Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
PFU
New Contributor

how to block spams received from various subdomain(with different IP) of sendgrid.net

Hi Experts,

 

Found that the 4 spam emails I received have similar header info as below:

the hops shown look like :

Received: from wrqvqthz.outbound-mail.sendgrid.net (149.72.71.14) by ….

Received: from wrqvdrfk.outbound-mail.sendgrid.net (149.72.213.241) by ...

Received: from wrqvqthz.outbound-mail.sendgrid.net (149.72.71.14) by ...

Received: from wrqvqthz.outbound-mail.sendgrid.net (149.72.71.14) by ...

 

senders look like:

From: DHL Express<bantuanspe@commercedc.com.my>

From: Outlook! Voice <asics.standard6@kingmaker-footwear.com>

From: Ems<bantuanspe@commercedc.com.my>

From: DHL Express calvin@solomonseedgroup.com

 

my question: seems spams use different fake sender addresses, I can't block spam using sender email address, so how to use other ways to block spam like these, how about the FortiGate -Black white list  and IP/Netmask? 

will FortiGate check all the IP addresses found in the header of SMTP email against the specified IP address black/white list, if the IP of any hops matched by the blacklist, will the email be blocked? 

 

what I need to achieve is to block as much spam as possible with better ways to do it.

 

Any suggestions will be greatly appreciated. 

 

Thanks and regards,

pfu

 

0 REPLIES 0
Labels
Top Kudoed Authors