We have been getting a ton of phishing emails lately. They pass through the fortimail without issue, and they contain links (either direct in body or in pdf) to sites that try to harvest email and password.
The websites they are linking to are usually hijacked and therefore usually categoriezed by fortigate as safe (business etc).
Is there a way to prevent users from being able to submit their email in forms? I have tried messing around with dlp without success.
You may want to submit your question into the FortiMail forum. ref. [link]https://forum.fortinet.com/tt.aspx?forumid=31[/link]
These emails bypass FortiMail because the links point to legitimate but compromised websites, which is common in many types of phishing attacks. Since the domains are still categorized as safe, reputation-based filtering doesn’t block them.
Blocking users from submitting email/passwords via DLP isn’t practical. DLP is for data leakage, not web form interaction.
What actually works:
Enable Deep SSL Inspection so FortiGate can detect credential-harvesting forms
Use Anti-Phishing profiles with real-time URL analysis
Block newly registered / low-reputation domains
Enable URL rewriting + time-of-click protection in FortiMail
Enforce MFA to neutralize stolen credentials
This layered approach is the effective defense against modern phishing.
| User | Count |
|---|---|
| 2988 | |
| 1473 | |
| 943 | |
| 826 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.