How to Troubleshoot Email Delivery Issues Using MX Lookup
Email delivery failures often stem from misconfigured domain name system records rather than server outages or spam filters. When outbound messages bounce or inbound mail simply vanishes, investigating your underlying mail exchanger and authentication records is the fastest path to a resolution. By systematically verifying your DNS zone files, you can pinpoint routing loops, missing authentication tokens, and priority mismatches before they disrupt business operations.
To quickly inspect your current zone settings and check how global nameservers resolve your records, you can use the DNS Lookup tool to instantly query authoritative servers and view live propagation states.
Understanding Email Routing and DNS Dependencies
When an external mail transfer agent attempts to deliver a message to your domain, it relies on a specific sequence of DNS queries. Understanding this lifecycle helps you isolate where a failure occurs.
The Mail Delivery Sequence
- MX Query: The sender's mail server queries your domain for Mail Exchanger (MX) records to find where to send the message.
- A/AAAA Resolution: The sender's server resolves the hostnames found in the MX records to IPv4 or IPv6 addresses.
- Connection: The sender connects to port 25 of your mail server IP address and hands over the message.
- Authentication Checks: Your receiving server (or the recipient's server if you are sending) checks SPF, DKIM, and DMARC records to verify message legitimacy.
If any link in this DNS chain is broken, mail delivery fails immediately or results in a delayed retry queue.
Essential DNS Records for Email Deliverability
To ensure reliable inbound and outbound mail, your domain must publish a specific set of DNS records. Incorrect syntax in any of these will break mail flow or trigger aggressive spam filters.
MX Records
MX records designate which mail servers accept incoming mail for your domain. They require a priority number and a target hostname. Lower numbers indicate higher priority.
example.com. IN MX 10 mail.example.com.
example.com. IN MX 20 backup-mail.example.com.
- Common Mistake: Pointing an MX record directly to an IP address instead of a valid A/AAAA hostname. MX records must always point to domain names, never IP addresses.
SPF Records
Sender Policy Framework (SPF) records are TXT records that list the authorized IP addresses and mechanisms permitted to send email on behalf of your domain.
example.com. IN TXT "v=spf1 include:_spf.example.com ip4:192.0.2.1 -all"
- Common Mistake: Publishing multiple SPF records in a single domain. A domain must have exactly one SPF TXT record; multiple records cause permanent validation failures.
DKIM Records
DomainKeys Identified Mail (DKIM) adds a cryptographic signature to your outgoing headers, proving the email was not altered in transit.
selector1._domainkey.example.com. IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQ..."
DMARC Records
Domain-based Message Authentication, Reporting, and Conformance (DMARC) tells receiving servers what to do if SPF or DKIM checks fail.
_dmarc.example.com. IN TXT "v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com"
Step-by-Step Troubleshooting Process
Follow this structured methodology to diagnose and fix email delivery bottlenecks.
Step 1: Verify MX Record Resolution
Check that your MX records resolve correctly and point to active servers. Open your terminal and query your domain's MX records using command-line tools.
nslookup -type=mx example.com
Alternatively, use dig for more detailed authoritative output:
dig example.com MX +trace
Sample output:
; <<>> DiG 9.16.1-Ubuntu <<>> example.com MX
;; global options: +cmd
;; Got answer:
;; -> __ER_HEADER__
;; QUESTION SECTION:
;example.com. IN MX
;; ANSWER SECTION:
example.com. 300 IN K 10 mail.example.com.
;; ADDITIONAL SECTION:
mail.example.com. 300 IN A 192.0.2.25
Step 2: Test Mail Server Connectivity
Verify that your mail server is actively listening on port 25 and responding to SMTP handshakes. You can test this using telnet or nc (Netcat).
nc -v mail.example.com 25
If the connection times out or is refused, your hosting provider, firewall, or cloud security group is blocking inbound port 25 traffic. Contact your network administrator or hosting support to open this port.
Step 3: Audit SPF, DKIM, and DMARC Alignment
Authentication failures are the leading cause of legitimate emails landing in spam folders or being rejected outright. Verify your TXT records exist and contain valid syntax.
nslookup -type=txt example.com
nslookup -type=txt _dmarc.example.com
Ensure your SPF lookup count does not exceed the 10-lookup limit imposed by RFC specifications. Nested includes quickly consume this limit.
Comparison of DNS Diagnostic Commands
| Tool / Command | Primary Use Case | Best For | Output Detail Level |
|---|---|---|---|
dig |
Advanced DNS queries | Detailed technical debugging, tracing paths | High, includes flags and TTLs |
nslookup |
Quick record checks | Simple operational spot-checks | Medium, straightforward record lists |
| Web DNS Lookup | Global resolution check | Verifying propagation across public resolvers | High, visual and easy to share |
Common DNS Mistakes and How to Fix Them
- Cname on Apex Domain: Placing a CNAME record on
example.combreaks MX record resolution and violates DNS standards. Use an ALIAS, ANAME, or A record instead. - Exceeding SPF Lookups: Using too many
includestatements in your SPF record leads to apermerror. Flatten your SPF record or use a dedicated IP pool. - Missing Reverse DNS (PTR): Without a valid PTR record matching your outbound mail server IP, receiving servers will immediately reject your connection due to anti-spam policies.
Email Deliverability Troubleshooting Checklist
- MX records point to valid hostnames with correct priorities.
- Target hostnames resolve to active A/AAAA IPv4 or IPv6 addresses.
- Port 25 is open and accepting inbound TCP connections on your mail server.
- Exactly one SPF record exists and stays under the 10-lookup limit.
- DKIM public keys are published correctly under your chosen selector.
- DMARC record is active with a monitoring or enforcement policy (
p=none,p=quarantine, orp=reject). - Reverse DNS (PTR) records match your outbound HELO/EHLO hostname.