Skip to main content
tinkpen_FTNT
Staff
Staff
August 1, 2016

Technical Tip: Limitations of getting all email from a single source

  • August 1, 2016
  • 0 replies
  • 1258 views

Description

 
This article describes that in some cases there is a device in front of a FortiMail which is forwarding all emails to the FortiMail.
If so, there will be issues with SPF checks, since any domain with a hard fail (-all) in their SPF/TXT record will fail since the IP of the incoming device is not in their SPF/TXT records.  
 
Scope
 
FortiMail.


Solution

 

It is possible to overcome that either by disabling SPF checking, safelisting trusted domains, creating a recipient policy for trusted domains with an antispam policy with SPF checking disabled, or adding the IP/mask of the previous MTA as trusted IP using the below CLI commands:
 

config antispam trusted {mta | antispam-mta}

    edit <smtp_ipv4/mask>

end

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.