Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jasonh1
New Contributor

Fortimail FORGED IP blocking

Hello

 

how to block FORGED IP in Fortimail v. 6.2.7 ?

 

thx

1 REPLY 1
Markus_M
Staff
Staff

Hi jasonh1,

 

if someone is faking an IP to an FQDN you would be able to detect this by a reverse lookup of that IP. It would not give the expected data and not match a forward lookup query.

 

I'm not a FortiMail expert, but it seems FML has a similar setting as this older article implies:

https://community.fortinet.com/t5/FortiMail/Technical-Note-Explanation-of-forged-IP/ta-p/198116?exte...

 

I see on a FML also the "Sender Policy Framework" that might help doing the same thing (doing a DNS lookup on the senders domain to see whether the senders mail address has been faked.

 

Markus

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors