Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SKN
New Contributor

FortiMail Cloud - Mailbox count Exceed | Hybrid Environment | Recipient Address Verification

Hi everyone,
Great to be part of this community. I'm looking for technical guidance on a FortiMail mailbox licensing and RAV (Recipient Address Verification) issue.


Scenario

We have a FortiMail deployment licensed for 1200 mailboxes, but the system reports that the mailbox count has been exceeded.

Observed behavior:

  • Groups, distribution lists, and aliases are being counted as individual mailboxes
  • Relay-only addresses (non-existent local mailboxes) are also counted due to RCPT TO verification is not rejecting invalid recipients, even though Recipient Address Verification is configured for SMTP Server Verification
  • No Access Profiles are applied on policies

I found this community post discussing 'Recipient Address Verification' and 'Automatic Removal of Invalid Quarantine Accounts' for exceeding mailbox count: Link

 


Environment Details

  • Downstream mail systems: O365 and Zoho, ( Cloud Tenants ) 
  • Inbound mail flow:

Internet → FortiMail → O365 → Zoho

  • O365 is configured as an Internal Relay
  • If the recipient does not exist in O365, the connector forwards the message to Zoho
  • FortiMail is expected to verify recipients upstream, not accept all RCPT TO requests

Technical Issues I Need Help Solving

1. Licensing Impact: Will mailbox over-counting cause service degradation?

Looking for clarification on whether exceeding the licensed mailbox count affects:

  • Message delivery
  • AS/AV scanning
  • Quarantine functionality
  • MTA/SMTP throughput

2. Preventing non-mailbox objects from being counted

How do I configure FortiMail so it counts only:

  • Real user mailboxes
    Not:
  • Aliases
  • Groups
  • Distribution list

Ideally FortiMail should not generate local quarantine accounts for these objects.


3. RCPT verification is not rejecting invalid recipients

With SMTP Server Verification enabled, FortiMail should issue an SMTP RCPT TO check, but currently:

  • All RCPT TO requests return accepted
  • FortiMail therefore cannot determine mailbox existence
  • Quarantine accounts and mailbox entries continue to inflate

I need recommended configuration for environments where downstream servers (O365 + Zoho) behave differently during SMTP recipient lookups.


4. Best practice design for hybrid inbound mail (O365 + Zoho)

Looking for guidance on:

  • Proper FortiMail RAV configuration in multi-MTA environments
  • Ensuring upstream rejection of invalid users
  • Ensuring mailbox licensing only accounts for real user mailboxes

Important Constraint

LDAP-based Recipient Address Verification cannot be used in this environment.


Any FortiMail engineers or admins who have dealt with hybrid downstream MTAs or complex recipient verification setups — your recommendations would be extremely helpful.

1 Solution
Jean-Philippe_P
Moderator
Moderator

Hello SKN again,

 

I found this solution. Can you tell us if it helps, please?

  1. Licensing Impact: Exceeding the licensed mailbox count in FortiMail Cloud does not directly cause service degradation. However, it is important to ensure compliance with licensing terms. The mailbox count is primarily a reminder, and billing is based on the number of active mailboxes declared by the customer. Fortinet uses internal methods to validate this number.

  2. Preventing Non-Mailbox Objects from Being Counted: Fortinet does not consider distribution lists and aliases as billable mailboxes. Ensure that your configuration reflects this by verifying that these objects are not being counted as individual mailboxes. You may need to review your configuration to ensure that only real user mailboxes are being counted.

  3. RCPT Verification Not Rejecting Invalid Recipients: Ensure that the Recipient Address Verification is correctly configured. Go to Domain & User -> Domain -> Domain, select the protected domain, expand Recipient Address Verification, and enable the SMTP server for verification. If the SMTP server verification is not rejecting invalid recipients, verify the configuration of your downstream servers (O365 and Zoho) to ensure they are correctly responding to SMTP RCPT TO checks.

  4. Best Practice Design for Hybrid Inbound Mail (O365 + Zoho):

    • For environments where LDAP-based verification cannot be used, focus on ensuring that SMTP server verification is correctly configured. This involves setting up FortiMail to perform recipient verification using the SMTP protocol. Ensure that your downstream servers are configured to provide accurate responses to these checks.
    • Consider setting up a test environment to simulate the mail flow and verify that FortiMail is correctly rejecting invalid recipients.
    • Regularly review and update your configuration to ensure that only real user mailboxes are counted, and invalid quarantine accounts are automatically removed.

 

If issues persist, consider reaching out to Fortinet support for further assistance tailored to your specific environment.

Regards,
Jean-Philippe - Fortinet Community Team

View solution in original post

5 REPLIES 5
Anthony_E
Community Manager
Community Manager

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
Jean-Philippe_P
Moderator
Moderator

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

Regards,
Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello SKN again,

 

I found this solution. Can you tell us if it helps, please?

  1. Licensing Impact: Exceeding the licensed mailbox count in FortiMail Cloud does not directly cause service degradation. However, it is important to ensure compliance with licensing terms. The mailbox count is primarily a reminder, and billing is based on the number of active mailboxes declared by the customer. Fortinet uses internal methods to validate this number.

  2. Preventing Non-Mailbox Objects from Being Counted: Fortinet does not consider distribution lists and aliases as billable mailboxes. Ensure that your configuration reflects this by verifying that these objects are not being counted as individual mailboxes. You may need to review your configuration to ensure that only real user mailboxes are being counted.

  3. RCPT Verification Not Rejecting Invalid Recipients: Ensure that the Recipient Address Verification is correctly configured. Go to Domain & User -> Domain -> Domain, select the protected domain, expand Recipient Address Verification, and enable the SMTP server for verification. If the SMTP server verification is not rejecting invalid recipients, verify the configuration of your downstream servers (O365 and Zoho) to ensure they are correctly responding to SMTP RCPT TO checks.

  4. Best Practice Design for Hybrid Inbound Mail (O365 + Zoho):

    • For environments where LDAP-based verification cannot be used, focus on ensuring that SMTP server verification is correctly configured. This involves setting up FortiMail to perform recipient verification using the SMTP protocol. Ensure that your downstream servers are configured to provide accurate responses to these checks.
    • Consider setting up a test environment to simulate the mail flow and verify that FortiMail is correctly rejecting invalid recipients.
    • Regularly review and update your configuration to ensure that only real user mailboxes are counted, and invalid quarantine accounts are automatically removed.

 

If issues persist, consider reaching out to Fortinet support for further assistance tailored to your specific environment.

Regards,
Jean-Philippe - Fortinet Community Team
SKN

Hello Jean-Philippe,

 

Thank you very much for the detailed clarification.

 

Your explanation regarding the mailbox count exceeding and the licensing impact is clear — Now understand that exceeding the displayed mailbox count in FortiMail Cloud does not directly affect service and is mainly a compliance reminder.

 

The guidance on RCPT verification not rejecting invalid recipients is also helpful. Will proceed to review and correctly configure the downstream servers (Microsoft 365 and Zoho) to ensure that they respond properly to SMTP RCPT TO checks.

 

Thank you again for the useful insights.

 

Regards,

SKN

Jean-Philippe_P

Hello SKN, 

 

Glad that it could help you!

 

Have a nice day and do not hesitate!

Regards,
Jean-Philippe - Fortinet Community Team
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors