The most common reason a sender is still quarantined after allowlisting is that Check Point Email Protection uses three independent security engines — Anti-Phishing, Anti-Spam, and Anti-Malware — and each engine has its own separate exception list. Adding a sender or domain to one list has no effect on the other engines.
The Three Engines and Their Exception Lists
Engine | What it blocks | Where to add the exception |
Anti-Phishing | Phishing emails, DMARC/SPF/DKIM failures, domain impersonation, suspicious links and content, social engineering. | Security Controls → Email Protection → Exceptions → Anti-Phishing |
Anti-Spam | Bulk email, newsletter-style messages, low sender reputation, high spam confidence. | Security Controls → Email Protection → Exceptions → Anti-Spam (Trusted Senders) |
Anti-Malware | Emails containing file types on the default block list (for example .wav, .exe, .js) or attachments matching malware signatures. | Security Controls → Email Protection → Exceptions → Anti-Malware |
Step 1: Find Out Which Engine Is Blocking the Email
Before adding an exception, identify the detection category so you add it to the right list. Open the quarantined email in Detection & Response → Issues → Quarantined Emails and check the detection reason shown in the email details. The category will tell you which engine flagged it. The same information is visible also through Check Point (Avanan) console.
Step 2: Add the Exception to the Correct List
Scenario A: Phishing or SPF/DMARC/DKIM failure
Go to Security Controls → Email Protection → Exceptions → Anti-Phishing and add the sender email address or domain.
If the email fails SPF checks (the sending IP is not listed in the sender domain's SPF record), the standard Anti-Phishing exception alone is not enough. You must also check the Ignore SPF flag on the exception entry. Without this flag, SPF failures will continue to trigger quarantine even with the exception in place.
To narrow the exception further — for example to allow only a specific sender IP rather than the entire domain — you can edit the exception in the Check Point portal directly and add criteria such as Sender IP.
Scenario B: Anti-Spam (bulk/newsletter emails)
Go to Security Controls → Email Protection → Exceptions → Anti-Spam and add the sender to the Trusted Senders list. Note: adding a sender here only bypasses spam detection. It does not affect phishing or malware checks.
Scenario C: WAV or other file types blocked by Anti-Malware
Some file types — including .wav — are on the default Anti-Malware block list. Allowlisting the sender in Anti-Phishing or Anti-Spam has no effect when the quarantine is caused by a blocked file type.
To allow emails with these attachments through, you have three options:
Add the specific sender to the Anti-Malware exception list at Security Controls → Email Protection → Exceptions → Anti-Malware. This allows that sender to send any file type without being blocked by Anti-Malware.
Remove the file type block for the specific file extension in the same Anti-Malware exceptions area. This allows that file type from any sender.
Ask the sending system (such as a voicemail service) to transmit the audio in a different file format that is not on the block list.
Microsoft 365 and Check Point: Independent Scanning
Microsoft 365 scans email before Check Point in the following flow: Sender → Microsoft Office 365 → Check Point Inline Scan → Microsoft Office 365 → End User.
If Microsoft 365 quarantines an email as high-confidence spam before it reaches Check Point, the message never enters the Check Point inline flow. In this case, Check Point scans the email via API from the Microsoft quarantine and provides a verdict, but the email stays in Microsoft quarantine, not the Guardz quarantine.
