Set reverse DNS for your server

What reverse DNS (PTR) records are, when you need one, how to set one in the panel or with vps9, and how to check it with dig.

Forward DNS turns a name into an address: mail.example.com to 203.0.113.42. Reverse DNS goes the other way, from 203.0.113.42 back to a name, using a PTR record. You set forward records wherever your domain's DNS lives. Reverse records belong to whoever owns the IP address, and for your server that's us, so it's set through VPSNine.

When you need it

You need it if you send email from the server. Plenty of mail servers reject or junk mail from an address with no reverse DNS, or whose reverse name doesn't point back to the same address. Set it before you send anything, and read Sending email: port 25 too.

It's also nice in logs and traceroute output, where a name is easier to recognise than a number. For a plain web server, though, you can skip it.

Create the forward record first

The reverse record should match a forward one, so start there. At your DNS provider:

text
mail.example.com.  A     203.0.113.42
mail.example.com.  AAAA  2001:db8:9::2

Check it from your computer:

bash
dig +short mail.example.com A

It has to return your server's address before you go on.

Set the reverse record

In the panel, open the server and choose reverse dns. There's a box for the server's IPv4 address and another for its IPv6 address, if it has one. Type the name and press set reverse dns.

With the vps9 CLI, it's one command per address:

bash
vps9 rdns web-1 set 203.0.113.42 mail.example.com
vps9 rdns web-1 set 2001:db8:9::2 mail.example.com

Before we accept the name, we look it up and check that it points to that address: the A record for the IPv4 address, AAAA for IPv6. If the name has no such record, points somewhere else, or doesn't answer within 3 seconds, you get a message saying which, and nothing changes. Fix the forward record, give it a minute, and try again.

Reverse records are set by hand for now. A request shows as requested, waiting to be set until it's done, usually within a working day, and then as live. To take a name off, press clear in the panel or run vps9 rdns web-1 rm 203.0.113.42. It shows as being removed until we've reset it.

You get ten tries an hour across your account. Clears count, and so do tries the forward check refuses. When you delete a server, we reset its reverse DNS before its addresses go to anyone else.

Check it

bash
dig +short -x 203.0.113.42
dig +short -x 2001:db8:9::2

Once the panel says live, each should print mail.example.com., trailing dot included. Resolvers can hang on to the old answer for up to the record's TTL.

Then close the loop:

bash
dig +short mail.example.com A

That should give back the same address you started with. Mail servers call this forward-confirmed reverse DNS, and it's what they actually check.

If dig -x still shows nothing or the old name, your resolver has it cached; wait out the TTL. If the reverse name doesn't resolve back, the forward A or AAAA record is the one to fix. If a request is still waiting after a working day, or shows failed, open a support ticket with the address.

Be first when orders open

Join the waitlist and we'll send you one email when VPSNine launches. Pick a plan if you already know which one you want, and we'll size the first servers around it.