Check Point splits its protection into separate security engines, each with its own job. This page is a quick reference for what each engine checks and what it typically catches. For how engines are switched on and applied to users, see How Check Point works: engines vs policies.
The engines at a glance
| Engine | What it checks | Example of what it catches |
|---|---|---|
| Anti-Phishing | The message itself: sender, wording, links, headers, QR codes and SPF/DKIM/DMARC results. Gives a verdict of phishing, suspected phishing, spam or graymail. | A fake invoice from a lookalike domain, or a CEO impersonation asking for a payment. |
| Anti-Malware | Attachments, including running them in a sandbox to see what they do when opened. | A Word document that downloads ransomware when opened. |
| Threat Extraction | Attachments that came back clean. Strips risky active content (macros, embedded objects, hidden links) and delivers a safe copy. | A clean-looking PDF with a hidden link or script that nothing has flagged yet. |
| Click-Time Protection | Links, checked at the moment they are clicked rather than only on arrival. | A link that was harmless when the email arrived but points to a phishing page by the afternoon. |
| URL Reputation | Links, checked against reputation data when the email is delivered. | A link to a domain already known for hosting malware. |
| DLP | Sensitive data in mail leaving (or arriving into) the organisation. Can block, quarantine or encrypt. | A spreadsheet of card numbers being emailed to an outside address. |
| Anomaly Detection | Accounts rather than emails: sign-in locations, mailbox rules and sending behaviour. | A login from another country minutes after a login from the office, or a new rule forwarding all mail out. |
| Smart Banners | Not a detection engine. Adds a contextual warning banner to emails so users get a prompt in the moment. | A banner on a first-time external sender saying to be careful with links and payments. |
Why separate engines?
- Different jobs. Judging the wording of an email, detonating an attachment and spotting a hijacked account are different problems, so each gets a specialist engine.
- Independent tuning. You can be strict on malware and relaxed on spam, or turn on Threat Extraction without changing anything else.
- Exceptions stay contained. An allow-list entry only affects its own engine, so trusting a sender for phishing does not switch off malware scanning on their attachments.
- One set of engines, many apps. The same engines protect email, Teams, OneDrive, SharePoint and Google Drive.
The trade-off is that there is more than one place to configure, and no single allow or block list. That is deliberate: it gives finer control and stops one exception from quietly weakening everything else.
Related
How Check Point works: engines vs policies
Managing exceptions and allow-lists
DLP and keyword-triggered email encryption
Anomaly Detection and impossible-travel logins
Creating a policy: a worked example with Click-Time Protection
Need Help with Check Point Harmony?
We deploy, configure, and manage Check Point Harmony Email & Collaboration for businesses, making sure your policies, engines, and protection modes are set up correctly so your organisation is fully covered.
Speak to an expertWas this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article