User Tools

Site Tools


email:dns-configuration:mx-records

This is an old revision of the document!


# MX Records (Mail Exchanger)

A Mail Exchanger (MX) Record is a type of Resource Record in the Domain Name System (DNS) that specifies the mail server responsible for accepting email messages on behalf of a domain name.

Without valid MX records, sending servers cannot locate your mail infrastructure, causing incoming emails to bounce or fail delivery.

## How MX Records Work

When someone sends an email to `user@example.com`, the sender's mail transfer agent (MTA) performs the following steps:

1. DNS Lookup: Queries DNS for the `MX` records associated with `example.com`. 2. Priority Resolution: Sorts the returned MX hostnames by their preference (priority) number. 3. A/AAAA Lookup: Resolves the primary MX hostname to an IP address (`A` or `AAAA` record). 4. SMTP Connection: Attempts an SMTP connection to the primary mail server on port `25`. If the primary server is unreachable, it attempts to connect to secondary backup servers in order of priority.

## MX Record Structure & Parameters

An MX record consists of three core components:

Component Value Example Description
:— :— :—
Name / Host `@` or `example.com` The domain name receiving the email.
Preference / Priority `10` Integer value indicating server priority (lower numbers = higher priority).
Mail Server / Target `mail.example.com` The Fully Qualified Domain Name (FQDN) of the mail server.
Crucial Rule: The target of an MX record MUST point to a valid domain name (`A` or `AAAA` record). It must never point directly to an IP address or a `CNAME` alias.

## MX Record Priority Explained

Priorities allow domain administrators to set up primary and backup fallback mail servers.

```text Priority 10 : mail1.example.com ←- Primary Mail Server (Tried First) Priority 20 : mail2.example.com ←- Secondary / Backup Server (Tried if Priority 10 fails)

```

* Equal Priorities: If multiple servers share the same priority (e.g., two servers with priority `10`), incoming mail load is distributed between them (round-robin / load balancing). * Lower Number = Higher Preference: Priority `5` takes precedence over Priority `10`.

## Example Configurations

### Example 1: Standard Self-Hosted Mail Server

Record Type Host Priority Value / Target TTL
MX `@` `10` `mail.example.com.` `3600`
A `mail` `192.0.2.25` `3600`

### Example 2: Google Workspace Configuration

Record Type Host Priority Value / Target TTL
MX `@` `1` `SMTP.GOOGLE.COM.` `3600`

## Common Issues & Troubleshooting

### 1. Pointing MX Records to CNAMEs

Pointing an MX record to a target that is a CNAME alias violates [RFC 2181 (Section 10.3)](https://datatracker.ietf.org/doc/html/rfc2181) and can lead to unpredictable mail loop errors or bounced emails.

### 2. Pointing MX Records directly to IP Addresses

MX records require an FQDN as their target. Pointing directly to an IPv4/IPv6 address will cause syntax validation failures across major mail servers.

### 3. Missing Trailing Dot (in Raw Zone Files)

In raw DNS zone files, failing to append a trailing dot (`mail.example.com.`) may cause DNS servers to append the root domain twice (`mail.example.com.example.com`).

## Verification & Testing

You can test and verify your MX records using Telenegar Tools or terminal commands:

### Using Telenegar Tools

Validate your domain's mail exchanger configuration using [Telenegar DNS Check](https://wiki.telenegar.ir/doku.php%3Fid%3Dtools:dnscheck) or [Telenegar Mail Check](https://wiki.telenegar.ir/doku.php%3Fid%3Dtools:mailcheck).

### Using Terminal Tools

#### `dig` (Linux / macOS)

```bash dig +short example.com MX

```

#### `nslookup` (Windows / Cross-platform)

```cmd nslookup -type=MX example.com

```

## Related Documentation

* [Telenegar DNS Check Tool](https://wiki.telenegar.ir/doku.php?id=tools:dnscheck) — Diagnostic tool for DNS record resolution and propagation. * [Telenegar Mail Check Tool](https://wiki.telenegar.ir/doku.php?id=tools:mailcheck) — Diagnostic tool for email authentication and mail server health. * [SPF (Sender Policy Framework)](https://wiki.telenegar.ir/doku.php?id=email:dns-configuration:spf) — Protect your domain against email spoofing. * [DKIM (DomainKeys Identified Mail)](https://wiki.telenegar.ir/doku.php?id=email:dns-configuration:dkim) — Add cryptographic signatures to outbound emails. * [DMARC](https://wiki.telenegar.ir/doku.php?id=email:dns-configuration:dmarc) — Define policy rules for SPF and DKIM alignment. * [Reverse DNS (PTR Records)](https://wiki.telenegar.ir/doku.php?id=networking:dns:reverse-dns) — Map mail server IP addresses back to domain names.

```

email/dns-configuration/mx-records.1785763512.txt.gz · Last modified: by 127.0.0.1