PTR deletion

John JY 221 Reputation points
2023-01-26T21:44:50.5666667+00:00

we have one Windows 2016 server with IP 192.168.2.100. The DNS A and PTR record for this server

is configured static. Somehow, the static PTR was deleted. Is there any log to detect why this PTR is deleted or what you think is the cause?

Thank you!

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,055 questions
0 comments No comments
{count} votes

Accepted answer
  1. Dave Patrick 426K Reputation points MVP
    2023-01-26T21:54:29.36+00:00
    1 person found this answer helpful.

3 additional answers

Sort by: Most helpful
  1. Dave Patrick 426K Reputation points MVP
    2023-01-27T15:44:03.9433333+00:00

    shows the PTR record is deleted from one of Windows DNS server but did not show who deleted. does it mean that server deleted itself

    Bottom line is there may not be a clear record of who or what deleted a PTR record.

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    1 person found this answer helpful.

  2. Limitless Technology 43,916 Reputation points
    2023-01-31T08:54:36.07+00:00

    Hi. Thank you for your question and reaching out. I’d be more than happy to help you with your query.

    There may be several reasons why a static PTR record would be deleted on a Windows server, including:

    1. Manual Deletion: The PTR record may have been deleted manually by an administrator or another user with access to the DNS server.
    2. Automated script: The PTR record may have been deleted by an automated script that was designed to remove or update DNS records.
    3. DNS server software: There could be a bug in the DNS server software that caused the PTR record to be deleted.
    4. Security breach: A malicious actor may have gained unauthorized access to the DNS server and deleted the PTR record.

    To identify the cause of the deletion, you can check the event logs on the DNS server for any events related to the PTR record deletion. The DNS server logs events in the Microsoft-Windows-DNS-Server-Service/Admin log located in the Event Viewer under the Applications and Services Logs.

    You can also check the Windows Security Event Log for any suspicious activity such as logon failures, logon successes, and account management events that may indicate a security breach.

    It's also important to check the backup of the DNS Server and see if the PTR record was deleted from there as well.

    In addition, it would be a good idea to review any changes that have been made to the DNS server's configuration, including any scripts or automated tools that may have been used to update or manage DNS records.

    If you suspect that the deletion was caused by a security breach, it's crucial to take immediate action to secure your DNS server, including changing all credentials, reviewing the security settings, and conducting a thorough security audit of your network.

    If the reply was helpful, please don’t forget to upvote or accept as answer, thank you.

    1 person found this answer helpful.

  3. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more