Hello This as follows : As the message is suggesting, the DNS server has received an invalid domain name. By invalid it means that it contains invalid characters. MS DNS only supports 0-9, a-z, A-Z, . (dot), and - (hyphen) as part of a domain name. Some other DNS servers may not strictly enforce RFC 952 (DOD INTERNET HOST TABLE SPECIFICATION) so invalid names reach the DNS server and the 5504 message is recorded. Usually this happens when Forwarders are used by the DNS server. Microsoft suggested to one user to turn off the forwarder in order to eliminate these messages. There used to be a Knowledge Base article "Q246797 - DNS EVENT IDS 5504, 9999, AND 5000 FILL EVENT VIEWER" but is no longer available. Another condition that may generated these messages is when the Internet connection is saturated or not working properly (losing packets). Because of the poor Internet connection, the DNS may receive incomplete or corrupted data and 5504 is generated. Might solve ur problem ! Uttam -----Original Message----- From: Bryan Andrews [mailto:bandrews@xxxxxxxxxxxxxxxxxx] Sent: Tuesday, October 09, 2001 7:24 PM To: [ISAserver.org Discussion List] Subject: [isalist] Wierd DNS stuff... http://www.ISAserver.org Hello All, I have been having dns trouble intermittently where emails are bouncing back (exchange2000) and I clear my dns caches and everything is ok. Quick note about my setup: 1. ISA server w/ 2 nics, no DNS, no IIS, no etc 2. internal AD, DNS (AD integrated), E2K server 3. internal AD, DNS (AD integrated) 4. other boxes that are not important. In troubleshooting I have noticed that I have repeated entries in my dns for: Event Type: Warning Event Source: DNS Event Category: None Event ID: 5504 Date: 10/2/2001 Time: 6:28:04 PM User: N/A Computer: TATL0S03 Description: The DNS server encountered an invalid domain name in a packet from 209.235.102.18. The packet is rejected. AND Event Type: Warning Event Source: DNS Event Category: None Event ID: 5504 Date: 10/2/2001 Time: 6:28:04 PM User: N/A Computer: TATL0S03 Description: The DNS server encountered an invalid domain name in a packet from 209.235.102.17. The packet is rejected. I have no idea why this is happening. I did digs and do not recognize this address, and whats more, I don't really understand how dns would be talking to this ip thru the firewall... often and repeatedly. Has anyone else seen this before is this something I should worry about? ------------------------------------------------------ You are currently subscribed to this ISAserver.org Discussion List as: uttamm@xxxxxxxxxxxxxx To unsubscribe send a blank email to $subst('Email.Unsub')