Hi, just checking in to see if white paper was finished. Thanks.
For my answers, with scam and phishing email the reputation of the sender is typically the flag but the FM has under profile URI a phishing tag. It allows you to select various settings ( phishing maliscious or categories ). You also want to look at set uri-filter in your AS profile.
For different reply address , you might get by with a X custom header insertion, but how would trigger it? Also it's not uncommon for a REPLY TO to be different than a sender. If you are not getting AS reputation matches than I would review your fortiguard services and scoring levels that are set for the AS profile.
Give a try and monitor.
PCNSE
NSE
StrongSwan
Hi Guys,
We are facing issue with fortimail because of Heuristic threshold.
I want to increase the threshold but I couldn’t find any document to understand value of that threshold.
What is max value to be set??
Current Threshold is :3.50
The Percentage is : 50
Regds
Ashik
I would monitor the logs b4 dabbling with the threshold. In fact you should monitor b4 and after for a few months and continual.
It uses the the combination of AS scoring results and the define threshold to tag or act upon emails that it thinks are spam. You can adjust the threshold to be lower or higher but monitor the logs and users and emails that are "thought" to be spam.
http://socpuppet.blogspot.com/2015/01/heuristic-options-fortimail_8.html
PCNSE
NSE
StrongSwan
Hi Emnoc,
Thanx for the information .I have one more query .How to stop spoofed emails.We are still get email from our own company employee email address .Almost all antispam features are enabled like graylisting ,SPF check etc etc .
Regds,
Ashik
Hello Ashik,
just enabling SPX wont help much. Do you have an SPF Record for your domain? if so how does it look like?
NSE 8
NSE 1 - 7
Hi,
We don't have SPF record .What is the alternative method to stop spoofed emails ?
regds
Ashik
SPF is the Best method and is easy to configure. You just have to put an txt Record to your Public DNS. Then SPF Check on the FortiMail will work.
You can also use DKIM but it more complicated than SPF.
Just google for SPF konfigurator, read some SPF Guide and put the Record
NSE 8
NSE 1 - 7
Hi
Thanx .What is the best score for sender reputation.
Regds
Ashik
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1748 | |
1114 | |
764 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.