Anti-Phishing Exceptions

The Anti-Phishing engine supports defining Allow-Lists and Block-Lists.

The Anti-Phishing engine stops scanning emails that match an Allow-List or Block-List rule. The Anti-Phishing verdict will automatically be clean (for Allow-List) or Phishing / Suspected Phishing / Spam (for Block-List).

Note:
  • Emails in the Anti-Phishing Allow-List and Block-List are evaluated by other security engines, such as Anti-Malware and DLP.

  • If an email matches both the Allow-List and Block-List rules, the Allow-List takes precedence, and the email will be delivered.

  • Email Security supports a limited number of Anti-Phishing Allow-Lists and Block-Lists, each accommodating up to 10,000 entries. If customers want to add more entries, they can contact Check Point Support

Viewing Anti-Phishing Exceptions

To view the configured Allow-List or Block-List rules:

  1. Access the Email Security Administrator Portal.

  2. Go to Security Settings > Exceptions > Anti-Phishing.

  3. In the drop-down from the top of the page, select the require exception type (Allow-List or Block-List).

    The page shows a table with all the exceptions and the defined criteria.

    In the Anti-Phishing Allow-List table, the Affected emails column shows the number of emails flagged as phishing or spam by the Anti-Phishing engine but marked as clean because of the allow-list rule.

    Note:

    The numbers for each allow-list rule in the Affected emails column do not update in real time. It might take up to an hour for them to update.