Skip to Main Content
Back to Learning CenterEmail Authentication

Avanan email security

By Taylor TabusaJuly 28, 20267 min read

In brief

Avanan is Check Point's API-based email protection. What it inspects, where it sits in your mail flow, and what it doesn't do for domain authentication.

Avanan email security

Choose Avanan email security if your organization needs Check Point's documented API-based inline protection for supported SaaS email applications and can validate its fit in the tenant. Choose a sender-authentication workflow alongside it when the question is whether mail using your domain passes SPF, DKIM, and DMARC. These products address different evidence: Avanan evaluates email threats and configured handling, while sender authentication establishes domain identity signals.

At a glance

Quick takeaways

  • Check Point documents Avanan as API-based inline protection for supported SaaS applications.
  • Check Point's Email Protection documentation lists Microsoft Exchange Online and Gmail as supported email applications.
  • Check Point says Avanan sends intercepted email to ThreatCloud for analysis before recipient delivery.
  • A malicious verdict follows the tenant's configured workflow, so public documentation cannot prove a particular message outcome.
  • Avanan email security and sender-domain authentication solve separate email-security problems.
  • Public documentation does not show a tenant's license, policies, security events, or quarantined messages.

Who this comparison is for

This comparison is for an email-security administrator evaluating Avanan, now documented by Check Point, as part of an inbound-email protection decision. It is also useful when a buyer needs to separate a product's documented architecture from the evidence needed to confirm that an individual organization's deployment works as intended.

The decision is narrower than choosing a general email-security category. An organization may need protection for messages delivered to Microsoft Exchange Online or Gmail, a way to handle phishing and malware, and separate controls for mail sent using its own domain. Those needs overlap operationally, but they do not produce the same evidence.

For a broader view of buyer choices, use Palisade's email-security comparison hub. For a general deployment comparison, read what an email security gateway is.

How the options were evaluated

The criteria below were checked against current first-party documentation on August 13, 2026. A documented capability counts only within the scope Check Point describes. A fact about an individual tenant remains unknown until the organization checks its authorized configuration and message evidence.

  • Deployment context: Whether the product is documented for the email application the organization uses.
  • Protection flow: What the vendor says happens to email before delivery and after a malicious verdict.
  • Operating evidence: What an administrator must inspect to confirm a tenant's actual policy and a message-specific outcome.
  • Sender-domain boundary: Whether the question concerns inbound threat handling or SPF, DKIM, and DMARC authentication.
  • Unknowns: Missing public documentation is recorded as an open question, not as proof that a capability is absent.
The comparison does not treat a product description as proof that an organization's mail is protected. Confirm DNS separately, confirm the vendor's tenant status, inspect a real message from the relevant production path, and review DMARC aggregate reports after they accumulate.

Avanan email security for API-based email protection

Check Point's Introduction to Avanan describes Avanan as API-based inline protection for SaaS applications. For Email Protection, the same documentation names Microsoft Exchange Online and Gmail as supported applications.

Check Point describes an email flow in which Avanan intercepts a sent email, sends it to ThreatCloud for analysis before recipient delivery, and applies the configured workflow when the verdict is malicious. The documentation also says Avanan inspects internal and outgoing traffic for data leakage, phishing, and malware. Check Point states that emails can be removed and modified after delivery when needed.

  • Best fit: Organizations evaluating documented API-based inline protection for supported Microsoft Exchange Online or Gmail environments.
  • Relevant evidence: Check Point documents pre-delivery ThreatCloud analysis, configured handling for malicious verdicts, and supported Email Protection applications.
  • Tradeoff: The public documentation does not establish the policy, licensing, event history, retained messages, or verdict for a specific tenant or message.
Scope diagram showing documented Avanan email flow from sent message through ThreatCloud analysis and configured handling to recipient delivery
Source: Check Point, "Introduction to Avanan", checked 2026-07-28.

A conventional secure email gateway can use a different routing model. Read what an email security gateway is when the buyer needs to compare that general model with Check Point's documented API-based approach. Do not assume that a category label proves identical deployment behavior.

Palisade for sender-domain authentication work

Palisade is a separate fit when the unresolved problem is sender-domain authentication rather than inbound threat analysis. Palisade is agentic DMARC software that analyzes DMARC aggregate-report data, identifies sending sources and authentication or alignment issues, and creates prioritized remediation tickets. It can propose the next DMARC policy step when evidence indicates a domain may be ready, while a human reviews the evidence and applies the DNS change.

