Monitoring the system : Viewing the greylist statuses : Viewing the pending and individual automatic greylist entries
Viewing the pending and individual automatic greylist entries
The Display tab lets you view pending and individual automatic greylist entries.
Pending greylist entries are those whose Status is not PASSTHROUGH. For email messages matching pending greylist entries, the FortiMail unit will reply to delivery attempts with a temporary failure code until the greylist delay period, indicated by Time to passthrough, has elapsed.
Individual greylist entries are those whose Status is PASSTHROUGH. For email messages matching pending greylist entries, the greylist scanner will allow the delivery attempt, and may create a consolidated automatic greylist entry. For information on consolidated entries, see “Viewing the consolidated automatic greylist exemptions”.
To access this part of the web UI, your administrator account’s:
Domain must be System
access profile must have Read-Write permission to the Policy category
For details, see “About administrator account permissions and domains”.
To view the greylist, go to Monitor > Greylist > Display.
 
Table 12: Viewing the list of pending and individual greylist entries
GUI item
Description
Search
(button)
Click to filter the displayed entries. For details, see “Filtering pending and individual automatic greylist entries”.
IP
Lists the IP address of the SMTP client that delivered or attempted to deliver the email message.
If the displayed entries are currently restricted by a search filter, a filter icon appears in the column heading. To remove the search filter, click the tab to refresh the display.
Sender
Lists the sender email address in the message envelope (MAIL FROM:), such as user1@example.com.
If the displayed entries are currently restricted by a search filter, a filter icon appears in the column heading. To remove the search filter, click the tab to refresh the display.
Recipient
Lists the recipient email address in the message envelope (RCPT TO:), such as user1@example.com.
If the displayed entries are currently restricted by a search filter, a filter icon appears in the column heading. To remove the search filter, click the tab to refresh the display.
Status
Lists the current action of the greylist scanner when the FortiMail unit receives a delivery attempt for an email message matching the entry.
TEMPFAIL: The greylisting delay period has not yet elapsed, and the FortiMail unit currently replies to delivery attempts with a temporary failure code. For information on configuring the greylist delay period, see “Configuring the grey list TTL and initial delay”.
PASSTHROUGH: The greylisting delay period has elapsed, and the greylist scanner will allow delivery attempts.
Time to passthrough
Lists the time and date when the greylisting delay period for a pending entry is scheduled to elapse. Delivery attempts after this date and time confirm the pending greylist entry, and the greylist scanner converts it to an individual automatic greylist entry. The greylist scanner may also consolidate individual greylist entries. For information on consolidated entries, see “Viewing the consolidated automatic greylist exemptions”.
N/A appears if the greylisting period has already elapsed.
Expire
Lists the time and date when the entry will expire. The greylist entry’s expiry time is determined by the following two factors:
Initial expiry period: After a greylist entry passes the greylist delay period and its status is changed to PASSTHROUGH, the entry’s initial expiry time is determined by the time you set with the CLI command set greylist-init-expiry-period under config antispam settings (for details, see the FortiMail CLI Reference). The default initial expiry time is 4 hours. If the initial expiry time elapses without an email message matching the automatic greylist entry, the entry expires. But the entry will not be removed.
TTL: Between the entry’s PASSTHROUGH time and initial expiry time, if the entry is hit again (the sender retries to send the message again), the entry’s expiry time will be reset by adding the TTL value (time to live) to the message’s “Received” time. Each time an email message matches the entry, the life of the entry is prolonged; in this way, entries that are in active use do not expire. If the TTL elapses without an email message matching the automatic greylist entry, the entry expires. But the entry will not be removed. For information on configuring the TTL, see “Configuring the grey list TTL and initial delay”.