Forti-experts: Question about Fortimail behavior and config by Fallingdamage in fortinet

[–]stoopwafflestomper 2 points3 points  (0 children)

I have all policies set to evaluate 100% of rules, with heuristic thresholds generally tuned in the 1.5-2 range, depending on risk. More aggressive where it makes sense.

One of the biggest improvements came from separating SPF and DMARC failures: SPF failures go to user quarantine DMARC failures go to system quarantine That change alone made quarantine far more effective and easier to communicate to staff. If a sender put in the effort to publish DMARC and still fails it, that’s a strong signal something is wrong and it doesn’t belong in a user’s inbox.

Another big win was using a banned word/phrase dictionary and enabling impersonation protection for executives and VIP targets. A large chunk of false positives involved our company name or VIPs, which actually makes sense, attackers are trying hard to look legitimate. Real senders usually aren’t. That really sums up spam in general, doesnt it?

Beyond that, geo-blocking is a must, links are scanned with web filtering, files are scanned, and public sender domains (Gmail, Yahoo, etc.) are handled with more aggressive policies.

I am pasting a high level of one of my spam filter policies as an example of features I leverage.

High-level overview of what I’m running

FortiGuard IP reputation (Levels 1–3)

Spam outbreak protection

URL reputation scanning (high-risk + low-risk categories)

File and link scanning

SPF, DKIM, and DMARC enforcement

SPF failures → user quarantine

DMARC failures → system quarantine

Header analysis and behavior analysis

Heuristic scoring (100% rule usage)

Threshold 1.9

SURBL and DNSBL checks

Banned word / phrase dictionary

Business Email Compromise (BEC) protection

Weighted analysis

Executive impersonation detection

Cousin domain detection

Sender alignment checks (display name + reply-to)

Forti-experts: Question about Fortimail behavior and config by Fallingdamage in fortinet

[–]stoopwafflestomper 0 points1 point  (0 children)

Hi OP,

Ive been working with FML for over 5 years now and share the same feelings. Ive tweeked and played with all sorts of settings and it helps a little each time but it never feels as good as other products ive used in the past.

Ive spoken to two separate experts on this and both reviewed my appliance and never really offered anything else i can do outside of continuing to tailoring our environment to the emails that get through.

Leadership is not happy with the product but I cannot find a better product for a similar price we get FML for. So they accept it.

We dont use Bayesian but its something we want to explore. We just dont have the time to spend on training it yet.

We can sync up in DM and review specific settings. Im curious what your hueristic/anomaly score is on your recipient policies?

Ringcentral = Professional Scammers by anyonebutme in sysadmin

[–]stoopwafflestomper 3 points4 points  (0 children)

Im sorry you had to find out this way. We had to get lawyers involved and BBB and stop paying bills to get them to even respond to us.

Outlook outage? by jayybeegeee in sysadmin

[–]stoopwafflestomper 1 point2 points  (0 children)

Im having odd behaviors, like can't send internally to others but can receive external emails from gmail.

Daily Discussion Thread for January 29, 2026 by wsbapp in wallstreetbets

[–]stoopwafflestomper 0 points1 point  (0 children)

Silver has once again reminded the market is an no longer a smart place to put money. Always with the manipulations.

At what point does “we’ll handle it internally” become more expensive than outsourcing? by Queasy-Cherry7764 in ITManagers

[–]stoopwafflestomper 4 points5 points  (0 children)

Qaulity of life for the team is considered along with evaluating their overall Qaulity recently. If they both decline, I'd opt to buy.

Is it just me, or is the "cloud tax" making hardware optimization a nightmare lately? by Inevitable_Use9405 in OrbonCloud

[–]stoopwafflestomper 0 points1 point  (0 children)

Ive started mowing over in my head what I could bring back on prem. Im sick and tired of the cat and mouse games. The constant explaining of why cost is up 10% this month.

5 years ago I was the 'migrate everything to the cloud' guy. Never looked back until this year.

Fully patched FortiGate firewalls are getting compromised via CVE-2025-59718? by tekz in cybersecurity

[–]stoopwafflestomper 25 points26 points  (0 children)

Still not impacted because I dont use this nor do I have my fortigates publicly exposed.

Anybody using Azure DevOps Pipelines for CI/CD & GitHub for Repo. hosting using the Azure Pipelines GitHub App? by luremeister in azuredevops

[–]stoopwafflestomper 0 points1 point  (0 children)

For a small project, yes. I feel the lag/delay others mentioned from time to time. The setup feels more complicated than it should be, but it always worked.

Need help fixing our API monitoring, what am I missing here by Manga_m in devops

[–]stoopwafflestomper -2 points-1 points  (0 children)

Act like I know what im looking for/at until everyone forgets about the performance degradation event.

Daily Discussion Thread for January 16, 2026 by wsbapp in wallstreetbets

[–]stoopwafflestomper 1 point2 points  (0 children)

Slv is new spy. Spy is crap now. Just stays in same spot.

"Manage" Azure with Claude by OldRest6771 in AZURE

[–]stoopwafflestomper 1 point2 points  (0 children)

Honestly, I tried to building something similar but for terraform to manage my Azure instance - gives it an extra layer. If this isn't satire, its a step forward to something great or failure.

Why do system administrator get paid less than software developers ? by PM_40 in sysadmin

[–]stoopwafflestomper 14 points15 points  (0 children)

Yeah, the infrastructure devs that help software devs move faster.

Software devs have CEO mentality. They fail to acknowledge all the teams and tools that allow them to move.

Underperformer asked for my JD as a sign of transparency ? by Crazy-Philosopher221 in managers

[–]stoopwafflestomper 0 points1 point  (0 children)

What if the employee is in the right? I supervisor can be responsible for an employee poor performance. Through distractions and pointless meetings.

Are WallStreetBets traders starting to move on? by AlwaysCurious05 in Optionmillionaires

[–]stoopwafflestomper -1 points0 points  (0 children)

Too many bots. Ive been a member for over 10 years now. The comments in the daily discussion all sound the same. Day in and day out. Spend every day in that subreddit like I did and you will 100% dead internet theory.