Recommended Posts

So this is a topic that can fit under many forums be it hardware, server or technical support, etc. My question comes down to this: how do these large cloud services providers manage their back-end to automate and even segregate the services from each customer?

There are a couple examples of what I'm referring to the best of which is Microsoft's Office 365 or, more specifically, Hosted Exchange. I'm talking about everything from licensing to reverse DNS records. If I wanted to do something like this for my clients, I could have an Exchange server that accepts mail for many domains and I could create many users with specific email addresses manually assigned. This is entirely a manual process though. How do these large cloud services providers do this in an automated way? I would assume Microsoft would use a Microsoft product to accomplish this. Maybe they have created a custom system using APIs or something?

On the more technical side, if I were to have an Exchange server and do this, it would be behind one IP address and thus only one reverse DNS record could be made for a lookup back to it (right?). It's completely inefficient to have an exchange server for each person that signs up for Microsoft's Hosted Exchange. Another large setback to using one Exchange server is the originating server's responding FQDN. As far as I know, this can be only one domain and if someone were to look at the an emails message details, they could see that this person's email did not come from domainxyz.co but from another domain123.co as would all other customers on the same Exchange server.

Hopefully someone has insight on this!

As a simple answer of "it just works don't worry about it" I would add in,

At a level of Microsoft or Google's services, you are talking custom written software to run all of this.

So they can program it exactly how they want it.

Which I would expect from Rackspace (another of these cloud providers) but I was hoping that Microsoft would be using their own product/tools to do this. I can understand though that to make this readily available creates direct competition.

I know that it just works and I'm fine with that. However there are some technical aspects such as reverse DNS records and FQDN responses that are fundamental workings of email technology, I don't think a custom software can make exceptions to how these things work.

accepting mail is different than sending mail. You don't need a PTR for accepting mail.. The only time a ptr is checked is the accepting server checking the server sending it mail - if no valid PTR then its most likely some fly by night mail server, etc.. and prob spam - so sure many major domains will not accept mail from such a server.

But this is not the case with having servers that accept mail for users.. They do not need ptr to match anything.

You can have a cluster of servers accepting mail on lots of different IPs, or even behind a load balancer accepting the connection on 1 IP and then sending on to email servers behind that to handle the getting of the mail and then once accepting it routing it to the mail server the mail box sits on for that user.

Take a look at your say gmail or yahoo.com headers for email sent to you.. It more than likely routes through a few servers on gmail or yahoo side.

example

Delivered-To: [email protected]

Received: by 10.60.141.201 with SMTP id rq9csp9608oeb;

Wed, 9 May 2012 10:23:08 -0700 (PDT)

Received: by 10.182.44.74 with SMTP id c10mr1164113obm.43.1336584188741;

Wed, 09 May 2012 10:23:08 -0700 (PDT)

Return-Path: <[email protected]>

Received: from mail.adagio.com (mail.adagio.com. [67.192.109.186])

by mx.google.com with ESMTPS id fq1si187201obc.135.2012.05.09.10.23.08

see where mx.google.com got it from mail.adagio.com -- then it went through 2 private IPs in googles network before I got it.

This is routing internal to gmail system..

Same goes for the way back out -- you send email using gmail to say yahoo. You create the message on the server you connected too, its more than likely going to be routed through a few servers again before it gets to the actual sending server(s) that will send the mail to yahoo.

If you want to understand how an email message flows - just look at the headers, it will show you all the different email servers that message went through to get from where sent to your mailbox.

Basically I am researching how I can duplicate these hosted Exchange solutions for my clients.Typically for my clients who have their own mail server, headers will read that the message originated from their domain/networks because of the send connector. If I host their mail, it will come from me. Is that unavoidable? Or am I being way to concerned about what the message headers say?

In an Exchange server that is hosting mail for many domains, what is the best way segregate the customers? Different databases? Could you create different send connectors for each domain and somehow only allow certain databases to send out with a connector? This would solve the outgoing mail headers having a strange originating domain. But can you have multiple PTRs going back to the same IP?

not sure why your hung up on PTR? so you want your sending server to match up with their forward domain?

So for example you have domainA.tld, domainB.tld, domainC.tld

And all being sent from same email server at 1.2.3.4, your concerned that when someone looks up 1.2.3.4 PTR it will reflect say mx.domainZ.tld?

There there is no way to have multiple PTR records for the same IP. Sure you can have mx.domainA.tld, mx.domainB.tld both point to the same IP.

I would not worry too much about the PTR, as long as its valid. So for example mx.domainZ.tld, while that server hosts mail for domainA, domainB, domainC, etc.. you don't even have to have the mx for domainA point to something domainA, it can point to mx.domainZ.tld just fine -- does not matter what the name of the server is accepting the mail for a specific domain.. Quite often it does not match.

example neowin.net mx points to google servers. Companies host their mail on other domains all the time, the name of the server that accepts mail for your domain does not have to be in the same domain.

Keep in mind that the sending server is not always the same name as the sending domain either. Just look through the headers of the email in your inbox

not sure why your hung up on PTR? so you want your sending server to match up with their forward domain?

So for example you have domainA.tld, domainB.tld, domainC.tld

And all being sent from same email server at 1.2.3.4, your concerned that when someone looks up 1.2.3.4 PTR it will reflect say mx.domainZ.tld?

That is exactly my concern. I would like it to be as seemingly segregated as possible. Do you think this is impossible when using one Exchange server? I think you answered that here:

There there is no way to have multiple PTR records for the same IP. Sure you can have mx.domainA.tld, mx.domainB.tld both point to the same IP.

This is only one technicality that I'm hung up on. I am still curious how Exchange is best configured to manage multiple domains.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Win11Debloat 2026.06.14 by Razvan Serea Win11Debloat is a lightweight, easy to use PowerShell script that allows you to quickly declutter and customize your Windows experience. It can remove pre-installed bloatware apps, disable telemetry, remove intrusive interface elements and much more. The script also includes many features that system administrators and power users will enjoy. Such as a powerful command-line interface, support for Windows Audit mode and the option to make changes to other Windows users. All changes made by Win11Debloat can be easily reversed, and most removed apps can be restored via the Microsoft Store. A full guide on how to undo the changes is available here. Win11Debloat features: Below is an overview of the key features and functionality offered by Win11Debloat. Please refer to the wiki for more information about the default settings preset. Remove a wide variety of preinstalled apps. Click here for more info. Disable telemetry, diagnostic data, activity history, app-launch tracking & targeted ads. Disable tips, tricks, suggestions & ads across Windows. Disable Windows location services & app location access. Disable Find My Device location tracking. Disable 'Windows Spotlight' and tips & tricks on the lock screen. Disable 'Windows Spotlight' desktop background option. Disable ads, suggestions and the MSN news feed in Microsoft Edge. Hide Microsoft 365 ads on the Settings 'Home' page, or hide the 'Home' page entirely. Disable & remove Microsoft Copilot. Disable Windows Recall. Disable Click to Do, AI text & image analysis tool. Prevent AI service (WSAIFabricSvc) from starting automatically. Disable AI Features in Edge. Disable AI Features in Paint. Disable AI Features in Notepad. Disable the Drag Tray for sharing & moving files. Restore the old Windows 10 style context menu. Turn off Enhance Pointer Precision, also known as mouse acceleration. Disable the Sticky Keys keyboard shortcut. Disable Storage Sense automatic disk cleanup. Disable fast start-up to ensure a full shutdown. ...and more. Once you’ve downloaded the Win11Debloat file (Get.ps1), just follow these quick steps: Locate the Get.ps1 script file. Right-click the file and select Run with PowerShell from the context menu. If prompted by User Account Control (UAC), select Yes to grant the script the necessary administrative permissions. Win11Debloat 2026.06.14 changes: This is a minor release that hopefully addresses the false positives in Windows Defender and Bitdefender that prevented users from downloading and/or running Win11Debloat. Refactor Get-RegFileOperations.ps1 to address false positives by @Raphire in #626 Add logging around WinGet app retrieval and increase timeout to 20s by @Raphire Download: Win11Debloat 2026.06.14 | Open Source View: Win11Debloat Home Page | Screenshots 1| 2 Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Still using Microsoft Money 2005 in 2026 here!
    • I have a couple to mention, and they still run great on Windows 11 Adobe Lightroom Version 2 Alcohol 120% CLZ Book, Comic, Game, Movie, & Music Collector (PC - No longer sold / Grandfathered in - now mobile apps/online only) DVDDecrypter ISO Buster Pro version 1.9.1 (Still supports HD-DVD too) Nero Burning Rom 8 (Only the burning software, no backup, media converter, etc)   OpenAL (Runtime) - GuildWars 1 Reforged still uses it for 3d headphone audio PowerDVD 12 Ultra SPTD (SCSI Pass through Direct Driver) UltraISO Windows Media Encoder 9 WinImage You can tell I still sport an optical drive    
    • Linux 7.1 arrives with an NTFS overhaul and major hardware performance boosts by Paul Hill The founder of the Linux kernel has just announced the availability of Linux 7.1. This is a stable version of the kernel that will now be tested by various Linux distributions before it is shipped to users through update managers. Some users, like those on Debian, for example, might not get it for a long time, if at all, while Fedora users can expect it in the near future. With Linux 7.1 out on time, the merge window for Linux 7.2 is now open, giving contributors the opportunity to send in major new features that have been waiting for the last two months. Torvalds warned that he is currently travelling and will be in another timezone, so timing for the merge window may be irregular due to timezone differences and limited internet access. Torvalds said that he has already fetched early pull requests to allow him to do some offline work, but the travel could still cause disruption. Right now, he is not planning to extend the release, but did consider it. He said he might later regret not extending, though. In terms of this last week of development for Linux 7.1, Torvalds said there were no major or alarming changes. This week consisted mostly of smaller driver updates to GPU, networking, and sound, networking fixes, trace tooling fixes, and misc minor fixes. The shortlog this week lists fixes for driver bugs, memory leaks, I/O and USB fixes, networking and RDMA fixes, DRM/graphics fixes, and tooling and verification improvements. Specific fixes include USB series heap-overflow and buffer overflow fixes, and multiple use-after-free, memory-leak, and refcount corrections across subsystems such as i2c, zram, gpio, and net. There are fixes for graphics drivers, including amdgpu, i915, and virtio, as well as hypervisor and virtualization tweaks affecting mshv, vmbus, and hyperv. According to Phoronix, anyone running Linux 7.1 should look out for the new NTFS driver, Intel FRED for improved performance on Panther Lake and future CPUs, faster graphics with Intel Arc Battlemage, and improvements for older AMD Radeon GPUs. If you are running Linux on your computer and everything is fine, then you don’t need to worry about updating to Linux 7.1 as a priority; just wait for it to be pushed to you. If you have tried Linux on hardware but it didn’t work properly, trying again with a distro that uses Linux 7.1 could cause Linux to work on your machine, thanks to the new hardware support.
    • you can also do this with this tool: PowerSettingsExplorer made by mbk1969 at 3dguru forum.. I found it by accident researching on modern standby and annoying quirks of it in 2022
  • Recent Achievements

    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
    • One Month Later
      AndreaB earned a badge
      One Month Later
    • One Month Later
      agatameier earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      507
    2. 2
      +Edouard
      196
    3. 3
      PsYcHoKiLLa
      139
    4. 4
      ATLien_0
      90
    5. 5
      Steven P.
      81
  • Tell a friend

    Love Neowin? Tell a friend!