Check Point Email Security now extends SPF and DKIM validation across custom sender domains used for end user notifications.

Organizations often customize the sender address of end user notifications to use their own domain instead of the default checkpoint.com domain. To help ensure these messages successfully pass DMARC validation and reach users as expected, Check Point Email Security now expands validation of SPF and DKIM settings across all custom notification sender configurations.

Previously, Check Point Email Security validated SPF records for most custom notification senders before applying a custom sender domain. With this release, SPF validation is now also enforced for the End User Quarantine Report (daily digest), completing SPF validation coverage across all end user notifications. When administrators configure a custom sender domain for the daily digest, the change will only take effect after Check Point detects the required SPF include statement (include:spfa.cpmails.com) in the domain’s SPF record.

In addition, Check Point Email Security now validates DKIM configuration whenever a custom sender domain is configured for any end user notification. This provides administrators with greater visibility into potential email authentication issues before notifications are sent, helping reduce the risk of delivery problems caused by missing or incorrect DKIM records. If SPF validation succeeds but DKIM validation fails, Check Point Email Security will still apply the custom sender domain while notifying administrators of the DKIM validation failure.

Important for Existing Customers

Customers who have already customized the sender domain for the End User Quarantine Report should review their current SPF validation status by navigating to:

Security Settings > User Interactions > Quarantine > End User Quarantine Report > Sender

If the SPF validation has not passed, update your DNS configuration to include the required include:spfa.cpmails.com statement. Customers have until August 19 to complete this update. After this grace period, if the SPF validation still fails, Check Point Email Security will automatically revert the daily quarantine report sender to a checkpoint.com domain to help ensure reliable email delivery.

This update is being gradually deployed and will become available in customer portals over the next 7 days.

You may also like