Two server same DNS but different results
Hi,
I have 2 servers, one of them seems hacked, which I noticed when I query the same DNS server I get different response. They both have same /etc/resolve files and query the same server, could someone please help me find out which files effect DNS? why am I getting different results on two server when I query the same DNS server of my ISP? I've restarted nscd daemon but still I'm getting the same thing. Thanks in advance. |
Quote:
|
Hi unSpawn,
Thanks for you response. So I've checked all the log files, and cannot find any traces. Basically on this server if I query MX record manually, I get these answers: Code:
nslookup -query=mx smtp.ultrahosting.com Code:
# /usr/lib/sendmail -bt -v To track it further down, I did use tcpdump and seems like when sendmail queries, it does send packages to the DNS server and does get a response. Code:
# tcpdump -r myfile | grep 'b-io' |
The MX for domain "ultrahosting.com" is listed not as "smtp.ultrahosting.com" but as "smtp.onx.com".
However Google DNS and ROBTEX both resolve (and back) "smtp.ultrahosting.com" to IPv4 66.240.144.254. See if you can use that if you have added that mapping to your /etc/hosts file? |
*I notice you have posted https://www.linuxquestions.org/quest...5/#post5170309 so apparently you know full well your provider doesn't have a MX record for its own advertised email relay server. We don't need duplicate questions so please don't post duplicate threads.
|
All times are GMT -5. The time now is 08:36 PM. |