FortiOS 6 – Anti-spam filter

Order of spam filtering

The FortiGate unit checks for spam using various filtering techniques. The order in which the FortiGate unit uses these filters depends on the mail protocol used.

Filters requiring a query to a server and a reply (FortiGuard Anti-Spam service and DNSBL/ORDBL) are run simultaneously. To avoid delays, queries are sent while other filters are running. The first reply to trigger a spam action takes effect as soon as the reply is received.

Each spam filter passes the email to the next if no matches or problems are found. If the action in the filter is Mark as Spam, the FortiGate unit tags the email as spam according to the settings in the email filter profile.

For SMTP and SMTPS, if the action is Discard, the email message is discarded or dropped.

If the action in the filter is Mark as Clear, the email is exempt from any remaining filters. If the action in the filter is Mark as Reject, the email session is dropped.

Order of SMTP and SMTPS spam filtering

The FortiGate unit scans SMTP and SMTPS email for spam in a specific order, depending on whether or not the local override feature has been enabled. By default, local override is disabled on the FortiGate. Enabling local override will give priority to local spam filters.

You can enable local override with the CLI command set local-override {enable | disable} when configuring a spamfilter profile. Enable this command to override SMTP or SMTPS remote check, which includes IP RBL check, IP FortiGuard AntiSpam check and HELO DNS check, with the locally defined black/white antispam list.

SMTPS spam filtering is available on FortiGate units that support SSL content scanning and inspection.

Order of spam filtering

Enabling local override of Anti-Spam filter

CLI Syntax

config spamfilter profile edit <filter_name> set spam-filtering enable

set options spambwl spamfsip spamfsurl spamhelodns spamfsphish config smtp set local-override enable

end

set spam-bwl-table 1

next

end

Order of SMTP and SMTPS spam filtering with local-override disabled

  1. HELO DNS Lookup, Last Hop IP check against ORDBL
  2. Return email DNS check, FortiGuard email checksum check, FortiGuard URL check, FortiGuard IP address check, Phishing URLs detection
  3. Last Hop IP check local black/white list (BWL)
  4. Envelope Address check local BWL
  5. Headers IPs local BWL
  6. Headers email address local BWL, MIME header checks based on local list of patterns (mheader)
  7. Banned words (subject first, then body) based on local BWL (bword)

Order of SMTP and SMTPS spam filtering with local-override enabled

  1. Last Hop IP check local black/while list (BWL)
  2. Envelope Address check local BWL
  3. Headers IPs local BWL, MIME header checks based on local list of patterns (mheader)
  4. Headers email address local BWL
  5. Banned words (subject first, then body) based on local list of patterns (bword)
  6. HELO DNS Lookup, Last Hop IP check against ORDBL
  7. Return email DNS check, FortiGuard email checksum check, FortiGuard URL check, FortiGuard IP address checks, Phishing URLs detection

Order of IMAP, POP3, IMAPS and POP3S spam filtering

The FortiGate unit scans IMAP, POP3, IMAPS and POP3S email for spam in the order given below. IMAPS and POP3S spam filtering is available on FortiGate units that support SSL content scanning and inspection.

  1. MIME headers check, E-mail address BWL check
  2. Banned word check on email subject
  3. IP BWL check
  4. Banned word check on email body
  5. Return email DNS check, FortiGuard Antispam email checksum check, FortiGuard Antispam URL check, DNSBL & ORDBL check.
This entry was posted in Administration Guides, FortiOS 6 and tagged , , on by .

About Mike

Michael Pruett, CISSP has a wide range of cyber-security and network engineering expertise. The plethora of vendors that resell hardware but have zero engineering knowledge resulting in the wrong hardware or configuration being deployed is a major pet peeve of Michael's. This site was started in an effort to spread information while providing the option of quality consulting services at a much lower price than Fortinet Professional Services. Owns PacketLlama.Com (Fortinet Hardware Sales) and Office Of The CISO, LLC (Cybersecurity consulting firm).

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.