Granular Trusted Sender Controls for Graymail
Check Point Email Security now allows administrators to let users trust Graymail senders without allowing them to trust Spam senders.
Some organizations apply strict Spam policies and do not want users to override Spam classifications. At the same time, they may want to give users more flexibility over legitimate Graymail they choose to receive. This update provides separate trusted sender controls for these scenarios.
Administrators can now manage two types of trusted senders: Spam and Graymail, which follows the existing trusted sender behavior, and Graymail only, which applies trust only when an email is classified as Graymail. If an email from a Graymail-only trusted sender is classified as Spam, the trusted sender entry will not override the classification, and the email will continue to follow the organization’s configured Spam workflow.
This additional granularity allows organizations to give users control over the Graymail they want to receive while maintaining stricter enforcement for Spam.
Administrators also have full visibility and control over both trusted sender lists. Under Security Settings > Exceptions > Anti-Spam, the trusted senders page now includes separate Anti-Spam and Graymail tabs. From there, administrators can view and manage senders trusted for Spam and Graymail separately from those trusted only for Graymail, including adding, editing, or removing trusted senders.
To allow users to trust only Graymail senders, go to the Threat Detection policy, select Allow end-users to trust senders of Graymail emails, and leave Allow end-users to trust senders of Spam emails unchecked.
Note for existing customers: If end users were already allowed to trust senders before this update, they will continue to be able to trust both Graymail and Spam senders. Existing configurations remain unchanged. .
This feature is being gradually deployed and should be available in customer portals over the next 14 days.



