Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
JP57
New Contributor II

Recipient Verification

Trying to fine tune recipient verification on my FortiMail.  I have LDAP setup to look up addresses in AD and that works fine....EXCEPT...if a user has multiple email addresses associated with their mailbox.  For example.  User: John Smith with a primary SMTP address of JSmith@Example.com matches thru the LDAP query and allows mail.  But, if John Smith also has another address setup in Exchange on the same mailbox, such as JohnS@example.com

the FML will deny the email based on recipient.  How do I setup LDAP to check for all addresses for a user?

3 REPLIES 3
AEK
SuperUser
SuperUser

Did you try with SMTP verification instead with LDAP verification?

On the other hand I always prefer avoid implementing such checks because I think it is better for security. I mean such feature will inform some bad senders that this recipient exists and that recipient doesn't exist.

AEK
AEK
JP57
New Contributor II

I believe I've found the answer...Profile, LDAP, LDAP, NAME, User Query Option, change Schema to Active Directory.

As for bad senders, I have the FML set to Discard mail that fails this check, not Reject.

abelio
SuperUser
SuperUser

Hi,
Indeed. As smtp recipient verification it's not supported for your MSExchange backend, your new approach is the way to go.
AD Schema available under Fortimail LDAP profile covers the most standard AD setup; but if your specific setup involves aliases o distribution lists you also have "User Alias Option" and "Group Alias Option", both available under LDAP profile to cover all needed scenarios.

Regarding to bad senders, once tested and verified your LDAP profile, Discard is a better option IMHO, it avoids to send back extra information to bad sender.



regards




/ Abel

regards / Abel
Labels
Top Kudoed Authors