FortiMail Email Security
FortiMail Email Security
1
DATA SHEET | FortiMail™
FEATURES
Impersonation Analysis
Cousin Domain Detection
Click Protection
Outbreak Protection
Behaviour Analysis
Content Disarm
2 2
DATA SHEET | FortiMail™
FEATURES
Zero Trust
Access
IT and security teams are able to more completely connect
FortiGuard
the dots to identify multi-vector campaigns by sophisticated Threat
Intelligence
Secure Open
Networking Ecosystem
3
DATA SHEET | FortiMail™
FEATURES
Easy-To-Use Configuration
Easy-to-use configuration controls make setting
up and managing email security – even advanced
security capabilities - easy for organizations of all
sizes and use cases.
4 4
DATA SHEET | FortiMail™
FEATURES
High Performance, Flexible Deployment
Scale easily to handle millions of messages per hour. Serving organizations of all sizes, Fortinet provides a wide range of
deployment models and operation modes to best match your organization’s email security needs.
Server Mode
The FortiMail device acts as a standalone messaging server
with full SMTP email server functionality, including flexible
support for secure POP3, IMAP, and WebMail access.
5
DATA SHEET | FortiMail™
FEATURES
We want full control.
Enterprise Advanced Threat Ent. ATP with Microsoft 365 API
Feature Base Bundle Protection Bundle Support Bundle
Message Tracking ✓⃝ ✓⃝ ✓⃝
Reporting ✓⃝ ✓⃝ ✓⃝
Impersonation Analysis ✓⃝ ✓⃝
Cloud Sandboxing ✓⃝ ✓⃝
FortiAnalyzer FortiNDR
FortiIsolator FortiSIEM
FortiSOAR
6 6
DATA SHEET | FortiMail™
FEATURES SUMMARY
SYSTEM CONTENT DETECTION
Wide range of deployment and operation options FortiGuard Antivirus Service detection
– On-premise or public or private cloud deployment – CPRL signature checking
– Gateway, M365 API, Transparent, and Server Mode – Heuristic based behavioral detection
– Cloud-Managed Service – Greyware detection
Geographic IP location-based policy Automatic decryption of Archives, PDF and Office Documents using built-in and
administrator-defined password lists and word detection within email body
Comprehensive Webmail Interface for Server Mode Deployments and Quarantine
Management PDF Scanning and image analysis
Full FortiGuard URL Category Filtering includes Centralized quarantine for large scale deployments
– Spam, malware and phishing URLs Optional centralized logging and reporting with FortiAnalyzer
– Pornographic and adult URLs
– Newly registered domains SNMP support using standard and private MIB with threshold-based traps
Greylisting for IPv4, IPv6 addresses and email accounts Local or external storage server support, including iSCSI devices
Local sender reputation (IPv4, IPv6 and End Point ID-based) External Syslog support
Behavioral analysis Open REST API for configuration and management
Integration with third-party spam URI and real-time blacklists (SURBL/RBL)
HIGH AVAILABILITY (HA)
Newsletter (greymail) and suspicious newsletter detection
High availability supported in all deployment scenarios
PDF Scanning and image analysis – Active-Passive mode
– Active-Active configuration synchronization mode
Block/safe lists at global, domain, and user levels
Quarantine and mail queue synchronization
Support for enterprise sender identity standards
– Sender Policy Framework (SPF) Device failure detection and notification
– Domain Keys Identified Mail (DKIM)
Link status, failover and redundant interface support
– Domain-Based Message Authentication (DMARC)
Flexible action and notification profiles ADVANCED
Multiple system and per-user self-service quarantines Policy-based e-mail archiving with remote storage options
– Support for Exchange journal archiving
