Skip to main content
mattia1
Staff
Staff
August 10, 2026

Technical Tip: How to enable Header From Check on Access Control Rule

  • August 10, 2026
  • 0 replies
  • 53 views

Description

This article describes how to enable a Header From Check on an Access Control Rule.

Scope

FortiMail v8.0.

Solution

  1. Enable the Header From option in access control.


GUI:
Note: An Advanced Management License is required to enable this option. In the GUI, navigate to the System -> FortiGuard -> Licensed Feature -> Advanced Management -> Header From option in access control, select 'Enable', and select Apply.

5264f21a.png


  1. A message will appear stating 'Licensed feature setting has been changed. The GUI will now reload'.


be506ea9.png


  1. To create a new access control rule checking the Header From:


Navigate to Policy -> Access Control -> New -> Configure the rule parameters as needed -> Choose any of the following options: Envelope From, Header From, Envelope or header from.

b1d340ee.png


CLI:

#config policy access-control receive
(receive)#edit <rule_id>
(1)#set sender-option {envelope-from | envelope-or-header-from | header-from}
(1)#end


7004a0cf.png


  1. Results:

  • If an Email is sent with a different Header From as configured, it will not match the rule and will be moved to the next rule with the configured action. In this test, it is a deny rule.


f35ff626.png


  • If an Email is sent with the configured Header From, it will match the rule and the configured action will be taken.


17c2ee7c.png

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!