Managing exceptions and allow-lists

Modified on Wed, Sep 23 at 10:14 AM

Every Check Point engine can have exceptions: entries that tell that engine to treat certain senders, domains, URLs, files, or recipients differently. Used well, exceptions kill false positives. Used carelessly, they punch holes in your protection. This article explains how exceptions work, the list types, and each engine's exception capability.

Where exceptions live

Go to Security Settings → Exceptions. Each engine has its own list. The most important rule to understand up front: an exception only affects the engine it sits under. Allow-listing a sender for Anti-Spam does not exempt it from Anti-Phishing or malware scanning.

List types

Most engines offer more than one list:

  • Allow-List — treat matching items as clean and exempt them from that engine's verdict.
  • Block-List — always treat matching items as bad, regardless of what the engine would decide.
  • Ignore-List (Click-Time) — don't apply the engine's action to these items (for example, don't rewrite these links) without fully trusting them.

Each engine's exception capability

EngineLists availableWhat you can match on
Anti-PhishingAllow-List, Block-ListSubject, recipient, sender email, sender domain, sender name, sender IP (client), server IP (SMTP), links, attachment hash, header. Also an "Ignore SPF Check" option per rule.
Anti-MalwareAllow-List, Block-List, Password-Protected AttachmentsSender, file hash, macro hash, file type. The Password-Protected Attachments list controls how encrypted attachments the sandbox cannot open are handled.
AnomalyAnomaly exceptionsSpecific anomaly types / details, so a known service that trips (for example) impossible-travel stops generating events.
Click-Time ProtectionAllow-List, Block-List, Ignore-ListDomain. Allow treats links as clean, Block as malicious, Ignore leaves the links un-rewritten.
Anti-Spam (Trusted Senders)Trusted SendersSender / domain, scoped to a recipient or all recipients. Spam from them reaches the inbox instead of quarantine or Junk.
Smart BannersTrusted SendersSender / domain, scoped to recipients. Their mail won't show smart banners to those users; spam, phishing, malware and quarantine handling are unchanged.
URL ReputationAllow-List, Block-ListExact URL or Domain. Allow-listed URLs won't be flagged by URL Reputation.
DLPAllow-List, Block-ListRecipient, sender, file hash, or string. Allow-listed matches won't be treated as a DLP violation.
Threat ExtractionAllow-ListSender or file hash. Matching mail skips content extraction and the original file is delivered.

Adding an exception (example: a spam Trusted Sender)

Go to Exceptions → Anti-Spam → Create Trusted Sender. Enter the sender or domain and the recipient (or tick All recipients). Spam from that sender then reaches the inbox rather than quarantine or Junk. Note the scope: this only exempts spam. Phishing, malware, and quarantine handling for that sender are unchanged.

DLP and URL allow-lists

DLP allow-lists can key off recipient, sender, file hash, or string, which is useful when a specific legitimate flow keeps tripping a DLP rule. URL Reputation allow-lists take an Exact URL or a whole Domain.

Example — allow a domain and its subdomains: to allow only the exact domain, choose List Type = Domain and enter example.com. To allow the domain and all of its subdomains (www.example.com, shop.example.com, and so on), use the wildcard form *.example.com. A bare example.com entry matches the apex domain and may not include subdomains, so use the wildcard when you intend to cover the whole subdomain tree.

Next steps

Next: Notifications, alerts and reporting

Previous: Anomaly Detection and impossible-travel logins

Need Help with Check Point Harmony?

We deploy, configure, and manage Check Point Harmony Email & Collaboration for businesses, making sure your policies, engines, and protection modes are set up correctly so your organisation is fully covered.

Speak to an expert

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article