Skip to main content
GabrielAuYong_FTNT
Staff & Editor
Staff & Editor
December 2, 2011

Technical Tip: Forged IPs

  • December 2, 2011
  • 0 replies
  • 4271 views

Description

 

This article explains what a forged IP is.


Scope

 

FortiMail.


Solution

 

When the forged IP scan is enabled, the FortiMail will perform a reverse (PTR record) lookup on the IP address of a connecting host to get a hostname. It will then perform a forward (A record) lookup on that hostname, and compare the returned IP address to that of the connecting host. If they do not match, then the IP address is considered 'forged'.


This can occasionally cause false-positives with hosts with multiple A records. The FortiMail will check the connecting IP against all the A records for the hostname, but some DNS servers will return a truncated list, possibly cutting off the IP address that was actually connecting.

 

FortiMail uses Sender Policy Framework to achieve this. Settings for SPF check can be configured in AntiSpam or Session profiles. For more information, see Enable SPF checking for incoming email and Technical Tip: SPF Checking on the FortiMail.

 

The Forged IP Check option was available under Antispam Profiles up to version 5.x, after which it was removed. Starting from version 7.6.3, it has been reintroduced and the option can now be found under Policy -> Access Control -> Receiving. For more details, see 'Forged IP check' under Controlling SMTP access and delivery.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!