nanog mailing list archives

gmail.com - 550 error for ipv6/PTR ?


From: Brandon Applegate <brandon () burn net>
Date: Tue, 14 Jan 2014 19:06:01 -0500 (EST)

Just saw this in a message tonight. No idea if this is a transient error or not.

---
host gmail-smtp-in.l.google.com [gmail-smtp-in.l.google.com][2607:f8b0:4002:c01::1a]
   said: 550-5.7.1 [2607:ff70:11::11] Our system has detected that this
   message does not 550-5.7.1 meet IPv6 sending guidelines regarding PTR
   records and authentication 550-5.7.1 . Please review 550-5.7.1
   https://support.google.com/mail/?p=ipv6_authentication_error [support.google.com] for more 550
   5.7.1 information. t26si2290895yhl.255 - gsmtp (in reply to end of DATA
   command) ---
That URL's relevant section says:

Additional guidelines for IPv6

The sending IP must have a PTR record (i.e., a reverse DNS of the sending IP) and it should match the IP obtained via the forward DNS resolution of the hostname specified in the PTR record. Otherwise, mail will be marked as spam or possibly rejected.

The sending domain should pass either SPF check or DKIM check. Otherwise, mail might be marked as spam.
---

I have both of these (PTR's RR has matching AAAA, and I have SPF (but not DKIM)).

I'm guessing that something on google's side is misinterpreting some data or other busted logic. I meet all the requirements laid out, and have been sending mail to gmail addresses (via ipv6) since $forever.

Off-list replies are fine to minimize noise, and if there is an answer or any meaningful correlation I will reply on-list. Thanks in advance for any info/feedback.

--
Brandon Applegate - CCIE 10273
PGP Key fingerprint:
830B 4802 1DD4 F4F9 63FE  B966 C0A7 189E 9EC0 3A74
"SH1-0151.  This is the serial number, of our orbital gun."


Current thread: