Created on
06-30-2020
11:01 PM
Edited on
06-20-2025
12:31 AM
By
jiaqiangji_FTNT
Description
This article describes how to block email by file signatures.
Scope
FortiMail.
Solution
If the SHA-1/SHA-256(Secure Hash Algorithm) hash values of some known virus-infected files are obtained, add these values as file signatures and then, in the antivirus profile, enable the actions against these files.
Manually add the SHA-1/256 checksums one by one and import such a checksum list in csv or txt format is possible.
The signatures can be exported as a .csv file.
Because not all attachment files are virus carriers, the FortiMail file signature check only supports the following file types:
.7z, .bat, .cab, .dll, .doc, .docm, .dotm, exe, .gz, .hta, .inf, .jar, .js, .jse, .msi, .msp, pdf, .pif, .potm, .ppam, .ppsm, .ppt, .pptm, .pptx, .reg, .scr, .sldm, .swf, .tar, .vbe, .ws, .wsc, .wsf, .wsh, .xlam, .xls, .xlsm, .xlsx, .xltm, .Z, and .zip files.
Above and more can be confirmed in the link: Configuring antivirus profiles, file signatures, and antivirus action profiles




The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.