Not every message Check Point flags is outright spam. Understanding how Check Point and Microsoft 365 classify mail, especially the difference between graymail and spam, helps you read the dashboards correctly and avoid chasing false alarms.
Graymail vs spam
- Spam is unsolicited junk that filtering should block.
- Graymail is bulk-but-not-spam: newsletters, marketing, and notifications a user may well have opted into. It is legitimate bulk mail rather than an attack.
Microsoft 365 tracks these separately, with a Bulk Complaint Level (BCL) for bulk/graymail and a Spam Confidence Level (SCL) for spam.
How Microsoft 365 decides bulk vs spam
M365 scores bulk mail with a BCL. When the BCL crosses a threshold (default 7), M365 promotes the message from "bulk" to "spam". So the same kind of message can be treated as bulk at one score and spam at a higher one. Bulk and spam are not mutually exclusive: spam is essentially bulk that has crossed the line.
Where Check Point fits
What Microsoft calls graymail, Check Point classifies as bulk with low spam confidence. It surfaces these in its dashboards so you can see bulk and marketing volume separately from genuine threats.

Related
Event states and severities explained
Need Help with Check Point Harmony?
We deploy, configure, and manage Check Point Harmony Email & Collaboration for businesses, making sure your policies, engines, and protection modes are set up correctly so your organisation is fully covered.
Speak to an expertWas this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article