Hi FML experts
I know that FML sends some attachments for scan to cloud Sandboxing. I also know that some FML features may send embedded links, source IP, e-mail hashes, but not mail body, to FortiGuard to compare with FortiGuard DNSBL, SURBL and spam DBs.
But is there any option in FortiMail antispam (or other profile) that requires from FML to send the email body to FortiGuard for scan?
Hello AEK!,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Thank you Jean!
Hello,
We are still looking for an answer to your question.
We will come back to you ASAP.
Thanks,
Hello again AEK :)
I found this solution with a GPT engine, can you tell me if it helps, please?
In FortiMail, the standard operation for antispam and other security features typically does not involve sending the entire email body to FortiGuard for scanning. Instead, FortiMail focuses on analyzing metadata, such as embedded links, source IP addresses, and email hashes, to determine the legitimacy of the email.
While FortiMail does use cloud-based services for scanning certain attachments through sandboxing, sending the complete email body for scanning is not a standard feature due to privacy and security considerations. The system is designed to maintain user confidentiality while still providing effective spam and threat detection.
If you're looking for specific configurations or advanced features, it's always a good idea to consult the official FortiMail documentation or reach out to Fortinet support for detailed guidance tailored to your deployment. If you have further questions about FortiMail configurations or features, feel free to ask!
Hi Jean
Sorry for the late response.
Certainly it sounds logic that the mail content is not sent to FortiGuard (or to other location), however I believe GPT can't provide a 100% verified answer in such case, as long as it is not officially published by Fortinet.
Why do you want to send the email in first place to Fortguard is the question?
Usually files are send to FortiSandbox on-prem/cloud and FortiNDR as well.
The mail text scanning is done on-prem with DLP , Content profile and SPAM that still could pull Threat intelligence from FortiGuard.
Other than that the urls in the message could be subject to check with fortigard database:
Thanks filiaks
This is indeed logical. However I just need something official, if it exists.
User | Count |
---|---|
2431 | |
1304 | |
778 | |
561 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.