XiaTools

How to Troubleshoot Email Delivery Issues Using MX Lookup

Updated 09 Oct 2026

Email delivery failures often stem from misconfigured domain name system records rather than server outages or spam filters. When outbound messages bounce or inbound mail simply vanishes, investigating your underlying mail exchanger and authentication records is the fastest path to a resolution. By systematically verifying your DNS zone files, you can pinpoint routing loops, missing authentication tokens, and priority mismatches before they disrupt business operations.

To quickly inspect your current zone settings and check how global nameservers resolve your records, you can use the DNS Lookup tool to instantly query authoritative servers and view live propagation states.

Understanding Email Routing and DNS Dependencies

When an external mail transfer agent attempts to deliver a message to your domain, it relies on a specific sequence of DNS queries. Understanding this lifecycle helps you isolate where a failure occurs.

The Mail Delivery Sequence

  1. MX Query: The sender's mail server queries your domain for Mail Exchanger (MX) records to find where to send the message.
  2. A/AAAA Resolution: The sender's server resolves the hostnames found in the MX records to IPv4 or IPv6 addresses.
  3. Connection: The sender connects to port 25 of your mail server IP address and hands over the message.
  4. Authentication Checks: Your receiving server (or the recipient's server if you are sending) checks SPF, DKIM, and DMARC records to verify message legitimacy.

If any link in this DNS chain is broken, mail delivery fails immediately or results in a delayed retry queue.

Essential DNS Records for Email Deliverability

To ensure reliable inbound and outbound mail, your domain must publish a specific set of DNS records. Incorrect syntax in any of these will break mail flow or trigger aggressive spam filters.

MX Records

MX records designate which mail servers accept incoming mail for your domain. They require a priority number and a target hostname. Lower numbers indicate higher priority.

example.com.   IN   MX   10 mail.example.com.
example.com.   IN   MX   20 backup-mail.example.com.
  • Common Mistake: Pointing an MX record directly to an IP address instead of a valid A/AAAA hostname. MX records must always point to domain names, never IP addresses.

SPF Records

Sender Policy Framework (SPF) records are TXT records that list the authorized IP addresses and mechanisms permitted to send email on behalf of your domain.

example.com.   IN   TXT   "v=spf1 include:_spf.example.com ip4:192.0.2.1 -all"
  • Common Mistake: Publishing multiple SPF records in a single domain. A domain must have exactly one SPF TXT record; multiple records cause permanent validation failures.

DKIM Records

DomainKeys Identified Mail (DKIM) adds a cryptographic signature to your outgoing headers, proving the email was not altered in transit.

selector1._domainkey.example.com.   IN   TXT   "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQ..."

DMARC Records

Domain-based Message Authentication, Reporting, and Conformance (DMARC) tells receiving servers what to do if SPF or DKIM checks fail.

_dmarc.example.com.   IN   TXT   "v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com"

Step-by-Step Troubleshooting Process

Follow this structured methodology to diagnose and fix email delivery bottlenecks.

Step 1: Verify MX Record Resolution

Check that your MX records resolve correctly and point to active servers. Open your terminal and query your domain's MX records using command-line tools.

nslookup -type=mx example.com

Alternatively, use dig for more detailed authoritative output:

dig example.com MX +trace

Sample output:

; <<>> DiG 9.16.1-Ubuntu <<>> example.com MX
;; global options: +cmd
;; Got answer:
;; -> __ER_HEADER__
;; QUESTION SECTION:
;example.com.		IN	MX

;; ANSWER SECTION:
example.com.		300	IN	K	10 mail.example.com.

;; ADDITIONAL SECTION:
mail.example.com.	300	IN	A	192.0.2.25

Step 2: Test Mail Server Connectivity

Verify that your mail server is actively listening on port 25 and responding to SMTP handshakes. You can test this using telnet or nc (Netcat).

nc -v mail.example.com 25

If the connection times out or is refused, your hosting provider, firewall, or cloud security group is blocking inbound port 25 traffic. Contact your network administrator or hosting support to open this port.

Step 3: Audit SPF, DKIM, and DMARC Alignment

Authentication failures are the leading cause of legitimate emails landing in spam folders or being rejected outright. Verify your TXT records exist and contain valid syntax.

nslookup -type=txt example.com
nslookup -type=txt _dmarc.example.com

Ensure your SPF lookup count does not exceed the 10-lookup limit imposed by RFC specifications. Nested includes quickly consume this limit.

Comparison of DNS Diagnostic Commands

Tool / Command Primary Use Case Best For Output Detail Level
dig Advanced DNS queries Detailed technical debugging, tracing paths High, includes flags and TTLs
nslookup Quick record checks Simple operational spot-checks Medium, straightforward record lists
Web DNS Lookup Global resolution check Verifying propagation across public resolvers High, visual and easy to share

Common DNS Mistakes and How to Fix Them

  • Cname on Apex Domain: Placing a CNAME record on example.com breaks MX record resolution and violates DNS standards. Use an ALIAS, ANAME, or A record instead.
  • Exceeding SPF Lookups: Using too many include statements in your SPF record leads to a permerror. Flatten your SPF record or use a dedicated IP pool.
  • Missing Reverse DNS (PTR): Without a valid PTR record matching your outbound mail server IP, receiving servers will immediately reject your connection due to anti-spam policies.

Email Deliverability Troubleshooting Checklist

  • MX records point to valid hostnames with correct priorities.
  • Target hostnames resolve to active A/AAAA IPv4 or IPv6 addresses.
  • Port 25 is open and accepting inbound TCP connections on your mail server.
  • Exactly one SPF record exists and stays under the 10-lookup limit.
  • DKIM public keys are published correctly under your chosen selector.
  • DMARC record is active with a monitoring or enforcement policy (p=none, p=quarantine, or p=reject).
  • Reverse DNS (PTR) records match your outbound HELO/EHLO hostname.

Frequently asked questions

Why are my emails going to spam even though my MX records are correct?

MX records only control where mail is delivered, not its reputation. If your emails land in spam, it is usually because your domain lacks proper SPF, DKIM, or DMARC authentication records, or your sending IP lacks a valid reverse DNS (PTR) pointer.

Can I use a CNAME record for my MX target hostname?

No, RFC standards prohibit using a CNAME record as the target of an MX record. Your MX records must point directly to an A or AAAA record hostname, never to an alias.

How long does it take for DNS changes to fix my email delivery?

DNS changes depend entirely on the Time To Live (TTL) value configured on your old records. If your TTL was set to 3600 seconds, it may take up to one hour for all global mail servers to cache and respect the new routing updates.

What happens if I have multiple SPF records on my domain?

Publishing multiple SPF records causes a permanent error (permerror) during validation by receiving mail servers. Mail servers will reject or filter messages because they cannot determine which single policy is authoritative.

Why does my mail server connection time out on port 25?

Port 25 timeouts almost always indicate a network-level blockage. Cloud providers, consumer ISPs, and corporate firewalls frequently block outbound or inbound port 25 to curb spam, requiring you to request a firewall exception or use an authenticated relay service.

Related articles

Free tools