Prerequisites to Avoid Failing SPF Checks
For Office 365 Mail, if you enable Protect (Inline) Outgoing Traffic in the DLP or Threat Detection policy, Email Security gets added to the email delivery chain before reaching external recipients (Internal email sender > Microsoft 365 > Email Security > Microsoft 365 > External recipient).
The recipient's email security solution sees the Email Security IP address as part of the delivery chain. If the recipient's email security solution fails to recognize the original IP address, it may consider the Email Security IP address as the IP address from which the email was sent.
If you do not configure the SPF record in your DNS to allow Email Security IP addresses to send emails on behalf of your domain, your emails might fail SPF checks and may be quarantined.
Check Point recommends you add the Email Security IP addresses to your SPF record before you enable Protect (Inline) Outgoing Traffic for outgoing emails.
To prevent outgoing emails from failing SPF checks and being quarantined, you must add include:spfa.cpmails.com to your SPF record.
The above statement includes several IP addresses and networks, some outside your Check Point Portal portal's data region. This is done for uniformity and consistency in all Check Point SPF records regardless of your data region. Email Security sends the emails only from one of the IP addresses in your region.