I am in dire need of help! Some of our hosted Exchange users recently are getting NDRs when sending to some domains. I believe error is 554 NO PTR IP FOUND. I swore we had our ISP put in a PTR and indeed it was there. However, my other colleague noticed that Google's DNS is not returning the results and instead provides a SERVFAIL error instead. Turns out that Google DNS does DNSSEC validations by default for all queries and if the zone is not signed, then no harm done. However, if zone is DNSSEC enabled but not configured correctly, then you'd get SERVFAIL.
We have talked with our ISP and they refuse to acknowledge that the problem is on their side as they keep saying that DNSSEC is never enabled on any of their .in-addr.arpa zones. But when we do online validation checks, this proves otherwise.
The IP in question is x.x.x.x and is hosted by Centurylink.
https://dnssec-debugger.verisignlabs.com/.in-addr.arpa http://dnsviz.net/d/.in-addr.arpa/dnssec/
My theory is that the receiving email server is simply doing a PTR SPAM check AND they are also configured to use Google's DNS servers of 8.8.8.8 as the resolvers. Because it receives the SERVFAIL message, our clients get the NDR since it can't verify our sending relay server.
I really need help in proving to the ISP that this is somehow DNSSEC related as they keep pushing back arguing that it has ZERO percent to do with DNSSEC. I'm trying to use DIG to prove somehow that DNSSEC is related so please help me out! I've shown those two links to them yet they aren't budging. Am I going crazy or are they correct?
TIA!
EDIT: I have removed our public IP from being listed as our issue seems to have been resolved for now.