Skip to main content
ESCHAN_FTNT
Staff
Staff
June 20, 2017

Technical Tip: FortiMail classifier explanation

  • June 20, 2017
  • 0 replies
  • 14525 views

Description

 
This article explains some of the common classifiers.
Every history log contains one field called Classifier. 

The Classifier field displays which FortiMail scanner applies to the email message. For example, 'Banned Word' means the email messages were detected by the FortiMail banned word scanner. 

The Disposition field specifies the action taken by the FortiMail unit. There are a total of 66 different types of classifiers to date at the time of this article being written (or 65 as 'Virus as Spam' is obsolete and only before the v4.3 release).


Scope

 
All firmware.


Solution

 

Bypass Scan on Auth.
 
This means that the Email was not scanned since authentication was successful. This setting can be changed in the Antispam profile, under Scan Options 'Bypass scan on SMTP authentication'.

Session Domain.
 
Recipient email domain unable to be resolved via configured DNS.

Session Limits.
 
Total sessions exceeding the matching configured session profile under Connection Settings or SMTP limits.

Sender Reputation.
 
A huge increase in emails sent from the same sender (IP address) caused it to hit the sender's reputation. Check on the Session profile under 'Sender Reputation'.

Session Remote.
 
Sessions are rejected by the remote server and the FortiMail is just relaying this information to the sender and logging it. This only appears in Transparent Mode.
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!