Skip to main content
roci
New Member
October 16, 2025
Question

Whitelisting based on Header From address (not From)

  • October 16, 2025
  • 2 replies
  • 551 views

Frequently, legit emails will get caught in greylist or quarantine where the Header From address shows the actual organization (for example, no_reply@standard.com) but the From address is something like 01020199df60110e-adad6878-1234-4d5f-9b1c-1d93aa94033a-000000@eu-west-1.amazonses.com.

 

Typically, when an email gets quarantined due to 'Sender Alignment' I would add their email domain to a whitelist that is attached to one of my Recipient Policies that bypasses SPF Sender Alignment.

 

However when the sender uses a service such as amazonses or sendgrid, where the header-from and the header don't match, whitelisting won't work since I assume the whitelist is using from (vs header from).

 

How can I ensure these emails get delivered successfully without opening up all of Amazon SES or sendgrid?

 

Is there a way to create an exception list for trusted DKIM domains? Or can you advise on a better way to handle this? I don't see any other posts about this topic so I suspect maybe my spam filtering strategy is not ideal.

 

How are you successfully filtering incoming emails from legitimate companies that are using bulk messaging services such as Sendgrid and AmazonSES? These services have so many IPs that can change.

 

 

2 replies

kolatpo5
New Member
October 17, 2025

We refuse allow list requests. 3rd parties should manage their email correctly in order to make their config is good and they do not end up on known deny lists.

abelio
SuperUser
SuperUser
October 17, 2025

Hello roci
Consider last 7.6.4 firmware to manage Header From as sender
(https://docs.fortinet.com/document/fortimail/7.6.4/release-notes/945544/whats-new)

7.6x also includes several enhancements to manage sender alignment in a more flexible manner than earlier versions

 

hope it helps

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!