Technical Tip : How to test anti-spam engine on phishing URL.
| Description | This article describes how to test the anti-spam engine on a phishing URL. |
| Scope | FortiGate. |
| Solution | Assuming that an email-filter is already configured, use FortiGuard to get a testing URL: https://www.fortiguard.com/webfilter/categories
In the category 'Phishing', get a URL for 'Full SSL INSPECTION'.
Example test URL for email content: https://www.fortiguard.com/wftest/61.html
The FortiGate submits all URL hyperlinks that appear in the email body to the FortiGuard service for checking. If a URL exists in the FortiGuard URL phishing list, the FortiGate removes the hyperlink from the message. The URL remains in place, but it is no longer a clickable hyperlink.
FortiGate will block it and will generate the log:
type="utm" subtype="emailfilter" eventtype="spam" level="notice" vd="root" policyid=33 sessionid=2982914 <output omitted >msg="email is reported as spam by ASE" size="237" attachment="no" |


