- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
We are experiencing an issue with Harmony Email security and would like your assistance.
On 8th September, a phishing email was successfully blocked by Harmony Email.
On 19th September, a similar phishing email from a different sender was delivered to the customer’s mailbox.
The phishing email on 19th September was not blocked by Harmony Email and we were unable to find any related logs for this event.
Email tracing shows that the message hit the Microsoft external email header policy, but it did not trigger any Check Point policy enforcement.
Despite this, the email still reached the customer mailbox.
Concerns / Questions:
Why did Harmony Email fail to block the phishing email on 19th September?
Why are there no Harmony Email logs for this email?
Why was the message processed only under Microsoft’s external header policy and not evaluated by Check Point’s security controls?
Do you have a SR# wuth CP TAC open already to get these questions answered?
For something like this, I would definitely open TAC case. In the meantime, are there any relevant logs you can send us?
Andy
Specific instances of false positives/false negatives should be addressed via TAC.
Do you have a SR# wuth CP TAC open already to get these questions answered?
We raised a service request, and their response was that “this user is not a protected user.” That part is correct, since the object in question is not an individual user but a Microsoft group. However, inside this group there are multiple protected users. The concern is why the email was still delivered to those protected users and not blocked. Additionally, we need to understand why the message was not automatically deleted from the inboxes of those protected users.
Definitely should have been deleted, agree.
Andy
Hey mate,
Any news about this? What did TAC say?
Best,
Andy
For something like this, I would definitely open TAC case. In the meantime, are there any relevant logs you can send us?
Andy
Specific instances of false positives/false negatives should be addressed via TAC.
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY