Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SKN
New Contributor

FortiMail Cloud - Mailbox count Exceed | Hybrid Environment | Recipient Address Verification

Hi everyone,
Great to be part of this community. I'm looking for technical guidance on a FortiMail mailbox licensing and RAV (Recipient Address Verification) issue.


Scenario

We have a FortiMail deployment licensed for 1200 mailboxes, but the system reports that the mailbox count has been exceeded.

Observed behavior:

  • Groups, distribution lists, and aliases are being counted as individual mailboxes
  • Relay-only addresses (non-existent local mailboxes) are also counted due to RCPT TO verification is not rejecting invalid recipients, even though Recipient Address Verification is configured for SMTP Server Verification
  • No Access Profiles are applied on policies

I found this community post discussing 'Recipient Address Verification' and 'Automatic Removal of Invalid Quarantine Accounts' for exceeding mailbox count: Link

 


Environment Details

  • Downstream mail systems: O365 and Zoho, ( Cloud Tenants ) 
  • Inbound mail flow:

Internet → FortiMail → O365 → Zoho

  • O365 is configured as an Internal Relay
  • If the recipient does not exist in O365, the connector forwards the message to Zoho
  • FortiMail is expected to verify recipients upstream, not accept all RCPT TO requests

Technical Issues I Need Help Solving

1. Licensing Impact: Will mailbox over-counting cause service degradation?

Looking for clarification on whether exceeding the licensed mailbox count affects:

  • Message delivery
  • AS/AV scanning
  • Quarantine functionality
  • MTA/SMTP throughput

2. Preventing non-mailbox objects from being counted

How do I configure FortiMail so it counts only:

  • Real user mailboxes
    Not:
  • Aliases
  • Groups
  • Distribution list

Ideally FortiMail should not generate local quarantine accounts for these objects.


3. RCPT verification is not rejecting invalid recipients

With SMTP Server Verification enabled, FortiMail should issue an SMTP RCPT TO check, but currently:

  • All RCPT TO requests return accepted
  • FortiMail therefore cannot determine mailbox existence
  • Quarantine accounts and mailbox entries continue to inflate

I need recommended configuration for environments where downstream servers (O365 + Zoho) behave differently during SMTP recipient lookups.


4. Best practice design for hybrid inbound mail (O365 + Zoho)

Looking for guidance on:

  • Proper FortiMail RAV configuration in multi-MTA environments
  • Ensuring upstream rejection of invalid users
  • Ensuring mailbox licensing only accounts for real user mailboxes

Important Constraint

LDAP-based Recipient Address Verification cannot be used in this environment.


Any FortiMail engineers or admins who have dealt with hybrid downstream MTAs or complex recipient verification setups — your recommendations would be extremely helpful.

0 REPLIES 0
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors