Skip to main content
Tibo
Visitor III
May 21, 2026
Solved

FortiMail: Recipient verification exception?

  • May 21, 2026
  • 1 reply
  • 97 views

Hello FortiPeople,

 

I’m checking if there’s a possibility to create a “recipient verification” exception for a particular source IP address. Let me explain:

We have a particular client application, which sends e-mails to multiple addresses in one SMTP session.

Whenever there’s a bad recipient address in the list of recipients, the application logically gets a “550 5.1.1 ... User unknown” reply from the FortiMail, via the recipient verification options set in the domain settings.

However, where this SMTP client differs compared to other SMTP clients like Exchange Online, is that it quits the session after this reply and will not send the mail for ANY of the recipient, so no one receives the e-mail when only 1 address is bad.

Exchange Online, for example, will continue on the same session (verified in the logs by session ID) and just continue for all the good addresses, which will then receive the mail.

 

We tested with Thunderbird as an SMTP client, which also gives the same behaviour (SMTP session stopped by client after “user unknown” error).

Also when setting the recipient verification action to “discard”, rather than “reject”, the result is the same, except that the error code is not detailing that the user is unknown.

So my question: is there a possibility to leave recipient verification ON at the domain-level (where it’s configured), but create an exception for particular source IP(s)?

 

Thanks in advance!

Best answer by AEK

Hi Tibo

Since FortiMail performs recipient verification at domain level and not at policy/profile level, I think the solution in this case is to disable it at FML level and let the mail server handle it.

1 reply

AEK
SuperUser
AEKAnswer
SuperUser
May 22, 2026

Hi Tibo

Since FortiMail performs recipient verification at domain level and not at policy/profile level, I think the solution in this case is to disable it at FML level and let the mail server handle it.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!