Production mail has stopped because the reverse DNS is wrong.
The forward records existed. The servers had addresses. What they did not have were the PTR records that let another mail system look up an IP address and confirm the name behind it.
Without that, messages are being rejected or delayed. The client's mail operation is at a standstill.
I opened an urgent ticket with the colocation provider and attached the records that need to be created. The list is long. Customer domains, mail hosts, application hosts, name servers, monitoring, load balancing, and internal services all sit across a small set of public addresses.
The immediate request is narrower than the full list. The production mail host needs the correct PTR record before delivery can return to normal.
Email trust is assembled from several checks. A server can accept a connection and still look suspicious. Forward DNS, reverse DNS, sender policy, reputation, and the behavior of the sending system all matter. Miss one layer and the message may never get through.
I sent the request several times and followed the provider ticket. Another person reported that turning on SSL in Outlook was helping some users, but that does not create the missing reverse-DNS record.
I cannot make this change from the mail server. The provider controls the reverse zone. I can give them the exact host and address, keep the ticket moving, and test delivery after they say the record is in place.
The subject line was exactly as calm as the outage allowed.
PTR records needed ASAP.
That is still the status. The request is open, production mail is waiting, and the next action belongs to the provider.