Reverse DNS maps an IP address back to a hostname. Mail servers without a PTR record — or with one that does not resolve back to the same IP — are rejected outright by Outlook.com and many corporate gateways.
Table of Contents
Setting a PTR record
PTR records live in the reverse zone owned by whoever controls the IP block, usually your hosting provider, not in your domain’s DNS. Set it in the provider’s control panel or ask support, pointing it at the server’s hostname (for example server1.example.com), then make sure that hostname has an A record for the same IP.
The FCrDNS column shows whether that round trip works. Amber means the PTR exists but the hostname points elsewhere.
Reverse DNS lookup at a glance



How to use this tool
- Paste up to 25 IPv4 or IPv6 addresses. Put them on separate lines or separate them with spaces, commas or semicolons. Anything after the 25th address is ignored.
- Enter IP addresses only. A hostname gets the row “not an IP address”; look up its A or AAAA record with the DNS lookup first and paste the address.
- Press Look up PTR. For each address the tool asks Cloudflare’s public resolver (1.1.1.1) for the PTR record, then looks up the A record (IPv4) or AAAA record (IPv6) of the returned hostname to see whether it points back to the same address.
- The same list is answered from cache for five minutes. If you have just changed a PTR record, wait a few minutes before checking again.
How to read the results
| Status | Hostname column | FCrDNS column | Meaning |
|---|---|---|---|
| Green | the PTR hostname | forward-confirmed | The PTR exists and that hostname resolves back to the same IP. This is what mail receivers want. |
| Amber | the PTR hostname | hostname does not resolve back to this IP | The PTR exists, but the hostname has no A/AAAA record or points to a different address. |
| Red | no PTR record | (empty) | Public DNS has no PTR for the address. Private addresses such as 192.168.1.10 always end up here, because their reverse zones exist only inside your network. |
| Red | not an IP address | (empty) | The entry is not a valid IPv4 or IPv6 address. |
If an address has more than one PTR record, the first one returned is checked. FCrDNS stands for forward-confirmed reverse DNS: IP to name, then name back to the same IP.
Common problems and how to fix them
Gmail: “550-5.7.25 … does not have a PTR record setup”
The full text is “The IP address sending this message does not have a PTR record setup, or the corresponding forward DNS entry does not point to the sending IP. As a policy, Gmail does not accept messages from IPs with missing PTR records.” Give the sending IP a PTR that points to the mail server’s hostname and make sure that hostname has an A record for the same IP. The address in the bounce is the one to fix, and it is often an IPv6 address, because a dual-stack server often connects to Gmail over IPv6.
If you cannot get an IPv6 PTR, send mail over IPv4 only. In Postfix set this in /etc/postfix/main.cf and reload:
inet_protocols = ipv4
In Exim the main option is disable_ipv6 = true; on cPanel add it in WHM through the Exim Configuration Manager advanced editor so it survives updates.
Postfix: “450 4.7.25 Client host rejected: cannot find your hostname”
The receiving server uses reject_unknown_client_hostname, which refuses clients whose IP has no PTR, whose PTR name does not resolve, or whose name resolves to a different IP. The fix is the same: a PTR plus a matching A or AAAA record, which shows as green in this tool.
Amber: the hostname does not resolve back
Usual causes: the server hostname was changed but the PTR still names the old one, the A record for the hostname was never created, or the hostname sits in Cloudflare with the proxy (orange cloud) turned on, so it resolves to Cloudflare addresses. Mail hostnames must be DNS only (grey cloud). Check both directions from a shell:
dig +short -x 203.0.113.10
dig +short A server1.example.com
On Windows use nslookup 203.0.113.10 or Resolve-DnsName -Name 203.0.113.10 -Type PTR in PowerShell.
Green, but mail is still treated as spam
A provider default such as static.10.113.0.203.clients.example.net passes FCrDNS but looks like a generic, unconfigured address, and some filters score that badly. Set a custom PTR such as mail.example.com and use the same name as the server’s SMTP HELO name. On cPanel, Exim uses the reverse DNS name as HELO when “Use the reverse DNS entry for the mail HELO/EHLO if available” is on, and /etc/mailhelo can set a HELO per sending domain once “Reference /etc/mailhelo for custom outgoing SMTP HELO” is enabled in the Exim Configuration Manager.
The provider says the PTR is set, but the tool shows the old value
Resolvers keep the old answer until its TTL runs out, and this tool caches results for five minutes. Ask the authoritative servers directly to see what is really published:
dig -x 203.0.113.10 +trace
You only have a few IPs, not a whole /24
Reverse zones are normally delegated in /24 blocks for IPv4. For smaller blocks the provider has to delegate with CNAME records as described in RFC 2317, and most providers simply set the PTR for you in their panel instead. On AWS, create the A record first, then use Elastic IPs » Actions » Update reverse DNS or:
aws ec2 modify-address-attribute --allocation-id eipalloc-0123456789abcdef0 --domain-name mail.example.com
How reverse DNS works
A PTR record lives in a special zone built from the address written backwards. For IPv4, 203.0.113.10 becomes 10.113.0.203.in-addr.arpa. For IPv6, every hexadecimal digit of the full 32-digit address is reversed and separated by dots under ip6.arpa, so 2001:db8::1 becomes a 32-label name ending in 8.b.d.0.1.0.0.2.ip6.arpa.
Those zones are delegated along the same chain as the addresses: from IANA to the regional internet registry, then to the provider that holds the block. That is why only the provider (or someone it delegates the zone to) can set the PTR, and why the WHOIS lookup for an IP tells you who to ask. The forward A record is yours to manage in your own DNS; FCrDNS only passes when both sides agree.
Official documentation: RFC 5321 (SMTP), AlmaLinux wiki, Linux man pages.
Related guides: Cloudflare Tunnel (cloudflared): expose an internal service without opening ports · Warm up a new mail server IP or sending domain without landing in spam · MailBaby with Postfix on Ubuntu/Debian as an authenticated smarthost.
Frequently asked questions
Why can’t I add a PTR record in Cloudflare?
Cloudflare only hosts your forward zone. The reverse zone for an IP belongs to the network that owns it — your VPS or dedicated server provider.
Does a web server need reverse DNS?
Not for websites, but any server that sends email should have a matching PTR.
Can one IP have several PTR records?
It is allowed but a bad idea for mail servers; receivers may check only one. Keep one PTR per sending IP.
How long does a PTR change take to show up?
Usually minutes, but resolvers keep the old record until its TTL expires, which can be several hours on some providers. Check the authoritative servers with dig -x and +trace to confirm the change is live.
Does the PTR hostname have to match my email domain?
No. It must be a real hostname that resolves back to the same IP, and it should match the HELO name your mail server uses. One server can send for many domains with a single PTR.
Do IPv6 addresses need reverse DNS too?
Yes, if the server sends mail over IPv6. Gmail and other large receivers apply the same PTR checks to IPv6 senders as to IPv4.
Why does a private IP show no PTR record?
Reverse zones for 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16 exist only on your own DNS servers. This tool queries public DNS, so check internal PTRs with nslookup against your internal DNS server.
How do I check reverse DNS for a whole /24?
Paste up to 25 addresses at a time here, or loop from a shell: for i in $(seq 1 254); do echo “203.0.113.$i $(dig +short -x 203.0.113.$i)”; done