This article covers how DLP (Data Loss Prevention) policies work in Check Point Email Protection (Avanan), how to configure alert notifications, and how to troubleshoot common issues including emails detected but not blocked, missing authentication codes for secure messages, and applying settings across all clients.
How DLP policies work
Check Point Email Protection scans outbound (and in some configurations, inbound) emails for sensitive content patterns — such as credit card numbers, social security numbers, or custom keyword patterns you define. When a match is found, the policy applies one of the following actions:
Monitor only — the email is allowed through and the event is logged. No message is blocked or modified.
Block — the email is prevented from being delivered.
Block and encrypt — the email is blocked from delivering in plain text; the recipient receives a secure message link instead and must authenticate to read it.
Quarantine — the email is held for admin review before delivery.
Common issue: DLP alert fires but email is not blocked
If you see DLP alerts in Events Management but the emails are still being delivered unblocked, your DLP policy is most likely set to Monitor only (not Block or Block and encrypt).
In the Avanan portal, navigate to Security Settings → DLP.
Locate the relevant DLP policy and check the Action configured for it.
If the action is Monitor, change it to Block or Block and encrypt depending on your requirement.
Save the policy and wait a few minutes for the change to take effect.
Note: DLP policy action changes apply to new emails only — previously delivered emails are not retroactively affected.
Common issue: Secure message recipient did not receive authentication code
When Block and encrypt is active, the recipient receives an email with a secure message link. To read the message, they must authenticate using a one-time code sent to their email address. If the recipient did not receive the authentication code:
Check the recipient's spam or junk folder. Authentication code emails are sent from a Check Point / Avanan no-reply address and are sometimes filtered.
Confirm the recipient's email address is correct — the code is sent to the same address the secure message notification was delivered to.
If the recipient is using a shared mailbox, confirm they have access to that mailbox's inbox directly — codes sent to a shared mailbox are not accessible if the recipient only has delegation access via their personal inbox.
Ask the recipient to use the 'Resend code' option on the secure message login page, which generates a fresh code.
If the issue persists, contact Guardz Support with the recipient address and the date/time of the secure message — Support can verify delivery at the backend.
How to enable DLP alert emails (notify when a subject regex triggers)
You can configure DLP to send an email notification when a policy triggers. This is separate from the block/monitor action and must be enabled explicitly.
In the Avanan portal, navigate to Security Settings → DLP.
Open the relevant DLP policy.
Look for the Notifications or Alert Settings section.
Enable 'Send Email Alert' and configure the recipient address for the notification.
Save the policy.
If the Notifications section is not available in your portal view, or if you need to apply this setting across all clients simultaneously, contact Guardz Support — bulk policy changes across a managed MSP portfolio require backend configuration.
Verifying DLP is active on a specific tenant
To confirm DLP is scanning a specific customer's email:
In the Avanan portal, navigate to the customer's tenant.
Go to Security Settings → DLP.
Confirm at least one DLP policy is enabled (shown as Active).
Send a test email containing a pattern that should trigger the policy (e.g. a test credit card number in the format 4111 1111 1111 1111) and verify that an event appears in Events Management within a few minutes.
