failover Cluster Step-by-Step Guide: Configuring Accounts in Active Directory
    http://technet.microsoft.com/en-us/library/cc731002(v=ws.10).aspx
    I’m glad to be of help to you!
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • [CUP 5.3] Error while email validation

    Hello all,
    Anyone seen this before in CUP 5.3 SP15?
    I have an access request form in which I allow user lookup. The user lookup is linked with an SAP HR system.
    When I search users on name, only the users that have an emailaddress filled in in the infotypes show up in my list. Users without an emailaddress are not shown. I can only get them in my search results when I specifically search for them on user ID.
    When I then select the user without emailaddress and insert him/her into my access request form, I always receive the "error creating request" message. The log tells me:
    2011-09-20 15:29:28,326 [SAPEngine_Application_Thread[impl:3]_24] ERROR  EUCreateRequestAction.java@224:loadHandler() : Error while email validation = E-mail address
    Users with an emailaddress are no problem.
    Even when I fill in an emailaddress manually, CUP apparently keeps using the emailaddress from the infotype.
    Anyone know how to resolve this?
    Thanks in advance,
    Edited by: Lanssens Tom on Sep 20, 2011 6:09 PM (spelling)

    Hello Srihari,
    User Email Address is a Mandatory field which cannot be changed. The only option to change is to turn off "Editable". However, if I do that I receive the warning "It is better to make the field editable, because the end user cannot submit the request, if the field value is not available in the user's data source".
    I know that the best solution/workaround is to make sure that all users in the HR list have an emailaddress, so we are going to follow up on this with a script. Still, I would like to know why I can't find nor work with users that don't have an emailaddress, and why I can't update their emailaddress myself manually via the CUP.
    Best regards,
    Tom

  • Hard error for non PO duplicate invoice

    Hi,
    In FB60 for a non PO invoice, how can we restrict the duplicate invoice through reference number for different date and amounts. How can I create a hard error when the user posts a duplicate invoice for different amount and date. Right now the hard error is appearing for the reference num, same date and same amount.
    I wanted to create a z function module and tag it to 1110 fucntion module in FIBF Tcode. But can anybody advice if any standard SAP process is available.
    Thanks,
    Vardhan.

    No standard feature.
    You can use the mentioned BTE in FIBF or a validation in GGB0/ OB28
    Regards,
    Gaurav

  • Material shortage ( soft or hard error ) while releasing production order?

    Hi Guys
    I  am a SAP tech guy wrote a BDC program to release production order. It worked fine in one enviroment but not working another enviroment saying ..Material shortage.
    My BDC program can't afford any hard errors in the process. The execution stop abruptly for any hard error.
    How to change that Material shortage from hard error to soft error or any info message.
    Any ideas? any thing to do with material master or spro?
    Thanks
    Hari

    Hi
    You can make settings in SPRO, so that the material availability check will not restrict you to go further...
    follow the path:
    SPRO>Production->Shop floor control>Operations->Availability Check-->Scope of check
    There you will find the settings for order creation and release (1 & 2)..
    You have remove the restriction there.
    Regards
    Bala

