Email impersonation is one of the main problems facing the safety of many businesses today. Impersonators create email headers to deceive the recipient into believing the sender is from a legitimate and trusted source.
FortiMail helps you fight against email impersonation by mapping high valued target display names with correct email address. For example, if an external spammer wants to impersonate the CEO of your company (CEO@company.com), the spammer places “CEO ABC <ceo@external.com>” in the email header and sends the message to the user. If FortiMail is configured with a manual entry “CEO ABC/”ceo@company.com” in the impersonation profile to indicate the correct display name and email pair, or it has learned the pair through the dynamic process, then that email is detected by impersonation analysis.
This recipe guides you through the easy to follow process of creating and implementing an impersonation profile to better protect your network.
There are two types of mapping:
Manual: You manually enter mapping entries and create impersonation analysis profiles as described below and then enable the impersonation profile in an antispam profile. Eventually you apply the antispam profile in the IP-based or recipient-based policies.
Dynamic: FortiMail Mail Statistics Service can automatically learn the mapping. See details below.
Creating an Impersonation Analysis Profile |
|
First you will need to create an impersonation profile and add display names and email addresses to map.
|
|
Activating the Impersonation Profile |
|
Now you’ll need to enable impersonation analysis in the antispam profile to check for mapping and then select the profile.
|
|
Configuring Dynamic Scanning |
|
In addition to manually entering mapping entries and creating impersonation analysis profiles, FortiMail Mail Statistics Service can automatically learn and track the mapping. To use the FortiMail manual/dynamic, or both, impersonation analysis scanning, enter the following command:
By default, FortiMail uses manual analysis only. Also enable the FortiMail Mail Statistics Service with the following command. This service is also disabled by default:
|
The post Protecting Against Email Impersonation in FortiMail appeared first on Fortinet Cookbook.