====== MX Records (Mail Exchanger) ======
A **Mail Exchanger (MX) Record** is a type of Resource Record in the Domain Name System (DNS) that specifies the mail server responsible for accepting email messages on behalf of a domain name.
Without valid MX records, sending servers cannot locate your mail infrastructure, causing incoming emails to bounce or fail delivery.
----
===== How MX Records Work =====
When someone sends an email to ''user@example.com'', the sender's mail transfer agent (MTA) performs the following steps:
# **DNS Lookup:** Queries DNS for the ''MX'' records associated with ''example.com''.
# **Priority Resolution:** Sorts the returned MX hostnames by their preference (priority) number.
# **A/AAAA Lookup:** Resolves the primary MX hostname to an IP address (''A'' or ''AAAA'' record).
# **SMTP Connection:** Attempts an SMTP connection to the primary mail server on port ''25''. If the primary server is unreachable, it attempts to connect to secondary backup servers in order of priority.
----
===== MX Record Structure & Parameters =====
An MX record consists of three core components:
^ Component ^ Value Example ^ Description ^
| **Name / Host** | ''@'' or ''example.com'' | The domain name receiving the email. |
| **Preference / Priority** | ''10'' | Integer value indicating server priority (lower numbers = higher priority). |
| **Mail Server / Target** | ''mail.example.com'' | The Fully Qualified Domain Name (FQDN) of the mail server. |
> **Crucial Rule:** The target of an MX record **MUST** point to a valid domain name (''A'' or ''AAAA'' record). It **must never** point directly to an IP address or a ''CNAME'' alias.
----
===== MX Record Priority Explained =====
Priorities allow domain administrators to set up primary and backup fallback mail servers.
Priority 10 : mail1.example.com <-- Primary Mail Server (Tried First)
Priority 20 : mail2.example.com <-- Secondary / Backup Server (Tried if Priority 10 fails)
* **Equal Priorities:** If multiple servers share the same priority (e.g., two servers with priority ''10''), incoming mail load is distributed between them (round-robin / load balancing).
* **Lower Number = Higher Preference:** Priority ''5'' takes precedence over Priority ''10''.
----
===== Example Configurations =====
==== Example 1: Standard Self-Hosted Mail Server ====
^ Record Type ^ Host ^ Priority ^ Value / Target ^ TTL ^
| **MX** | ''@'' | 10 | ''mail.example.com.'' | 3600 |
| **A** | ''mail'' | — | ''192.0.2.25'' | 3600 |
==== Example 2: Google Workspace Configuration ====
^ Record Type ^ Host ^ Priority ^ Value / Target ^ TTL ^
| **MX** | ''@'' | 1 | ''SMTP.GOOGLE.COM.'' | 3600 |
----
===== Common Issues & Troubleshooting =====
==== 1. Pointing MX Records to CNAMEs ====
Pointing an MX record to a target that is a CNAME alias violates [[https://datatracker.ietf.org/doc/html/rfc2181|RFC 2181 (Section 10.3)]] and can lead to unpredictable mail loop errors or bounced emails.
==== 2. Pointing MX Records directly to IP Addresses ====
MX records require an FQDN as their target. Pointing directly to an IPv4/IPv6 address will cause syntax validation failures across major mail servers.
==== 3. Missing Trailing Dot (in Raw Zone Files) ====
In raw DNS zone files, failing to append a trailing dot (''mail.example.com.'') may cause DNS servers to append the root domain twice (''mail.example.com.example.com'').
----
===== Verification & Testing =====
You can test and verify your MX records using **Telenegar Tools** or terminal commands:
==== Using Telenegar Tools ====
* **DNS Resolution:** Check MX lookup propagation with the [[tools:dnscheck|Telenegar DNS Check Tool]].
* **Mail Server Health:** Run a complete deliverability scan with the [[tools:mailcheck|Telenegar Mail Check Tool]].
==== Using Terminal Tools ====
=== dig (Linux / macOS) ===
bash
dig +short example.com MX
=== nslookup (Windows / Cross-platform) ===
cmd
nslookup -type=MX example.com
----
===== Related Documentation =====
* [[tools:dnscheck|Telenegar DNS Check Tool]] — Diagnostic tool for DNS record resolution and propagation.
* [[tools:mailcheck|Telenegar Mail Check Tool]] — Diagnostic tool for email authentication and mail server health.
* [[email:dns-configuration:spf|SPF (Sender Policy Framework)]] — Protect your domain against email spoofing.
* [[email:dns-configuration:dkim|DKIM (DomainKeys Identified Mail)]] — Add cryptographic signatures to outbound emails.
* [[email:dns-configuration:dmarc|DMARC]] — Define policy rules for SPF and DKIM alignment.
* [[networking:dns:reverse-dns|Reverse DNS (PTR Records)]] — Map mail server IP addresses back to domain names.