  • Error when email enabling a document library

    Hi - I've checked through other threads re errors when email enabling a doc library, but our scenario is a bit different. We have some custom code that creates sites based on a site template and uses data from a 3rd party system to define the site
    name, permissions etc. I don't think that the process for creating the sites is relevant to the issue, but mentioning that anyway to be complete. As part of the site creation workflow, one of the document libraries is email enabled. However, on one specific
    site, the document library was not email enabled. When I try and do this manually, I get the following error:
    Error in the application.   at
    Microsoft.SharePoint.SPList.UpdateDirectoryManagementService(String oldAlias,
    String newAlias)
       at Microsoft.SharePoint.SPList.Update(Boolean
    bFromMigration)
       at Microsoft.SharePoint.SPList.Update()
       at
    Microsoft.SharePoint.ApplicationPages.EmailSettingsPage.SubmitButton_Click(Object
    sender, EventArgs args)
       at
    System.Web.UI.WebControls.Button.OnClick(EventArgs e)
       at
    System.Web.UI.WebControls.Button.RaisePostBackEvent(String eventArgument)
       at System.Web.UI.Page.RaisePostBackEvent(IPostBackEventHandler
    sourceControl, String eventArgument)
       at
    System.Web.UI.Page.ProcessRequestMain(Boolean includeStagesBeforeAsyncPoint,
    Boolean includeStagesAfterAsyncPoint)
    Other tests/observations:
    On the problem site, I get the same error when trying to email enable other document libraries
    Other sites on the same site collection have been created using the same process/site template, and the appropriate document library was email enabled automatically (sites created both before and subsequent to this problem site)
    I have successfully managed to manually email enable a document library on an different existing site
    I have manually created a new site using the same site template and successfully managed to manually email enable a document library on that site
    So I am fairly certain that it is nothing to do with permissions as other posts relating to this issue have suggested. Does anyone have any ideas on what is happening, how to resolve or further checks I can make? Many thanks

    Hi qaaweb,
    based on my experience, the issue itself may be caused by some triggers, 
    the permission is one of them only, 
    to narrow down usually, we try to update credential first, that at some environment may less impact.
    example:
    based on: http://technet.microsoft.com/en-us/library/cc262947.aspx, to configure email, if already configured then skip.
    make sure that application pool account that is used for central admin to be the same for central admin, site and the web application.
    make sure SQL server and granted DBCreator , Serveradmin, Setupadmin on service account. 
    remove old database and sync:
    C:\program files\common files\Microsoft shared\web server extensions\12\bin>stsadm -o sync -listolddatabases 0
    C:\program files\common files\Microsoft shared\web server extensions\12\bin>stsadm -o sync -deleteolddatabases 0
    Update farm credentials, http://support.microsoft.com/kb/934838 
    if needed: central administration > Operation > Authentication provider and changed Kerberos to NTLM on central admin site.
    Login service account on the SharePoint server and enable IncomingEmail settings on the web application 
    please let us know if the workaround is not applicable
    Regards,
    Aries
    Microsoft Online Community Support
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

  • Unknown Hard Error when installing Windows XP?

    Ok first off I tried installing Windows Vista Home Premium on my new 24in iMac and after installation had problems installing drivers. Found out it was because I had a 64 bit version of Vista and the iMacs dont support that. Then I got a copy of XP Home Service Pack 3 from a friend to try. Im not sure if it is 32 or 64 bit but I was going to try it anyways. Its starts to extract the files and get ready for the install but not long after it does that it gives me an unknown error and the blue screen of death.
    "STOP: c0000221 Unknown Hard Error
    \SystemRoot\System32\ntdll.dll"
    Does anyone know what this means? I would really like to get one of them installed. I dont care which one...if anyone knows how I can put a 64bit version of Vista on my iMac that would probably be best since it installed fine and just messed up when installing the drivers. Otherwise can anyone tell me what to do about this unknown error? Or do I need to search around for yet another operating system cd?
    Any help will be greatly appreciated.

    Hi KadeP,
    there is indeed not a solution for that CD-problem, since you are getting it when installing from the CD not after the installation, when there is a problem with that specific file on your harddisk.
    So, apart from the checking of the CD for physical problems (dirt, dust, scratches) the only other solution would be the use of another CD and maybe doing a full disc-copy of that CD onto a CD-R or CD-RW and hoping the best.
    As for the Vista procedures the hatter described, all these has to be done before even installing Vista and also on a Windows PC.
    The outcome of that would be a modified Vista Installation DVD, which seems to be installing even on iMacs not really supported.
    Since I don't have Vista I never tried it myself, though.
    But the hatter is 'our local Vista/Windows 7 genius'
    As for the 'old XP CD' you found:
    such behaviour/error is usually a sign that the XP CD is not at Service Pack level 2 (SP2) which is a must for XP CDs.
    However, you can use these instructions http://www.winsupersite.com/showcase/windowsxpsp2slipstream.asp to 'slipstream' yourself a XP SP2 installation CD.
    But again, you have to do it on a running Windows PC.
    Regards
    Stefan

  • Sending photos from iphone, email bounces every time.

