/ developer & network toolbox
← all tools

$ fcrdns

server-side

FCrDNS Checker

Test forward-confirmed reverse DNS for an IP: the PTR name must resolve back to the same address, or mail servers treat it as suspect.

fcrdns — invoker.tools

FCrDNS = the PTR name must resolve forward back to this IP.

About the FCrDNS Checker

FCrDNS, forward-confirmed reverse DNS, is a two-step test on an IP address. First the PTR record gives the hostname the address claims to be. Then that hostname is resolved forward to its A or AAAA records, and the check passes only if the original IP is among the results. The tool above does both steps for every PTR name it finds and tells you which ones confirm.

The reason for the second step is that anyone who controls an IP block can set its PTR to any name they like, including mail.google.com. Only the owner of the domain can make that name resolve back to the address. A PTR that forward-confirms therefore proves that the network owner and the domain owner agree, which is a meaningful trust signal. A PTR that does not confirm is treated as no better than no PTR at all.

Mail servers are the main consumer of this test. Many receivers reject or heavily penalise connections from addresses without valid FCrDNS, Gmail requires sending IPs to have a PTR with a matching forward record, and Postfix can refuse such clients outright. The same technique is used to verify search engine crawlers: a request claiming to be Googlebot is genuine only if its IP reverses to googlebot.com or google.com and that name resolves back to the same IP.

How to use it

  1. Enter the IPv4 or IPv6 address you want to test, typically your outgoing mail server's address.
  2. Run the lookup to fetch the PTR record or records.
  3. Check each hostname: confirmed means its forward lookup contains the original IP.
  4. If there is no PTR, ask whoever owns the IP block (hosting or ISP) to set one; only they can.
  5. If the PTR exists but does not confirm, add an A or AAAA record for that hostname pointing to the IP in your own DNS.

Examples

  • 203.0.113.25 has PTR mail.example.com, and mail.example.com resolves to 203.0.113.25: FCrDNS passes.
  • 203.0.113.25 has PTR mail.example.com, which resolves to 203.0.113.99: PTR exists but FCrDNS fails.
  • 203.0.113.25 has PTR static-203-0-113-25.isp.example: passes technically, but generic ISP-style names still score badly with spam filters.
  • 66.249.66.1 reverses to crawl-66-249-66-1.googlebot.com, which resolves back to 66.249.66.1: a genuine Googlebot request.
  • An IPv6 sender without any ip6.arpa PTR: fails, and Gmail rejects mail from IPv6 addresses without valid reverse DNS.

How to fix a failing FCrDNS check

  • No PTR record: the PTR lives in the reverse zone of the IP block, controlled by your hosting provider or ISP. Set it in their control panel or ask support.
  • PTR points to a name without an A/AAAA record: create that record in your domain's DNS, pointing to the IP.
  • PTR name resolves to a different IP: update the A/AAAA record, or change the PTR to a name that does resolve to this IP.
  • Generic PTR (dynamic, dsl, pool or the IP in the name): set a descriptive name such as mail.example.com.
  • Mail server greets with a different name: make the SMTP HELO/EHLO hostname match the PTR as well.

FCrDNS versus a plain reverse DNS lookup

A plain reverse lookup only reads the PTR record, which the owner of the IP block can set to anything. FCrDNS adds the forward check, which requires control of the domain in the PTR name. Mail servers, crawler verification and many access-control systems rely on the combination, not on the PTR alone.

Frequently asked questions

What is FCrDNS?

Forward-confirmed reverse DNS: an IP's PTR hostname must resolve forward to the same IP. It proves that the IP owner and the domain owner agree on the name.

Why do mail servers check FCrDNS?

Addresses without valid reverse DNS are overwhelmingly compromised machines and consumer connections. Checking FCrDNS is a cheap way to filter them before looking at the message.

Who can set the PTR record for my IP?

The organisation that owns the IP block: your hosting provider, cloud provider or ISP. Your own domain's DNS panel cannot change it.

Does FCrDNS work for IPv6?

Yes. The PTR is stored under ip6.arpa and the forward check uses AAAA records instead of A records.

Is FCrDNS the same as matching the HELO name?

No, but they are related. Many receivers also expect the HELO/EHLO name to match the PTR, so set all three consistently: PTR, forward record and HELO.

More network tools