Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jasonh1
New Contributor

Fortimail FORGED IP blocking

Hello

 

how to block FORGED IP in Fortimail v. 6.2.7 ?

 

thx

1 REPLY 1
Markus_M
Staff
Staff

Hi jasonh1,

 

if someone is faking an IP to an FQDN you would be able to detect this by a reverse lookup of that IP. It would not give the expected data and not match a forward lookup query.

 

I'm not a FortiMail expert, but it seems FML has a similar setting as this older article implies:

https://community.fortinet.com/t5/FortiMail/Technical-Note-Explanation-of-forged-IP/ta-p/198116?exte...

 

I see on a FML also the "Sender Policy Framework" that might help doing the same thing (doing a DNS lookup on the senders domain to see whether the senders mail address has been faked.

 

Markus

Labels
Top Kudoed Authors