Best Practices and Fine Tuning

SMTP connectivity tuning

  • Configure a fully qualified domain name (FQDN) that is different than that of your protected email server (gateway mode and transparent mode). The FortiMail unit’s domain name will be used by many FortiMail features such as quarantine, spam reports, Bayesian database training, alerts, and DSN email. The FQDN is formed by prepending the host name to the local domain name, both of which are configured in Mail Settings > Settings > Mail Server Settings.
  • Use a different host name for each FortiMail unit when managing multiple FortiMail units of the same model or when configuring an HA cluster. The host name is set in Mail Settings > Settings > Mail Server Settings.
  • If the FortiMail unit is used as an outbound relay (gateway mode and server mode only) or if remote email users will view their per-recipient quarantines, the FortiMail unit’s FQDN must be globally DNS-resolvable. External SMTP servers require that A records and reverse DNS records be configured on public DNS servers for both forward and reverse lookup of the FQDN and its IP address.
  • Configure the public DNS records for each of your protected domains with only one MX record that routes incoming email through the FortiMail unit (gateway mode). With only one MX record, spammers cannot bypass the FortiMail unit by using lower-priority mail gateways.
  • If the FortiMail unit is operating in transparent mode, SMTP clients are configured for authentication, and you have disabled the Use client-specified SMTP Server to send email option for SMTP proxies (located in Mail Settings > Proxies > Proxies), you must configure and apply an authentication profile (such as Profile > Authentication > Authentication). Without the authentication profile, authentication with the FortiMail unit will fail. Additionally, you must configure an access control rule (located in Policy > Access Control > Receive) to allow relay to external domains.

Having trouble configuring your Fortinet hardware or have some questions you need answered? Check Out The Fortinet Guru Youtube Channel! Want someone else to deal with it for you? Get some consulting from Fortinet GURU!

One thought on “Best Practices and Fine Tuning

  1. Esther

    Hello:

    Is it possible to made a alert to notify me when sender exceeds some maximuns? For example when sender exceeds 500 mails/hour?

    Thanks

    Reply

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.