Anti-Phishing Exceptions
The Anti-Phishing engine supports defining Allow-Lists and Block-Lists.
The Anti-Phishing engine stops scanning emails that match an Allow-List or Block-List rule. The Anti-Phishing verdict will automatically be clean (for Allow-List) or Phishing / Suspected Phishing / Spam (for Block-List).
-
Emails in the Anti-Phishing Allow-List and Block-List are evaluated by other security engines, such as Anti-Malware and DLP.
-
If an email matches both the Allow-List and Block-List rules, the Allow-List takes precedence, and the email will be delivered.
-
Email Security supports a limited number of Anti-Phishing Allow-Lists and Block-Lists, each accommodating up to 10,000 entries. If customers want to add more entries, they can contact Check Point Support
Viewing Anti-Phishing Exceptions
To view the configured Allow-List or Block-List rules:
-
Access the Email Security Administrator Portal.
-
Go to Security Settings > Exceptions > Anti-Phishing.
-
In the drop-down from the top of the page, select the require exception type (Allow-List or Block-List).
The page shows a table with all the exceptions and the defined criteria.
In the Anti-Phishing Allow-List table, the Affected emails column shows the number of emails flagged as phishing or spam by the Anti-Phishing engine but marked as clean because of the allow-list rule.
Note:The numbers for each allow-list rule in the Affected emails column do not update in real time. It might take up to an hour for them to update.