Although I could not run the analyzer internally because my router would not route back to itself, I did have them run it and send the report (attached) As far as I know everything works here.  My questions about their errors are as follows

1)Non-authoritative data received from the server "dns.wwnet.net." (full error below)

     Q- how do I fix this?

This could mean nothing but that the response was cached but it can also mean your DNS is listed at the "authority" for the domain, but the SOA record was not found our your DNS. 

2)) The primary mail server "wwwserver.apratech.org." can possibly be used as a mail relay...(full error below)

gotta fix this.  controlpanel:imail:smtpsecurity:relay for:<your choice>

    Q- I only want to relay mail for the domains that I host, is "Relay mail for Local Hosts" the correct choice. Will this be transparent to the users? (I feel naked with this one)

relay for ip addresses is probably the most common choice, then your roaming users (running POP3 access when then are not logged in to your ip addresses) will have to set SMTP AUTH in their mail clients.

3) There is no PTR record for the host "apra.org." (full error below)

    Q- NT's DNS manager makes no mention of PTR records, except that when creating an 'A' record there is a checkbox that says "update associated PTR record" which is checked. How do I fix this, or do I care?

you care, at least for your Imail servers PTR record, so that other mail servers who do reverse lookups find your mail server and then will accept mail from you.  To fix it, you need to talk to your upstream, have him do the reverse for you, or have him delegate your reverse to you, and you do it yourself.

MS DNS allows zone transfers, which is not prudent in this paranoid age.

Use BIND 8, go back to being fat and happy, but not so dumb!!! vbg

ISC's BIND effort received a contribution of BIND 8.8.2 for NT from Nortel.  You can get the binary, patch5, from: ftp://ns4.netpacq.net

www.ISC.org for an excellent mailing list, docs, hints, links.

also www.AcmeBW.com.

Also need to get the bible:  DNS & BIND, 3rd ed., O'Reilly, the "cricket" book. 
======================

----------------------------------------------------------------------

o There is just one NS record in the zone

When the domain was registered, it had to have 2 DNS's, as is now found in the root-servers.  What happened to the second one?  These DNS have to have NS RR's in the zone file. 

o There is only one MX record in the zone

Many zones are like this (see my msg of today to European Imail users who want to provie each other with secondary DNS and MX)

Len

Reply via email to