Symantec Messaging Gateway (SMG) IP reputation does not appear to block connections as expected, resulting in an increase in missed spam messages. The Brightmail Engine logs show multiple errors indicating that DNS TXT queries are failing.
DNS TXT query for "18.104.22.168.zodiac.brightmail.com" failed unexpectedly.
This error results from a failure in looking up the IP of a mail sender on the Symantec Global Reputation Service.
Note: This error does not appear if there is no record associated with the sender in the reputation service. This error appears only if there is a failure in the lookup process.
Ensure that you have a correctly configured DNS server for the appliance on which this error occurred. You can find the DNS server configuration for the appliance in question by accessing the Control Center's Administration > Hosts > Configurations screen. Select the checkbox next to the appliance with the error and click Edit. In the page that appears, click theDNS/Time tab and confirm that you have only valid entries for your DNS server.
Execute a DNS query using either the Admin CLI's nslookup command, or the Control Center's Administration > Hosts > Utilities > Nslookup tool. Extract the domain from the error in question. The domain looks similar to: 22.214.171.124.zodiac.brightmail.com.
Execute a TXT record query for that domain. Following is a sample record query:
126.96.36.199.zodiac.brightmail.com text = "H=1"
If the nslookup utility fails:
Check if you can execute the same query off the appliance, preferably from another network segment.
If you cannot execute this query from another network segment:
Contact your network administrator to ensure that there are no firewall rules that prevent communication between your appliance and the configured DNS server. Check your configured DNS server for errors and ensure that the forwarders are configured correctly on that DNS server.
Subscribing will provide email updates when this Article is updated. Login is required.