TARGETED ATTACK PROTECTION
Advanced Email Server feature set including
Content Disarm and Reconstruction – Comprehensive webmail interface
– Neutralize Office and PDF documents (remove macros, active content, attachments, and – POP3, IMAP mail access
more) – Calendaring functions
– Neutralize email HTML content by removing hyperlinks / rewrite URLs – Undo Send
Business Email Compromise (BEC) SAML 2.0 SSO and ADFS integration for webmail and quarantine access
– Multi-level anti-spoof protection
– Impersonation analysis — manual and automatic address impersonation detection SUPPORT
– Cousin domain detection
Simple support options with inclusive bundles
URL Click Protect to rewrite URLs and rescan on access
Advanced RMA Support
Integration with FortiIsolator Browser Isolation platform to neutralize browser-based
Professional services and installation support options
threats
API INTEGRATION
Microsoft 365 Integration
– Post-delivery threat clawback
– Scheduled scan
– Real-time scanning
– Internal mail scanning
7
DATA SHEET | FortiMail™
SPECIFICATIONS
FORTIMAIL 200F FORTIMAIL 400F FORTIMAIL 900F
Recommended Deployment Scenarios
Small businesses, branch offices, Small to midsized organizations Mid to large enterprise, education, and
and organizations government departments
Hardware Specifications
10/100/1000 Interfaces (Copper, RJ45) 4 4 4
SFP Gigabit Ethernet Interface - - 2
SFP+ 10 Gigabit Ethernet Interface - - -
Redundant Hot Swappable Power Supplies No No Yes
Storage 1x 1TB 2x 1 TB 2x 2 TB (2x 2 TB Optional)
RAID Storage Management No Software 0, 1 Hardware 0, 1, 5, 10, Hot Spare
(Based on Drive Count)
Form Factor Rack Mount, 1U Rack Mount, 1U Rack Mount, 1U
Trusted Platform Module (TPM) Yes Yes Yes
Power Supply Single Single (Dual Optional) Dual
System Specifications
Protected Email Domains* 20 100 800
Recipient-based Policies (per Domain / per System) 60 / 300 400 / 1500 600 / 2000
— Incoming or Outgoing
Server Mode Mailboxes 150 400 1500
Antispam, Antivirus, Authentication, and 50 / 60 50 / 200 50 / 400
Content Profiles (per Domain / per System)
Data Loss Prevention No Yes Yes
Centralized Quarantine No Yes Yes
Dimensions
Height x Width x Length (inches) 1.73 x 17.24 x 16.61 1.73 x 17.24 x 16.38 1.75 x 17.00 x 27.61
Height x Width x Length (mm) 44 x 438 x 422 44 x 438 x 416 44 x 438 x 701
Weight 11.9 lbs (5.4 kg) 25.0 lbs (11.0kg) 33.1 lbs (15.00 kg)
Environment
Power Source 100–240V AC, 50–60 Hz 100–240V AC, 50–60 Hz 100–240V AC, 50–60 Hz
Maximum Current 100V / 3A, 240V / 1.5A 100V / 5A, 240V / 3A 100V / 5A, 240V / 2.5A
Maximum Power Required 62 W 113 W 190 W
Power Consumption (Average) 51 W 77 W 174 W
Heat Dissipation 245 BTU/h 418 BTU/h 681 BTU/h
Forced Airflow Front to back Front to back Front to back
Humidity 5%–90% non-condensing 5%–90% non-condensing 5%–90% non-condensing
Operating Temperature 32°–104°F (0°–40°C) 32°–104°F (0°–40°C) 32°–104°F (0°–40°C)
Storage Temperature -4°–158°F (-20°–70°C) -4°–158°F (-20°–70°C) -4°–158°F (-20°–70°C)
Compliance
FCC Part 15 Class A, RCM, VCCI, CE, FCC Part 15 Class A, RCM, VCCI, CE, FCC Part 15 Class A, RCM, VCCI, CE,
UL/cUL, CB, RoHS UL/cUL, CB, BSMI, RoHS UL/cUL, CB, BSMI, RoHS
Certification
VBSpam and VB100 rated, Common VBSpam and VB100 rated, Common VBSpam and VB100 rated, Common
Criteria NDPP, FIPS 140-2 Compliant Criteria NDPP, FIPS 140-2 Compliant Criteria NDPP, FIPS 140-2 Compliant
* Protected Email Domains is the total number of email domains that can be configured on the appliance.
Domain Associations can be used to enable additional domains which share configuration with the primary domain to which they are assigned.
