what would be the best approach to enforce better security if sender and recipient coming from same domain?
in such case user1@example.com is infected of malware/riskware and keeps sending emails to user2@example.com and etc...
How fortimail will address thus of dilemma?
I installed my Fortimail in gateway mode. Two possible setup; Fortimail and Mails Server resides on same subnet or Mail Server located in LAN and FortiMail is located in DMZ
Any thoughts are much welcome and appreciated.
Fortigate Newbie
FortiMail should have 1 internal IP address and 1 external IP address.
Block access to Email server, except when requests comes from FortiMail's Internal/External IP address.
Above will force Internal users to send emails through FortiMAIL.
you can also use the fortimail and the mailserver in the same subnet. the direct access to the mailserver you can limit over the firewall before the dmz. You can restrict the receipt of external mails with your domain as the sender via a receiving access policy.
Sender abc@yourdomain.com -> fortimail -> Access Control rule -> discard/deny -> mailserver @yourdomain.com
Sender abc@abc.com -> fortimail -> Access Control rule -> relay -> mailserver @yourdomain.com
receiving Access Control rule:
Sender pattern: *@yourdomain.com
recipient pattern: *@yourdomain.com
Sender ip: 0.0.0.0/0
Action: dicard
Fortigate 500E HA Fortimail 200 Fortimanager
FortiEMS
FortiSandbox 1000D
FortiSwitch Network Some other Models in use :-) ---------------------------------------------------- FCSE ----------------------------------------------------
User | Count |
---|---|
2046 | |
1169 | |
770 | |
448 | |
339 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.