Admin tip: set rDNS / PTR on a crypto VPS

A PTR that matches the HELO is the first ticket most mail setups need. What to send the desk, how to align SPF and DKIM, and how fast it lands.
نص المقال الطويل بالإنجليزية. الواجهة والكتالوج والدفع مترجمة.
Why PTR shows up in tickets
Receiving mail servers and a handful of payment APIs check reverse DNS before they read a word of your message: a generic allocator name as PTR is the classic spam signature, and Postfix documentation cannot compensate for it. It is the usual first ticket after a mail VPS order — nothing is broken; reputation plumbing starts here. Port 25 is open by policy on every plan, so the record is the missing piece.
VPS from $3* (fund $50+), storage 1–5 TB NVMe from $24/mo annual-eff, dedicated with IPMI from $30.80/mo. Crypto invoice, no KYC.
Launch nowWhat to send
- The IPv4 (and the IPv6, if you published its AAAA record).
- The FQDN that already points back at that address via A/AAAA.
- The invoice code, if the panel session is new.
The desk sets the pointer; forward and reverse then agree, which is the property receivers actually test. While the ticket is open, harden OpenSSH manual — key-only login is the same afternoon's work — and keep port 25 for mail you operate yourself.
Matching HELO, SPF and DKIM
The PTR is one of four strings that must tell the same story: reverse DNS, the SMTP HELO name, the SPF record and the DKIM selector on the sending domain. Receivers score the agreement before the prose, so set the pointer first and introduce the MTA with the same FQDN. A mismatch anywhere in that chain costs deliverability no matter how clean the address history is.
Warm-up and reputation
A fresh IPv4 has no reputation anywhere, and no provider can sell a shortcut around that physics. Start with low volume toward recipients who open your mail, hold bounce rates under a few percent, and let weeks rather than days set the ramp. Big receivers score domain and IP separately: a domain's reputation follows it onto a new address, and a clean domain digs out of a shared history faster than the reverse.
When one address is not enough
Splitting roles — web, VPN egress, mail — across addresses keeps one job's reputation from taxing another's. Extra IPv4s are a $3.50/mo add-on, each with its own settable pointer — the cheap fix long before dedicated metal. When the workload outgrows slices entirely, the dedicated tiers carry IPMI and ECC from $30.80 annual-eff with the same PTR workflow; bulk archives belong on storage, from $24.
IPv6 PTR too?
Yes, for any address whose AAAA is published — include the IPv6 in the ticket alongside the IPv4. Receivers check both families, and an unpaired AAAA is its own deliverability penalty.
How fast does the change land?
Same support queue as every other ticket, with DNS propagation on top — usually quick, occasionally cached longer by resolvers you do not control. It is a desk action, not a self-serve panel field.
Does a web server need PTR?
Rarely. Browsers and search crawlers do not score reverse DNS; the record matters to mail receivers, some FTP mirrors and a few API gateways. Set it once anyway — it costs a ticket and removes a variable.
Can the PTR change again later?
Yes — re-ticket the IP with the new FQDN whenever the hostname moves. Update HELO and SPF to match in the same change, since the agreement between them is what receivers verify, not the string itself.
Does rDNS alone fix deliverability?
No — it removes one known penalty, not all of them. Content, volume ramp, list hygiene and authenticated headers (SPF, DKIM, DMARC) carry the rest, and a warmed address stays clean only if the mail stays wanted.
Ready to launch?
Build the box — VPS, storage or bare metal — create the password, pay the invoice that follows.