To (envelope)
The to field is in most FortiMail log messages where:
-
type=statistics -
type=spam -
type=virus
It indicates the recipient email address in the SMTP envelope (RCPT TO:). If the recipient address was rewritten, then the original recipient is recorded in original_to. Therefore to get complete search results, search filters with the recipient email address may need to use both fields (match if to or original_to).
This field is empty if session_id is empty, and when a DKIM key could not be retrieved from the DNS server.