    When I got iLife 08 last week and published my gallery, everything worked fine including sending photos from my iPhone, and they would show up on my gallery. For the last two days when I tried to send a new photo from my iPhone to my web gallery I get an email that bounces back and says...
    "...Relaying denied, try authenticating"
    All other mail sends fine, but from my iPhone sending directly to my webgallery it won't work. How might I fix this?
    Thank you.

    I've come across with the same problem. It worked up until the last two days. Now when I try to send an email to my web gallery to update a photo from my iPhone I also get an email bouncing back saying "...relaying denied, try authenticating..."
    I made no changes to my web gallery prior to this happening.
    I deleted the existing gallery and created a new gallery. I get the same response when trying to upload an email from my iPhone.

  • Is it possible to change warning "& is marked for deletion" to a hard error

    As part of our periodic update of our bank directory in transaction BAUP, Bank Keys which are no longer valid are marked for deletion. We are not at the point where we are archiving records yet, so the actual deletion has not occurred in our system.
    When an HR user updates a person's bank information (transaction PA20 or PA30, InfoType 09), if they enter one of these bank keys, they are given a warning that the bank key is marked for deletion. However, this is not a hard stop, only a warning message. As a result, they are able to save the record with an invalid bank key. The details indicate that this is message class F4, message 230. However, it appears from the IMG that it may be message 210. I have tried working with each of them.
    I have attempted to change the message to a hard error in message control, but have not been able to do so.  I receive an error telling me that "Message 230 (or 210) is not allowed". I have tried several application areas, including FV, Electronic Banking Messages.
    Is there any way in configuration to change this to a hard error? If so, please supply details, including application area.
    Also, are there risks of disruption of standard business processes if we do change this to a hard error? I know that this same message is issued for other master data elements which are marked for deletion such as GL accounts or Customer records,
    Thank you.
    I have searched forums with terms "marked for deletion" and "warning" but have not found an answer. I have also searched various outside expert forums on this topic. Everything I have seen seems to assume that this message will be a warning only.
    Aoife B.
    Edited by: Aoife Bratton on Oct 16, 2008 4:16 PM
    Edited by: Aoife Bratton on Oct 16, 2008 4:16 PM

    If particular message is not allowed in OBA5, then it is not configurable message. Neverthless if you like to change this message, you need to configure this in OBMSG first

  • How do I remove a DNS Solution Error?  Sometimes when I do a search using a Firefox browser, this message comes up and it doesn't take me to the site I am looking for.

    Sometimes I use Firefox for browsing and when I do a search,  the search engine will not take me to the site but I get a message that says "DNS Solution Error".
    I believe it is some kind of malware.  I appreciate any help from anyone who knows how to fix it.

    You may have installed a malicious or defective Firefox extension. Remove all extensions that you don't know you need. If in doubt, remove all of them. Otherwise, check the Firefox network settings (not the Network pane in System Preferences) for a proxy server.

  • Unknown Hard Error when reformatting. Please help.

    Hi, I was going to reformat my HD but got the following error after I inserted the Recovery CD into my CD Rom.
    STOP: 0xC0000221 unknown hard error
    C:\Winnt\System32\Ntdll.dll
    Error 0X 80070456: The media in the drive may have changed PREIN ST6.SWM
    Could someone kindly help me please?  Is it safe to abort now?
    Thanks.

