Check Point Email Protection uses multiple security engines — Anti-Phishing, Anti-Spam, Anti-Malware, and Data Protection (DLP) — and each engine maintains its own separate exception list. Adding a sender to one engine's allow list does not affect the others. This is the most common reason an email continues to be blocked even after you have added the sender to an allow list.
Why an allowed sender is still being blocked
Each security engine runs independently. When you add a sender to the Anti-Spam allow list, the Anti-Phishing engine still scans their emails and can still quarantine them. The same is true in reverse.
To stop all blocking of a specific sender or domain, you need to add an exception in each engine that is blocking them. If you are unsure which engine is triggering the block, check Detection & Response → Issues → Quarantined Emails and review the detection category shown on the email.
Where to manage exceptions in Guardz
Go to Security Controls → Email Protection → Exceptions. You will see separate tabs or sections for each engine:
Anti-Phishing — allows exceptions by sender email, domain, IP, header, and file type. Also supports bulk import via CSV for anti-phishing exceptions.
Anti-Spam — allows exceptions by sender email or domain.
Anti-Malware — manages file type allow and block lists. For example, .wav files blocked as a potential malware vector can be allowed here.
Data Protection (DLP) — manages rules that detect sensitive content such as PII patterns. Nine-digit number sequences are detected as potential SSN (social security numbers) by default, which can trigger false positives on invoice numbers.
Subject-based exceptions
Subject-based exceptions are not available in the Anti-Phishing engine within Guardz. The Anti-Phishing engine only supports exceptions by sender email, domain, IP, header, or file type. Subject-based allow rules are available in the Check Point portal directly (with Editor access), but cannot be applied per-user from Guardz — they apply to the whole tenant.
Domains that cannot be added to the block list
A small number of domains are protected by default in Guardz and cannot be added to the block list through the Guardz interface. These are typically domains used as part of the Guardz phishing simulation system. Emails from these domains are still scanned by all security engines — they are not delivered without inspection. If you need to block one of these domains anyway, you can do so directly in the Check Point portal with Editor access.
Bulk importing an allow or block list
Bulk import via CSV is available for Anti-Phishing exceptions only. The import file requires two columns: type (email or domain) and value. The import function is under Security Controls → Email Protection → Exceptions → Anti-Phishing.
For other engine types (Anti-Spam, Anti-Malware, DLP), exceptions must be added individually in Guardz or imported directly through the Check Point portal with Editor access.
Phishing simulation domains
Guardz phishing simulation domains and IPs are automatically added to the Check Point Anti-Phishing allow list during activation. You do not need to add them manually after migrating to Check Point Email Protection. If you want to confirm they are present, you can check the Check Point portal directly.
