nerdexam
Fortinet

FCP_FML_AD-7.4 · Question #42

A FortiMail device is configured with the protected domain example.com. If senders are not authenticated, which two envelope addresses will require an access receive rule? (Choose two.)

Options A and B require access receive rules because both involve mail being relayed outbound through a FortiMail device where the recipient is not in the protected domain. A (MAIL FROM: @example.com → @external.org): The sender claims to be from the protected domain, but the…

Email Operations

Question

A FortiMail device is configured with the protected domain example.com. If senders are not authenticated, which two envelope addresses will require an access receive rule? (Choose two.)

Options

Explanation

Options A and B require access receive rules because both involve mail being relayed outbound through a FortiMail device where the recipient is not in the protected domain.

  • A (MAIL FROM: @example.com → @external.org): The sender claims to be from the protected domain, but the recipient is external. Unauthenticated senders cannot relay outbound without an access receive rule permitting it.
  • B (MAIL FROM: @example.com → @biz.example.com): Even though biz.example.com looks related, it is not the configured protected domain (example.com). FortiMail treats it as an external recipient, making this also an outbound relay that requires an access receive rule.
  • C (MAIL FROM: @hosted.net → @example.com) is wrong because the recipient is in the protected domain - FortiMail automatically accepts inbound mail destined for its protected domain without needing a specific access receive rule.
  • D (MAIL FROM: @example.org → @example.com) is wrong for the same reason - delivery to the protected domain is always accepted by default.

Memory tip: Think of it this way - if the RCPT TO is the protected domain, FortiMail already knows what to do (accept it). You only need an access receive rule when FortiMail is being asked to relay outbound to somewhere it doesn't "own," especially from unauthenticated senders. Subdomains don't count as the same protected domain unless explicitly configured.

Topics

#access receive rules#protected domain#relay control#SMTP envelope

Community Discussion

No community discussion yet for this question.

Full FCP_FML_AD-7.4 Practice