Yes, the Gateway must be set up as an MTA so it can see & control the delivery of all mail as it gets scanned.
Depending on how you have your email delivery configured, you may not have to change MX records. For example, you could leave your existing Internet-facing MTA where it is and insert your Threat Extraction Gateway in-between the public MTA and your Internal mail server. If you did it this way, you'd only have to change where the public MTA forwards mail inside and make sure your e-mail server is configured to accept mail from the Check Point Gateway.
R80 CCSA / CCSE