Skip to main content
luisjo
New Member
July 10, 2026
Question

False Positive SPF Detections in FortiMail 8.0.0

  • July 10, 2026
  • 2 replies
  • 45 views

Good day, everyone.

I have been experiencing intermittent SPF false positives in **FortiMail 8.0.0**. In some cases, FortiMail reports that the sender's domain does not have an SPF record. However, after verifying the domain manually using both our internal DNS servers and public DNS servers, the SPF record is available and resolves correctly.

I would like to know if there is any configuration or best practice that could help reduce these false positives. For example:

* Is it possible to increase the DNS query timeout used by FortiMail?
* Is it possible to adjust or reduce the DNS cache timeout?
* Are there any recommended DNS-related settings for improving SPF validation reliability?

One behavior I have noticed is that multiple emails from the same sender domain, received at nearly the same time, may produce different SPF results. Some messages pass SPF successfully, while others are rejected because FortiMail reports that no SPF record was found.

Our environment consists of **two FortiMail appliances running in Active-Active HA**, so I am also wondering whether anyone has experienced similar behavior in a comparable deployment.

Any recommendations or shared experiences would be greatly appreciated. Thank you.
 

2 replies

abelio
SuperUser
SuperUser
July 10, 2026

Hello
which DNS servers are  configured in your Fortimail?   Those DNS servers are in charge of lookups.

Check once again: 
https://docs.fortinet.com/document/fortimail/8.0.0/cli-reference/774908/system-dns
 

There you'll have cache, timeout settings and more.

SPF validation is just another dns query, no extra science.

If you're using A-A  HA, remember that  not all settings are synchronized between primary and secondary.
DNS settings is one of them
https://docs.fortinet.com/document/fortimail/8.0.0/administration-guide/846008/using-high-availability-ha#Settings_that_are_not_synchronized_by_HA

hope it helps


 

luisjo
luisjoAuthor
New Member
July 10, 2026

Hello, good day, Abel.

I am currently using internal DNS server because, due to the network configuration, I do not have full access to external DNS servers.

My question is whether adjusting the DNS timeout values could help mitigate these intermittent false positives, or if this issue would need to be resolved directly on the DNSserver side.

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.