Technical Tip: Post-upgrade validation checklist for FortiMail
Description
This article describes how to validate the operation of FortiMail after a firmware upgrade.
Scope
FortiMail.
Solution
After upgrading FortiMail firmware, perform the following validation checks to confirm that the system is operating normally.
Verify firmware version.
Navigate to Dashboard -> Status.
Confirm that the displayed firmware version matches the intended upgrade version.
Alternatively, from the CLI:
get system status
Verify the firmware build and version information.
Confirm system services are running.
Verify that all FortiMail services have started successfully.
Review:
Status page.
Email logs.
System alerts.
Check for any service startup failures or unexpected warnings.
Verify mail flow.
Send a test email:
From an external sender to an internal recipient.
From an internal sender to an external recipient.
Confirm that:
Messages are delivered successfully.
No unusual delays occur.
Mail logs show successful delivery.
Check the mail queue.
Navigate to Monitor -> Mail Queue.
Verify that:
Mail queues are processing normally.
No significant increase in queued messages is observed.
No messages remain stuck in the queue.
Verify DNS resolution.
Confirm that FortiMail can resolve external domains.
This is especially important after VM migrations, network changes, or infrastructure maintenance.
Review logs for DNS-related errors.
Verify antivirus and antispam services.
Confirm that security scanning services are functioning correctly.
Verify:
Antivirus updates are current.
Antispam services are operational.
Security profiles remain enabled.
Verify that mail policies are in place.
Review configured:
Access control policies.
IP Policies.
Recipient policies.
Confirm that all expected configurations remain intact after the upgrade.
Review system logs.
Navigate to Monitor -> Log.
Check for:
Service failures.
Database errors.
Network connectivity issues.
Licensing errors.
Investigate any recurring critical or warning events.
Verify HA status (if applicable).
For HA deployments: navigate to System -> High Availability.
Verify that:
All members are online.
Synchronization status is normal.
The cluster is functioning as expected.
10. Monitor the system.
Monitor the system for several hours after the upgrade.
Pay attention to:
Mail processing performance.
Resource utilization.
User-reported issues.
Unexpected log entries.
