<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SPF temperror and Unverified tag added to internal emails after integrating with Microsoft Offic in Email and Collaboration</title>
    <link>https://community.checkpoint.com/t5/Email-and-Collaboration/SPF-temperror-and-Unverified-tag-added-to-internal-emails-after/m-p/253748#M660</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/41996"&gt;@ToffenDask&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the quick reply.&lt;/P&gt;&lt;P&gt;I have a case opened with Check Point support but I'm also not seeing it go very far.&lt;BR /&gt;Have you tried to put ipv4:&lt;SPAN&gt;52.212.19.177 on your SPF configuration, to see if the time out happens when Microsoft tries to communicate with&amp;nbsp;spfa.cpmails.com domain, to see their IPs?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I'm not 100% sure, but I assume that if we put&amp;nbsp;ipv4:&lt;SPAN&gt;52.212.19.177 first thing in the SPF config, then Exchange just sees that that IP is allowed to send mails from your domain, and doesn't give temperror.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Either way I'll test that with the customer and report back if it fixes it.&lt;BR /&gt;&lt;BR /&gt;I have tried creating some allow rules in the Tenant Allow/Block Lists, on Microsoft Exchange config but haven't been able to make the tags stop showing up from the Exchange side.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Rafael Santiago&lt;/P&gt;</description>
    <pubDate>Wed, 23 Jul 2025 09:52:25 GMT</pubDate>
    <dc:creator>RafaelSantiago</dc:creator>
    <dc:date>2025-07-23T09:52:25Z</dc:date>
    <item>
      <title>SPF temperror and Unverified tag added to internal emails after integrating with Microsoft Office365</title>
      <link>https://community.checkpoint.com/t5/Email-and-Collaboration/SPF-temperror-and-Unverified-tag-added-to-internal-emails-after/m-p/253744#M658</link>
      <description>&lt;P&gt;Recently we have integrated the Harmony Email solution with a customer's Microsoft Exchange environment.&lt;/P&gt;&lt;P&gt;After applying a Prevent (Inline) policy to some users, we started experiencing some internal mails (between users of the same domain) showing up on the users mailboxs with an unverified tag, assumingly added by Exchange.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Captura de ecrã 2025-07-23 093012.png" style="width: 777px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31009iF52FE080E831E3B0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Captura de ecrã 2025-07-23 093012.png" alt="Captura de ecrã 2025-07-23 093012.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;All of them are between users with Prevent policies applied to them in the Harmony Email config. Also when looking at the headers, all of them give an SPF:temperror DNS timeout.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Authentication-Results: spf=temperror (sender IP is 52.212.19.177)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;smtp.mailfrom=&lt;STRONG&gt;&amp;lt;customer_domain&amp;gt;&lt;/STRONG&gt;; dkim=none (message not signed)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;header.d=none;dmarc=temperror action=none&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;header.from=&lt;STRONG&gt;&amp;lt;customer_domain&amp;gt;&lt;/STRONG&gt;;compauth=fail reason=601&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Received-SPF: TempError (protection.outlook.com: error in processing during&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;lookup of &lt;STRONG&gt;&amp;lt;customer_domain&amp;gt;&lt;/STRONG&gt;: DNS Timeout)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The IP it's trying to check is from Check Point, included in the&amp;nbsp;&lt;SPAN&gt;spfa.cpmails.com domain.&lt;BR /&gt;We added this domain to SPF a while before changing the policy to Prevent.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;As the name temperror indicates, this behavior with the Unverified tag, and the SPF temperror that comes with it, are very volatile. The customer has a big email volume, so we see it every day, but it doesn't happen with the majority of internal mails of users included in the Prevent policy.&lt;/P&gt;&lt;P&gt;For the emails that don't have the unverified tag, the SPF passes with exactly the same IP.&lt;/P&gt;&lt;P&gt;One possible justification for this could be issues with the customer DNS, but before adding the Prevent Policies (and before the Harmony Email solution) to the customers infrastructure, they had never seen this kind of behavior with unverified tags, and they also had never had any SPF related issues.&lt;/P&gt;&lt;P&gt;One other possible justification is problems with the&amp;nbsp;&lt;SPAN&gt;spfa.cpmails.com domain, sometimes timing out when the Exchange tries to check the IPs included in their DNS configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I asked the customer to add ipv4:&lt;SPAN&gt;52.212.19.177, to try to avoid having to check the&amp;nbsp;spfa.cpmails.com domain and see if the unverifieds stop happening.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If it is, this customer can't be the only one suffering with this issues.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;For other customers that use Harmony Email in Prevent, have their data residency in the EU, and see the IP&amp;nbsp;52.212.19.177 on SPF (from what I have seen, in the EU, multiple IPs can be used but in this scenario I have only seen this one), has anyone been having this kind of issues with SPF?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" href="https://sc1.checkpoint.com/documents/Harmony_Email_and_Collaboration/Topics-Harmony-Email-Collaboration-Admin-Guide/Getting-Started/Activating-O365-Mail/O365-Footprint-Mail-flow-rules.htm?Highlight=52.212.19.177#" target="_blank" rel="noopener"&gt;&lt;SPAN class=""&gt;Infinity Portal&lt;/SPAN&gt;&amp;nbsp;tenants residing in Europe&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;52.17.62.50&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;52.212.19.177&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;3.252.108.160/28&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;13.39.103.0/28&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;13.39.103.16/28&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;3.252.108.176/28&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Thank you for your attention.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rafael Santiago&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 08:59:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Email-and-Collaboration/SPF-temperror-and-Unverified-tag-added-to-internal-emails-after/m-p/253744#M658</guid>