    Hi KadeP,
    there is indeed not a solution for that CD-problem, since you are getting it when installing from the CD not after the installation, when there is a problem with that specific file on your harddisk.
    So, apart from the checking of the CD for physical problems (dirt, dust, scratches) the only other solution would be the use of another CD and maybe doing a full disc-copy of that CD onto a CD-R or CD-RW and hoping the best.
    As for the Vista procedures the hatter described, all these has to be done before even installing Vista and also on a Windows PC.
    The outcome of that would be a modified Vista Installation DVD, which seems to be installing even on iMacs not really supported.
    Since I don't have Vista I never tried it myself, though.
    But the hatter is 'our local Vista/Windows 7 genius'
    As for the 'old XP CD' you found:
    such behaviour/error is usually a sign that the XP CD is not at Service Pack level 2 (SP2) which is a must for XP CDs.
    However, you can use these instructions http://www.winsupersite.com/showcase/windowsxpsp2slipstream.asp to 'slipstream' yourself a XP SP2 installation CD.
    But again, you have to do it on a running Windows PC.
    Regards
    Stefan

  • Importer Error lookup help

    Hello, Can some one help me understand what i could be missing
    We are on 12.1.3
    In the importer setup for Standard PO, I have defined
    1. Group has been defined
    2. Attribute mapping has been defined
    3. Concurrent program is set to - Synchronous call to "Import Standard Purchase Orders"
    4. Error row definition is set to point to a custom view after tying to interface error table
    5. Error lookup obtains the value of error_message from the interface table (while this is totally unnecessary but I still have to obtain the single value from interface error table again)
    Am getting the following error
    bne:text="The import program could not be started.  Contact your system administrator." bne:cause="Parameter 1 of the SQL import step parameter List 201:XXPO_CRTPO_ERRL must have a value in attribute 2 for RETURN parameters."
    I would like to know if I have to specifically define any out parameter and where I should define it.
    Appreciate an early response.
    Md

    Hi,
    I have overcome the perivous error and now i'm facing the new error in Error Looup message with these errors
    An error has occurred while running an API import. 231:TEST_IMPORTER_ERRL
    SQL statement returned no rows when values are expected.
    My setups are
    select meaning FROM FND_LOOKUPS WHERE LOOKUP_TYPE ='XX_TEST_ERROR' AND LOOKUP_CODE =$PARAM$.RESULT
    Parameter Name   Reference Name Data type  source    value
    RESULT                RESULT              VARCHAR2  Interface Table   XX_TEST_IMPR_INTERFACE.RESULT
    Any clue what i'm missing.
    Thanks
    Suresh.

  • Check Email Bounce Back

    Hi Experts,
    My client needs to check if an email bounces back to the SAP inbox. The email is sent using the function module 'SO_DOCUMENT_SEND_API1'. Is there any way to do this?
    Thanks and regards,
    Vishal.

    Normally the mails will be sent out by SCOT program. Hence you don't have a control in your program whether the mail will bounce or not?
    If any failure happens the mail status will be updated in user's outbox folder.
    You need to check whether the sent mail status is success or not, if failure then take an action.
    For this you need write a program to read the user's mails status.
    Regds
    Manohar

  • Error NtpClient was unable to set a manual peer. DNS resolution error When using IP address.

    Hya,
    We have been migarting to some new DCs. one of the new DCs now has all the master roles call it DC01.
    when I try and sync/setup NTP on this server as the the authoritive NTP in the doamin I get:
    NtpClient was unable to set a manual peer to use as a time source because of DNS resolution error on '”10.*.*.*,0x1”'. NtpClient will try again in 15 minutes and double the reattempt interval thereafter. The error was: No such host is known. (0x80072AF9)
    I am using the following commands to set NTP up on the server.
    >net stop w32time
    >w32tm /config /syncfromflags:manual /manualpeerlist:"10.*.*.*,0x1"
    >w32tm /config /reliable:yes
    >net start w32time.
    Is anyone aware of what the issue could be?
    Ps one of the old dc can still sync to this site manually if tried.
    cheers Mike

    Hi,
    First make sure your DNS is working properly, then please try this article below:
    Event ID 134 — Manual Time Source Acquisition
    http://technet.microsoft.com/en-us/library/cc756393(v=ws.10).aspx
    Hope this helps.

Maybe you are looking for