Skip to main content
gdf1
New Member
February 27, 2026
Question

FortiMail DLP Standard Compliance & Fingerprint

  • February 27, 2026
  • 10 replies
  • 476 views

From FortiMail documentation, one can read:

Sensitive data can be any of the following types:

Predefined: For your convenience, FortiMail comes with a list of predefined information types, such as credit card numbers and SIN numbers. To view the predefined sensitive data, go to Data Loss Prevention > Sensitive Data > Standard Compliance.

 

Indeed, I can find the list of pre-defined sensitive data and their names made clear what they match most of the time. However, I was wondering if it was possible to get details on how these default predefined sensitive data are actually configured. For instance, would "Illegal_Drugs" match drug names in any language? The same question applies to "Offensive_Words". If not, knowing the structure of these would help configure our own fingerprint.

 

Regarding fingerprint, the documentation states:

DLP document fingerprinting

One of the DLP techniques to detect sensitive data is fingerprinting (also called document fingerprinting). Most DLP techniques rely on you providing a characteristic of the file you want to detect, whether it’s the file type, the file name, or part of the file contents. Fingerprinting is different in that you provide the file itself. The FortiMail unit then generates a checksum fingerprint and stores it. The FortiMail unit generates a fingerprint for all email attachments, and compares it to all of the fingerprints stored in its fingerprint database. If a match is found, the configured action is taken.

 

Does that mean DLP document fingerprinting can detect that a part of a document being attached in the email or not? Let's say the document used to create the fingerprint is an .xlsx file of 50 company names. Would this match the exact same document being attached in the email or would it match any .xlsx document containing any single one of the company names? Is this just a matching on the file hash or an actual document fingerprinting?

10 replies

Jean-Philippe_P
Staff & Editor
Staff & Editor
March 2, 2026

Hello gdf1, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

Jean-Philippe - Fortinet Community Team
gdf1
gdf1Author
New Member
March 2, 2026

Hi @Jean-Philippe_P ,

 

Many thanks for checking here! I am deep diving on this as well, I will let you know if I find anything.

Jean-Philippe_P
Staff & Editor
Staff & Editor
March 3, 2026

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

Jean-Philippe - Fortinet Community Team
gdf1
gdf1Author
New Member
March 3, 2026

Hello @Jean-Philippe_P,

 

I did some tests this morning. Let me share the steps performed:

  1. Generate 2 test files containing 10 randomly generated first name/last name/IBAN, one being names.xlsx and another being names.txt.
  2. Create 2 separate Fingerprints from the Data Loss Prevention -> Sensitive Data tab. One (DLP_FP_XLSX) for names.xlsx and the other (DLP_FP_TXT) for the names.txt.
  3. Create a rule (DLP_TEST_FP) matching both generated fingerprints either in body or attachment from the Data Loss Prevention -> Rule & Profile tab.
  4. Assign the rule to the used DLP profile.

The result of this is that, when the entire names.xlsx or names.txt file is attached to the email being sent, then the DLP rule is properly matched. However, if I paste a sample of it in the email body or send part of these files as an attachment, the DLP rule is not triggered. So I guess the fingerprint is a basic file hash and not a complete file fingerprint.

 

Now, the question is, how can I configure a "Data Template" instead of "Fingerprint" based on my own data? (For instance the name list from names.xlsx/names.txt). Exactly like (I guess) it's done for the "Standard Compliance" sets.

Jean-Philippe_P
Staff & Editor
Staff & Editor
March 3, 2026

Hello again gdf1,

 

Thanks for sharing those tests :)

 

I found this answer, can you tell us if it helps, please?

 

Predefined Sensitive Data Configuration

FortiMail provides a list of predefined sensitive data types, such as credit card numbers and SIN numbers, which can be accessed under Data Loss Prevention > Sensitive Data > Standard Compliance. However, the specific configuration details of these predefined types, such as whether "illegal_drugs" matches drug names in any language or the structure of "offensive_words," are not explicitly detailed in the documentation. This information is typically proprietary and not disclosed in public documentation.

 

DLP Document Fingerprinting

Document fingerprinting in FortiMail involves generating a checksum fingerprint of the entire document. This means that the DLP system will match the exact document that was fingerprinted. If you attach the exact same document to an email, the DLP rule will trigger. However, if only a part of the document is included in the email body or as a partial attachment, the rule will not trigger. This indicates that the fingerprinting is based on the file hash rather than content-based matching.

 

Configuring a Data Template

To configure a "data template" similar to the predefined "standard compliance" sets, you would typically use user-defined sensitive data patterns. This involves specifying patterns or regular expressions that match the data you want to detect. Unfortunately, the context provided does not include specific steps for creating a data template based on your own data, such as a list of names from names.xlsx or names.txt.

 

Follow-ups and Clarification Questions

  1. Predefined Data Details: Would you like more information on how to create custom sensitive data patterns using regular expressions or specific keywords?

  2. Fingerprinting Limitations: Are you interested in exploring alternative methods for detecting partial document content, such as using content-based DLP rules?

  3. Data Template Configuration: Would you like guidance on using regular expressions or other methods to create custom data templates for specific data types?

Jean-Philippe - Fortinet Community Team
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!