Graymail and spam explained

Modified on Wed, Sep 23 at 10:15 AM

Not every message Check Point flags is outright spam. Understanding how Check Point and Microsoft 365 classify mail, especially the difference between graymail and spam, helps you read the dashboards correctly and avoid chasing false alarms.

Graymail vs spam

  • Spam is unsolicited junk that filtering should block.
  • Graymail is bulk-but-not-spam: newsletters, marketing, and notifications a user may well have opted into. It is legitimate bulk mail rather than an attack.

Microsoft 365 tracks these separately, with a Bulk Complaint Level (BCL) for bulk/graymail and a Spam Confidence Level (SCL) for spam.

How Microsoft 365 decides bulk vs spam

M365 scores bulk mail with a BCL. When the BCL crosses a threshold (default 7), M365 promotes the message from "bulk" to "spam". So the same kind of message can be treated as bulk at one score and spam at a higher one. Bulk and spam are not mutually exclusive: spam is essentially bulk that has crossed the line.

Where Check Point fits

What Microsoft calls graymail, Check Point classifies as bulk with low spam confidence. It surfaces these in its dashboards so you can see bulk and marketing volume separately from genuine threats.

Related

Event states and severities explained

Need Help with Check Point Harmony?

We deploy, configure, and manage Check Point Harmony Email & Collaboration for businesses, making sure your policies, engines, and protection modes are set up correctly so your organisation is fully covered.

Speak to an expert

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article