Skip to main content
alya
Staff
Staff
May 15, 2026

Technical Tip: How to perform different actions to filter keywords in email

  • May 15, 2026
  • 0 replies
  • 27 views

Description


This article describes how to configure different actions in Fortinet FortiMail to filter emails containing specific keywords by using the Data Loss Prevention (DLP) feature.

Scope

FortiMail.

Solution


In some environments, administrators may require different actions to be applied when certain keywords are detected in an email subject, body, or attachment content where the actions in antispam Banned words only applied to a single email action for all banned words.


Examples include:

  • Rejecting emails containing restricted words.

  • Quarantining suspicious messages.

  • Tagging or monitoring emails for auditing purposes.

This can be achieved by configuring a DLP dictionary and applying the required action through a DLP profile.

Step 1: Configure DLP rules.


Configure the keywords or patterns that FortiMail should detect as described in Configuring DLP Rules, and configure the following rules:

  • Rule name.

  • Scan rule.

  • Condition: Subject/body.

  • Contains: virus (keyword in the email).


Add multiple keywords, such as virus/spam/password.

Step 2: Configure a DLP profile.


After creating the DLP rules, add them to a DLP profile. Configure a DLP profile as per Configuring DLP Profiles, add the previously created DLP rules, and configure a different action for each.

Step 3: Apply the DLP profile in the recipient policy.

Go to Policy -> Recipient Policy and apply the DLP to the current policy or create a new one matching the specific sender or recipient.