** Tested using FortiMail 7.0
8 8
DATA SHEET | FortiMail™
SPECIFICATIONS
FORTIMAIL 2000F FORTIMAIL 3000F
Recommended Deployment Scenarios
Large enterprise, education, and government departments Highest performing appliance for the largest corporate,
university, ISP, and carriers
Hardware Specifications
10/100/1000 Interfaces (Copper, RJ45) 4 4
SFP Gigabit Ethernet Interface 2 2
SFP+ 10 Gigabit Ethernet Interface - 2
Redundant Hot Swappable Power Supplies Yes Yes
Storage 2x 2 TB SAS 2x 2 TB
(6x 2 TB Optional) (10x 2 TB Optional)
RAID Storage Management Hardware; 1, 5, 10, 50, Hot Spare (Based on drive count) Hardware; 1, 5, 10, 50, Hot Spare (Based on drive count)
Form Factor Rack Mount, 2U Rack Mount, 2U
Trusted Platform Module (TPM) Yes Yes
Power Supply Dual Dual
System Specification
Protected Email Domains* 1000 / (1500) 2000 / (3000)
Recipient-Based Policies (per Domain / per System) — 800 / 3000 1500 / 7500
Incoming or Outgoing
Server Mode Mailboxes 2000 3000
Antispam, Antivirus, Authentication, and Content Profiles 50 / 400 50 / 600
(per Domain / per System)
Data Loss Prevention Yes Yes
Centralized Quarantine Yes Yes
Dimensions
Height x Width x Length (inches) 3.5 x 17.2 x 25.5 3.5 x 17.2 x 25.5
Height x Width x Length (mm) 89 x 437 x 647 89 x 437 x 647
Weight 32 lbs (14.5 kg) 40.0 lbs (18.2 kg)
Environment
Power Source 100–240V AC, 50–60 Hz 100–240V AC, 50–60 Hz
Maximum Current 10.0A / 110V, 3.5A / 240V 9.8A / 110V, 4.9A / 220V
Maximum Power Required 219 W 379 W
Power Consumption (Average) 189 W 348 W
Heat Dissipation 781 BTU/h 1325 BTU/h
Forced Airflow Front to back Front to back
Humidity 8%–90% non-condensing 8%–90% non-condensing
Operating Temperature 41°–95°F (5°–35°C) 50°–95°F (10°–35°C)
Storage Temperature -40°–140°F (-40°–60°C) -40°–158°F (-40°–70°C)
Compliance
FCC Part 15 Class A, RCM, VCCI, FCC Part 15 Class A, RCM, VCCI,
CE, UL/cUL, CB, BSMI, RoHS CE, UL/cUL, CB, BSMI, RoHS
Certification
VBSpam and VB100 rated, Common Criteria NDPP, FIPS VBSpam and VB100 rated, NDPP,
140-2 Compliant FIPS 140-2 Compliant
* Protected Email Domains is the total number of email domains that can be configured on the appliance.
Domain Associations can be used to enable additional domains which share configuration with the primary domain to which they are assigned.
** Tested using FortiMail 7.0
9
DATA SHEET | FortiMail™
SPECIFICATIONS
TECHNICAL SPECIFICATIONS FOR
VM01 VM02 VM04 VM08 VM16 VM32
FORTIMAIL VIRTUAL APPLIANCES
Recommended Deployment Scenarios *
Small businesses, Small to midsized Mid to large Large enterprise Large enterprise Large enterprise
branch offices, and organizations enterprise
organizations
Technical Specifications
Hypervisors Supported VMWare ESX/ESXi 6.0/6.7/7.0 and later, Citrix XenServer v5.6 SP2/6.0 and later, Microsoft Hyper-V Server 2008 R2/2012/2012
R2/2016/2019, KVM qemu 2.12.1 and later, AWS (Amazon Web Services), Nutanix AHV**, Microsoft Azure, Google Cloud Platform,
Oracle Cloud Infrastructure***
Maximum Virtual CPUs Supported 1 2 4 8 16 32
Virtual NICs Required (Minimum/Maximum) 1/4 1/4 1/6 1/6 1/6 1/6
Virtual Machine Storage Required 250 GB / 1 TB 250 GB / 2 TB 250 GB / 4 TB 250 GB / 8 TB 250 GB / 12 TB 250 GB / 24 TB
(Minimum/Maximum) ****
Virtual Machine Memory Required 2 GB / 4 GB 2 GB / 8 GB 4 GB / 16 GB 4 GB / 64 GB 4 GB / 128 GB 4 GB / 128 GB
(Minimum/Maximum)
System Specifications
Protected Email Domains ****** 20 70 500 1000 1500 2000
Recipient-Based Policies (Domain / System) 60 /300 400 / 1500 800 / 3000 800 / 3000 1500 / 7500 1500 / 7500
— Incoming or Outgoing
Server Mode Mailboxes 150 400 1500 2000 3000 3000
Antispam, Antivirus, Authentication, and 50 / 60 50 / 200 50 / 400 50 / 400 50 / 600 50 / 600
Content Profiles (per Domain / per System)
Data Loss Prevention No Yes Yes Yes Yes Yes
Centralized Quarantine No Yes Yes Yes Yes Yes
Microsoft 365 API Integration No Optional Optional Optional Optional Optional
* Recommended sizing for Gateway and Transparent deployments. For Server Mode, see Server Mode Mailbox metric.
