Hi @Sinichi_Kudo ,
While no email security solution catches 100% of spam variants, understanding why a specific email bypassed Harmony Email & Collaboration (HEC) comes down to inspecting scan verdicts, policy actions, and exceptions.
Here is a breakdown of the common causes and the recommended troubleshooting steps:
1. Possible Causes
- Active Whitelist / Exceptions: The sender, domain, IP, or URL might match an allow-list rule under Security Settings > Exceptions.
- Policy Action Configuration: The Anti-Spam or Anti-Phishing policy rule might be set to Detect/Monitor or In-box Warning instead of Inline Quarantine.
- Evolving Spam / Clean Sender Reputation: Zero-day spam campaigns using newly compromised accounts or clean domains may not trigger threshold scores at the exact time of delivery.
- Mail Flow Routing: In Microsoft 365 or Google Workspace, ensure mail flow rules correctly route incoming mail through HEC before inbox delivery.
2. Step-by-Step Troubleshooting Workflow
- Inspect Event Verdicts:
- Navigate to Events in the HEC Infinity Portal.
- Locate the email and review Scan Info to see individual engine scores (Anti-Spam, Anti-Phishing, URL Reputation).
- Check Exceptions:
- Go to Security Settings > Exceptions and confirm no whitelist rule bypasses inspection for this sender or domain.
- Report Mis-classification (Crucial):
- Open the message in Events and click Report Mis-classification.
- This submits the email sample directly to Check Point ThreatCloud to update global engine signatures and tune your tenant's detection model.
- Review Policy Action & Thresholds:
- Ensure your Anti-Spam policy action is set to Inline Quarantine or Move to Junk.
For further details on engine configuration and event management, check the Harmony Email & Collaboration Administration Guide.