Whitelist DocuSign
I am running FortiMail v7.0.x and the spam aggressiveness is set a bit on the high side. We are aware of email scams that appear to come from DocuSign but are not from DocuSign. These are all getting quarantined.
However, legit emails from DocuSign are also getting quarantined and I am looking for the best way to allow these.
Currently, every time a user receives a real DocuSign email, FortiMail will move it to quarantine due to "Sender Alignment: (From value: docusign.net) does not align with Reply-To domain"
As a convenience, when someone sends you a (real) DocuSign email, the From address is something like 'Mike Smith via DocuSign <dse_na2@docusign.net>' but the Reply-To address is the sender's email address. For example 'mike.smith@companyx.com'.
DocuSign has a KB article that lists their domains and IP addresses - https://www.docusign.com/trust/security/esignature
How can I create a recipient policy that says if an email comes from one of these IPs or domains, whitelist and deliver the message, bypassing quarantine, spam outbreak, etc?