If unsure, please validate the model selection by checking the peak mail flow rates and average message size detail with a FortiMail specialist.
** FortiMail 7.0.1 has been validated on Nutanix AHV 20201105.2096 and AOS 5.20.1.1.
*** Transparent mode deployment is not fully supported on Microsoft HyperV and cloud hypervisors due to limitations in the available network configurations.
**** For the initial VM setup, 250GB is required to install the default Fortinet OVF file. After deployment, the default OVF file can be deleted and the disk space set no less than 50 GB.
***** Hardware dependent. Indicative figures based on a VMWare 6.0 system utilizing 2x Intel Xeon E5-2620 v4 @ 2.10 GHz restricted to the specified number of cores.
****** Protected Email Domains is the total number of email domains that can be configured on the appliance. Domain Associations can be used to enable additional domains which share
configuration with the primary domain to which they are assigned. Advanced management license increases the protected domain limit by 50%.
10 10
DATA SHEET | FortiMail™
ORDER INFORMATION
For information on ordering, please talk with your Fortinet account manager, or refer to the Ordering Guide for a full list of
FortiMail-related SKUs and pricing information.
Accessories
Power Supply SP-FAD700-PS AC power supply for FML-400E
Power Supply SP-FML900F-PS AC power supply for FML-400F and FML-900F
Power Supply SP-FML2000F-PS AC power supply for FML-2000F
Power Supply SP-FML3000F-PS AC power supply for FML-3000F and FML-3200F
Hard Drive SP-D2TE 2 TB 3.5" SAS hard drive with tray for FML-2000F, FML-3000F and FML-3200F
Hard Drive SP-FML900F-HDD 2 TB 3.5" SATA hard drive with tray for FML-900F
Service and Support
Appliances - Hardware plus 24x7 FortiCare and FortiGuard Base Bundle
Appliances - Hardware plus 24x7 FortiCare and FortiGuard Enterprise ATP Bundle
Virtual Machines - 24x7 FortiCare and FortiGuard Base Bundle Contract
Virtual Machines - 24x7 FortiCare and FortiGuard Enterprise ATP Bundle Contract
Microsoft 365 API Integration Service
Add-on Capabilities
Dynamic Adult Image Analysis Service
Email Continuity
For Service Providers and Enterprises
Advanced Administration License for MSSPs and Enterprises requiring multi-tenancy and additional features
www.fortinet.com
Copyright © 2022 Fortinet, Inc. All rights reserved. Fortinet®, FortiGate®, FortiCare® and FortiGuard®, and certain other marks are registered trademarks of Fortinet, Inc., and other Fortinet names herein may also be registered and/or common law trademarks of Fortinet. All other product
or company names may be trademarks of their respective owners. Performance and other metrics contained herein were attained in internal lab tests under ideal conditions, and actual performance and other results may vary. Network variables, different network environments and other
conditions may affect performance results. Nothing herein represents any binding commitment by Fortinet, and Fortinet disclaims all warranties, whether express or implied, except to the extent Fortinet enters a binding written contract, signed by Fortinet’s General Counsel, with a purchaser
that expressly warrants that the identified product will perform according to certain expressly-identified performance metrics and, in such event, only the specific performance metrics expressly identified in such binding written contract shall be binding on Fortinet. For absolute clarity, any
such warranty will be limited to performance in the same ideal conditions as in Fortinet’s internal lab tests. Fortinet disclaims in full any covenants, representations, and guarantees pursuant hereto, whether express or implied. Fortinet reserves the right to change, modify, transfer, or otherwise
revise this publication without notice, and the most current version of the publication shall be applicable.
Fortinet is committed to driving progress and sustainability for all through cybersecurity, with respect for human rights and ethical business practices, making possible a digital world you can always trust. You represent and warrant to Fortinet that you will not use Fortinet’s
products and services to engage in, or support in any way, violations or abuses of human rights, including those involving illegal censorship, surveillance, detention, or excessive use of force. Users of Fortinet products are required to comply with the Fortinet EULA
(https://www.fortinet.com/content/dam/fortinet/assets/legal/EULA.pdf) and report any suspected violations of the EULA via the procedures outlined in the Fortinet Whistleblower Policy (https://secure.ethicspoint.com/domain/media/en/gui/19775/Whistleblower_Policy.pdf).
FML-DAT-R57-20221117