      <dc:creator>RafaelSantiago</dc:creator>
      <dc:date>2025-07-23T08:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: SPF temperror and Unverified tag added to internal emails after integrating with Microsoft Offic</title>
      <link>https://community.checkpoint.com/t5/Email-and-Collaboration/SPF-temperror-and-Unverified-tag-added-to-internal-emails-after/m-p/253745#M659</link>
      <description>&lt;P&gt;Yes, we noticed this intermittent time-out issue from Microsoft towards 52.212.19.177 after we switched to having SPF managed by Check Point. We raised a ticket with Harmony support in early June but were basically brushed off with "&lt;SPAN&gt;you would need to engage with Microsoft as the means to gain that information would not be available to us given that this occurred in the Microsoft environment".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Life's too short for us to raise tickets with MS if it can be avoided - we can live with this as it's only affecting us very intermittently (and the only negative effect appears to be an "Unverified" banner in Outlook). If I were an MSP support this solution for customers I would chase this to the bottom, though - Check Point should definitely be stepping up.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 09:19:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Email-and-Collaboration/SPF-temperror-and-Unverified-tag-added-to-internal-emails-after/m-p/253745#M659</guid>
      <dc:creator>ToffenDask</dc:creator>
      <dc:date>2025-07-23T09:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: SPF temperror and Unverified tag added to internal emails after integrating with Microsoft Offic</title>
      <link>https://community.checkpoint.com/t5/Email-and-Collaboration/SPF-temperror-and-Unverified-tag-added-to-internal-emails-after/m-p/253748#M660</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/41996"&gt;@ToffenDask&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the quick reply.&lt;/P&gt;&lt;P&gt;I have a case opened with Check Point support but I'm also not seeing it go very far.&lt;BR /&gt;Have you tried to put ipv4:&lt;SPAN&gt;52.212.19.177 on your SPF configuration, to see if the time out happens when Microsoft tries to communicate with&amp;nbsp;spfa.cpmails.com domain, to see their IPs?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I'm not 100% sure, but I assume that if we put&amp;nbsp;ipv4:&lt;SPAN&gt;52.212.19.177 first thing in the SPF config, then Exchange just sees that that IP is allowed to send mails from your domain, and doesn't give temperror.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Either way I'll test that with the customer and report back if it fixes it.&lt;BR /&gt;&lt;BR /&gt;I have tried creating some allow rules in the Tenant Allow/Block Lists, on Microsoft Exchange config but haven't been able to make the tags stop showing up from the Exchange side.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Rafael Santiago&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 09:52:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Email-and-Collaboration/SPF-temperror-and-Unverified-tag-added-to-internal-emails-after/m-p/253748#M660</guid>
      <dc:creator>RafaelSantiago</dc:creator>
      <dc:date>2025-07-23T09:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: SPF temperror and Unverified tag added to internal emails after integrating with Microsoft Offic</title>
      <link>https://community.checkpoint.com/t5/Email-and-Collaboration/SPF-temperror-and-Unverified-tag-added-to-internal-emails-after/m-p/254097#M661</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;We have added the ip4:&lt;SPAN&gt;52.212.19.177 on the SPF of the customer's domain, and since then no more unverified emails appeared.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm pretty confident this is a problem with the domain spfa.cpmails.com propagation and or response throughout DNS. I am trying to address this issue with Check Point TAC, but in the meantime this seems to be a valid fix.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks once again to&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/41996"&gt;@ToffenDask&lt;/a&gt;,&amp;nbsp;definitely helpfull to know we were not the only ones experiencing this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Rafael Santiago&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 14:04:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Email-and-Collaboration/SPF-temperror-and-Unverified-tag-added-to-internal-emails-after/m-p/254097#M661</guid>
      <dc:creator>RafaelSantiago</dc:creator>
      <dc:date>2025-07-28T14:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: SPF temperror and Unverified tag added to internal emails after integrating with Microsoft Offic</title>
      <link>https://community.checkpoint.com/t5/Email-and-Collaboration/SPF-temperror-and-Unverified-tag-added-to-internal-emails-after/m-p/254115#M662</link>
      <description>&lt;P&gt;Apologies for the late reply. We had indeed done something just like that earlier - we added&amp;nbsp;&lt;SPAN&gt;include:spf.protection.outlook.com to our record to resolve a similar issue. It somewhat defies the purpose of having Check Point manage our SPF entries if we need to add multiple exceptions.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jul 2025 15:31:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Email-and-Collaboration/SPF-temperror-and-Unverified-tag-added-to-internal-emails-after/m-p/254115#M662</guid>
      <dc:creator>ToffenDask</dc:creator>
      <dc:date>2025-07-28T15:31:30Z</dc:date>
    </item>
  </channel>
</rss>