  • Best fit: IT teams and MSPs that need to identify sending sources and work toward DMARC enforcement across one domain or many domains.
  • Relevant evidence: A sender-domain review begins with published SPF, DKIM, and DMARC records, then uses delivered-message and DMARC-report evidence to validate the production sending path.
  • Tradeoff: Palisade does not control an Avanan tenant's policies, message verdicts, quarantine handling, or a receiver's decision about a particular message.
The distinction matters because SPF, DKIM, and DMARC do not perform the same job as message threat analysis. RFC 9989 defines DMARC as a mechanism that uses domain-authentication results and a published policy to guide receiver handling. A passing published record does not prove that every future message will authenticate or reach the inbox.
Decision boundary showing when to evaluate Avanan tenant protection, sender-domain authentication, or both
Source: Palisade.

How to choose

Choose Avanan when the immediate decision is whether its documented Email Protection scope and API-based deployment fit the organization's supported SaaS email environment. Confirm that conclusion in the tenant, because the configured workflow determines how a malicious verdict is handled.

Choose Palisade alongside Avanan when the immediate decision is whether all authorized senders using a domain authenticate and align for DMARC. The two evaluations can both be necessary. One cannot substitute for the other.

Use this evidence scorecard before treating either product description as an operating result:

YAMLyaml
- option: "Avanan email security"
  checked_on: "2026-08-13"
  best_fit: "API-based inline Email Protection for documented supported SaaS email applications"
  verified_evidence:
    - "Check Point documents Microsoft Exchange Online and Gmail support."
    - "Check Point documents ThreatCloud analysis before recipient delivery."
    - "Malicious-email handling follows the configured tenant workflow."
  open_question: "Which policies, licenses, events, and message outcomes apply in this tenant?"

- option: "Palisade" checked_on: "2026-08-13" best_fit: "DMARC operations and sender-domain authentication remediation" verified_evidence: - "DMARC work requires published DNS, message, and aggregate-report evidence." - "Palisade analyzes DMARC aggregate-report data and proposes remediation priorities." open_question: "Which production sending sources still fail authentication or alignment?"

Do not change a DMARC policy based only on a public DNS result. Validate the authoritative DNS record, the vendor's status, a real delivered message from the production path, and DMARC aggregate-report data.

Check the deployment fit before purchase

Review Check Point's Avanan product introduction against the organization's documented email applications and required policy outcomes. Then use the authorized tenant's configuration and message evidence to confirm how the deployment behaves.

This review cannot prove tenant policy, a quarantine action, a specific email verdict, or whether a sender domain will pass SPF, DKIM, or DMARC.

Evidence

Sources and further reading

Questions readers ask

Frequently asked questions

Is Avanan email security a secure email gateway?

No. Check Point documents Avanan as API-based inline protection for supported SaaS applications. A secure email gateway can use a different routing model, so evaluate the documented deployment architecture and the organization's actual configuration.

Does Avanan support Microsoft Exchange Online and Gmail?

Yes. Check Point's Avanan introduction lists Microsoft Exchange Online and Gmail as supported Email Protection applications. That documentation does not show which policies or licenses apply in a particular tenant.

Does Avanan replace SPF, DKIM, and DMARC?

No. Avanan's documented Email Protection scope concerns threat analysis and configured message handling. SPF, DKIM, and DMARC address sender-domain authentication and receiver policy, so they require separate validation.

Can Avanan remove a message after delivery?

Yes. Check Point states that Avanan can remove and modify emails after delivery if needed. Public documentation cannot establish whether this occurred for a particular message in a particular organization.

Can a public check reveal an Avanan tenant's policies?

No. Public documentation can describe the product's scope, but it cannot reveal a tenant's policies, licensing, message events, quarantined items, or the verdict for an individual email. Those require authorized tenant evidence.

Check the domain’s public email-security controls

Enter your domain.

Check your domainGet started

Share this article

Taylor Tabusa

Written by

Taylor Tabusa

Co-Founder & Head of Business Development, Palisade

Taylor Tabusa is the co-founder and Head of Business Development at Palisade, helping managed service providers turn email security into a practical, valuable service.

More from Taylor

Related articles and tools