Created on
12-01-2011
05:03 PM
Edited on
11-25-2025
06:27 AM
By
Stephen_G
Description
This article explains what a forged IP is.
Scope
FortiMail.
Solution
When the forged IP scan is enabled, the FortiMail will perform a reverse (PTR record) lookup on the IP address of a connecting host to get a hostname. It will then perform a forward (A record) lookup on that hostname, and compare the returned IP address to that of the connecting host. If they do not match, then the IP address is considered 'forged'.
FortiMail uses Sender Policy Framework to achieve this. Settings for SPF check can be configured in AntiSpam or Session profiles. For more information, see Enable SPF checking for incoming email - FortiMail cookbook and Technical Tip: SPF Checking on the FortiMail.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.