Overview:
Occasionally, Google Workspace (GWS) may flag a message as spam even after it has been classified as clean and successfully delivered by Check Point. If you encounter this issue, work through the steps below one at a time until it is resolved.
Action Items:
1. Verify the regexp is set to 'X-CLOUD-SEC-AV-SCL: true' for the inbound gateway
Apps > Google Workspace > Settings for Gmail > Spam, Phishing, and Malware > Inbound gateway
If this was set to a different value previously, installing Check Point Harmony (Avanan) will not update it, resulting in Google classifying messages as spam after scanning and redelivery to the inbox.
2. Check the setting: 'Disable Gmail spam evaluation on main from this gateway; only use header value' (under Apps > Google Workspace > Settings for Gmail > Spam, Phishing, and Malware > Inbound gateway).
This checkbox is off by default, but in some cases where Gmail continues to move messages to spam, enabling the feature will resolve the issue.
3. Add the Sender to an allowlist in Gmail (under Apps > Google Workspace > Settings for Gmail > Spam, Phishing, and Malware > Spam > Edit rule > click 'Bypass spam filters and hide warnings for messages from senders or domains in selected lists' checkbox shown below).
4. Disable X-Gm-Spam and X-Gm-Phishy headers under Compliance settings (Apps > Google Workspace > Settings for Gmail > Compliance > edit 'tenantname_inline_ei' rule > disabled 'Add X-Gm-Spam and X-Gm-Phishy headers' (the rule will begin with the tenants name)).
This will prevent gmail from adding evaluation headers. Check Point will still factor in Gmail's scan results but the headers will not be updated so when the message delivers again to Gmail it won't be able to see it as spam even if it previously classified the message as such.β
