FortiMail
FortiMail provides advanced, multi-layer protection against the full spectrum of email-borne threats
tinkpen_FTNT
Staff
Staff
Article Id 198386

Description

 
This article describes that in some cases, a blank sender may mean that the email is spam. There are two places where the sender can be blank. One is in the envelope and the other is in the From field in the data section of the email. 

The following article explains the process of configuring the FortiMail so that blank senders/domains are blocked.
 
Scope
 
FortiMail.


Solution

 
Blocking an Empty Sender in the Envelope

Profile -> Session -> Edit the inbound session profile -> Unauthenticated Session Settings, Select 'Reject empty domains', and then OK.

Blocking an Empty Sender in the From field in the Data section
 
  1. Go to Profile -> Dictionary.

  2. Create a new dictionary with the following 2 regex expressions:

    ^From: $
    ^From:$

    Ensure that:
    • Enable pattern maximum weight limit.
    • Search header.
    • Search body.
    Are all selected for each of the 2 entries and that the Pattern weight and Pattern maximum weight should both be left at 1.

  3. Select 'Create'.
                                                                                
    2025-01-30 10_46_02-FortiMail.jpg
  4. Go to Profile -> AntiSpam and edit the antispam policy in use.

  5. Select Dictionary -> With dictionary profile: and select the Dictionary that has just been created.

  6. Select OK.
       
                                                        

2025-01-30 10_45_12-FortiMail.jpg
This will prevent emails with empty senders/domains from getting to users.