False Positive SPF Detections in FortiMail 8.0.0
Good day, everyone.
I have been experiencing intermittent SPF false positives in **FortiMail 8.0.0**. In some cases, FortiMail reports that the sender's domain does not have an SPF record. However, after verifying the domain manually using both our internal DNS servers and public DNS servers, the SPF record is available and resolves correctly.
I would like to know if there is any configuration or best practice that could help reduce these false positives. For example:
* Is it possible to increase the DNS query timeout used by FortiMail?
* Is it possible to adjust or reduce the DNS cache timeout?
* Are there any recommended DNS-related settings for improving SPF validation reliability?
One behavior I have noticed is that multiple emails from the same sender domain, received at nearly the same time, may produce different SPF results. Some messages pass SPF successfully, while others are rejected because FortiMail reports that no SPF record was found.
Our environment consists of **two FortiMail appliances running in Active-Active HA**, so I am also wondering whether anyone has experienced similar behavior in a comparable deployment.
Any recommendations or shared experiences would be greatly appreciated. Thank you.
Â
