Skip to main content
romanr
New Member
April 25, 2014
Question

Deep Header Check and X-Originating-IP

  • April 25, 2014
  • 13 replies
  • 20024 views
Hi, does anyone got some details about the Black/White IP checking on the Fortimail? Esp on the use of the X-Originating-IP attribute? I always thought, that Blacklisted Sender IPs will not hit if the e-mail comes from a whatever not listed ip address unless " Deep Header Check" Option is used. Then the Fortimail will also look into the headers of the mail and apply antispam actions if it finds a listed IP in the header section of the mail. Exchange 2013 Frontent Proxy Service sets the X-Originating-IP Attribute in the mail header when transporting authenticated mail. Fine! When this outbound mail now gets routed to a Fortimail - The Fortimail will also check the X-Originating-IP attribute - even if Deep Header Scanning isn' t enabled... It also tells me, there is a SPF violation (even this is disabled on the session profile) somehow confusing.... Br, Roman

    13 replies

    Bromont_FTNT
    Staff
    Staff
    April 25, 2014
    To be honest I' m surprised you don' t have SPF enabled in the AS or session profiles at all... typically the Fortimail would use the connecting IP for SPF check but if the connecting IP is in a private address range then it looks at the last Received header for SPF regardless of whether deep header is enabled.
    romanr
    romanrAuthor
    New Member
    April 25, 2014
    SPF is enabled on all policies that would connect from the outer world - So only on incoming policies. Like Session policy which handles 0.0.0.0/0 and Access + Recipient policies that have outside sources. Especially in this situation - where the customer had to forward a lot of mail via his mail servers to the outside - we carefully watched not to check against SPF for mails from the DMZ based mail servers...
    Bromont_FTNT
    Staff
    Staff
    May 9, 2014
    Any updates? Did you get the issue resolved?
    emnoc
    New Member
    April 25, 2014
    To be honest I' m surprised you don' t have SPF enabled in the AS or session profiles at all... typically the Fortimail would use the connecting IP for SPF check but if the connecting IP is in a private address range then it looks at the last Received header for SPF regardless of whether deep header is enabled.
    I aggreed on this statement and is how I handle AS protection. I drop maybe 2-5% of email due to SPF checks thru-out the day. Not a lot but it helps. On the exchange-server, i would build a profile that does not use deep-header check nor SPF validation. This would prevent AS inspection dropping mail, that' s legit. You can always disable AS inspection for mail from trusted host but it' s adviseable to ensure proper mail from trusted inside relays. fwiw: Since " X-Originating-IP" covers the sender, you could build a ip based policy on this source/mask and allow this traffic.