Skip to main content
Muri
Explorer
May 6, 2024
Question

Fortimail - SPAM mails - how to avoid such messages

  • May 6, 2024
  • 5 replies
  • 3405 views
 

Hello,

can anyone suggest me, how to avoid such simmilar SPAM messages?

2024-05-06_14h55_27.png

2024-05-06_14h58_56.png

5 replies

AEK
SuperUser
SuperUser
May 6, 2024

Hi Muri

In your AntiSpam profile have you enabled FortiGuard filter with URL category "default"? If you did it already then the above mails could be legitimate mails (not categorized as SPAMs). In that case you can deny them with blocklist.

AEK
Muri
MuriAuthor
Explorer
May 7, 2024

Hello @AEK 
Yes, we set the URL category by our selfe and picked also more categoryes as are included in "default" profile:

2024-05-07_07h41_19.png

AEK
SuperUser
SuperUser
May 7, 2024

Then I guess the received mails are not actually spam, or they don't have the spam qualifications. Maybe spear phishing (which is not spam), but you can analyze them deeper ans see if they are really so.

As mentioned before, you may still block them with blocklists.

AEK
Cajuntank
Contributor III
May 6, 2024

Adding to what @AEK mentioned, I might also include at least 1 or 2 DNSBL lists to your AntiSpam profile (eg... zen.spamhous.org, b.barracudacentral.org, etc...). Also, based on the examples you gave are from varied countries, do you typically receive email from said countries or other countries in general? You can look at implementing Geo IP blocking as an additional option if this is applicable.

 

https://community.fortinet.com/t5/FortiMail/Technical-Tip-How-to-block-incoming-emails-from-some-countries/ta-p/307660#:~:text=In%20FortiMail%2C%20it%20is%20possible,countries%20that%20will%20be%20blocked

 

The example shown applies to the Access Control policy or you can do it at the IP Policy instead... each has there slight pros and cons. For me, the IP Policy was recommended to me by Fortinet support and since I receive email from very few countries outside of the USA, I built a Allowed_Countries policy (Inbound Session) to be on top with a few countries defined, then a policy under it called Blocked_Countries that had all countries with policy set to reject.

 

Muri
MuriAuthor
Explorer
May 7, 2024

Hello @Cajuntank 

we already use list of 10. DNSBL providers:

2024-05-07_07h46_34.png

The Geo IP blocking sounds as good idea in this case. Maybe we can try with this yes.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.