Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AEK
SuperUser
SuperUser

Can FortiMail send e-mail body to FortiGuard?

Hi FML experts

I know that FML sends some attachments for scan to cloud Sandboxing. I also know that some FML features may send embedded links, source IP, e-mail hashes, but not mail body, to FortiGuard to compare with FortiGuard DNSBL, SURBL and spam DBs.

But is there any option in FortiMail antispam (or other profile) that requires from FML to send the email body to FortiGuard for scan?

AEK
AEK
7 REPLIES 7
Jean-Philippe_P
Moderator
Moderator

Hello AEK!, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
AEK

Thank you Jean!

AEK
AEK
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello again AEK :)

 

I found this solution with a GPT engine, can you tell me if it helps, please?

 

In FortiMail, the standard operation for antispam and other security features typically does not involve sending the entire email body to FortiGuard for scanning. Instead, FortiMail focuses on analyzing metadata, such as embedded links, source IP addresses, and email hashes, to determine the legitimacy of the email.

While FortiMail does use cloud-based services for scanning certain attachments through sandboxing, sending the complete email body for scanning is not a standard feature due to privacy and security considerations. The system is designed to maintain user confidentiality while still providing effective spam and threat detection.

If you're looking for specific configurations or advanced features, it's always a good idea to consult the official FortiMail documentation or reach out to Fortinet support for detailed guidance tailored to your deployment. If you have further questions about FortiMail configurations or features, feel free to ask!

Jean-Philippe - Fortinet Community Team
AEK

Hi Jean

Sorry for the late response.

Certainly it sounds logic that the mail content is not sent to FortiGuard (or to other location), however I believe GPT can't provide a 100% verified answer in such case, as long as it is not officially published by Fortinet.

AEK
AEK
filiaks1
Contributor II

Why do you want to send the email in first place to Fortguard is the question?

 

Usually files are send to FortiSandbox on-prem/cloud and FortiNDR as well. 

 

The mail text scanning is done on-prem with DLP , Content profile and SPAM that still could pull Threat intelligence from FortiGuard.  

 

Other than that the urls in the message could be subject to check with fortigard database:

 

Configuring URL filter profiles | FortiMail Appliances and Virtual Machines 7.6.3 | Fortinet Documen...

AEK

Thanks filiaks

This is indeed logical. However I just need something official, if it exists.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors