# Avanan email security

> Avanan email security is Check Point's API-based inline protection for supported SaaS email. Learn what it examines and what it does not prove.

Avanan email security is Check Point's API-based inline protection for supported SaaS applications. For email, Check Point says it analyzes messages before delivery and handles a malicious verdict through the configured workflow, while non-malicious mail is delivered. Its documented email-protection coverage includes Microsoft Exchange Online and Gmail. That makes it an inbox-threat-protection product, not proof that a sending domain's SPF, DKIM, or DMARC configuration is correct. [Check Point's introduction to Avanan](https://sc1.checkpoint.com/documents/Avanan_Admin_Guide/Email_Security/Admin_Guide/Topics/introduction/introduction-to-Email-Security.html) describes that scope.

## Quick takeaways

- Avanan is documented as API-based inline protection for SaaS applications, including email and collaboration services.
- For email, Check Point describes analysis before recipient delivery and a configured workflow for malicious verdicts.
- The product documentation names Microsoft Exchange Online and Gmail as supported email applications.
- A message-security decision and sender-domain authentication answer different questions, so inspect both when email trust is the concern.

## What Avanan email security does

[Check Point's current product introduction](https://sc1.checkpoint.com/documents/Avanan_Admin_Guide/Email_Security/Admin_Guide/Topics/introduction/introduction-to-Email-Security.html) says Avanan protects SaaS applications from threats including phishing, account takeover, data leakage, and zero-day threats. In its email-protection description, Check Point says Avanan intercepts a sent email, sends it to ThreatCloud for analysis before recipient delivery, and applies the configured workflow when the verdict is malicious. The same documentation says it also inspects internal and outgoing traffic for data leakage, phishing, and malware.

That operating model is different from the conventional pre-inbox routing model described in [our secure email gateway explainer](/learning/how-secure-email-gateways-protect-organization). The important point is not to treat one architecture as a universal label. For Avanan, verify the documented application coverage and the tenant's own policy choices before drawing conclusions about a specific message.

![Four-stage deterministic flow showing email sent, ThreatCloud analysis, configured workflow, and recipient delivery](/images/editorial/avanan-email-security/avanan-email-security-scope.svg "1200x540")

*Source: Original deterministic scope diagram based on [Check Point's Avanan introduction](https://sc1.checkpoint.com/documents/Avanan_Admin_Guide/Email_Security/Admin_Guide/Topics/introduction/introduction-to-Email-Security.html). It summarizes documented flow, not a tenant interface or a guarantee of a message outcome.*

## What Avanan email security does not answer

Avanan documentation describes the product's protection flow. It does not let a public observer determine a particular tenant's policies, licensing, event history, retained messages, or the verdict for one email. Those facts depend on the organization and its configuration.

![Check Point documentation capture of Avanan's quarantined-items view with message filters and a restore action](/images/editorial/avanan-email-security/avanan-quarantine-admin-view.png "876x256")

*Source: [Check Point's Avanan Administration Guide: All Quarantined Emails (Admin View)](https://sc1.checkpoint.com/documents/Avanan_Admin_Guide/Email_Security/Admin_Guide/Topics/managing-quarantine/all-quarantined-emails-admin-view.html), captured from the current official documentation on July 29, 2026. The documentation image shows the interface shape, not any organization's tenant state.*

It also does not replace the separate sender-domain question: whether mail that claims to be from a domain is authenticated and aligned. Read the foundations of [DMARC](/learning/what-is-dmarc), [SPF](/learning/what-is-spf), and [DKIM](/learning/what-is-dkim) alongside the inbox-protection review. DMARC uses domain-authentication results and a published policy to guide receiver handling, rather than serving as an inbox threat-analysis engine. [RFC 7489's DMARC overview](https://www.rfc-editor.org/rfc/rfc7489.html) explains that distinction.

## A practical way to evaluate the scope

Use this short record to keep product scope, tenant evidence, and sender authentication separate. It prevents a familiar mistake: treating a public product description as proof of what happened to one message.

```text
Question: What do I need to know?
Product scope: Check the current Check Point documentation.
Tenant behavior: Review the organization's own policy and event evidence.
Sender-domain identity: Inspect the published SPF, DKIM, and DMARC records.
Message outcome: Use the message and tenant evidence, not a product summary.
```

If the concern is a suspicious email in a mailbox, preserve the message and use the organization's approved incident process. If the concern is a brand that can be impersonated, start with the published authentication records and then decide whether the sender inventory supports a stronger DMARC policy. Neither check proves the other.

## Sources and further reading

- [Check Point: Introduction to Avanan](https://sc1.checkpoint.com/documents/Avanan_Admin_Guide/Email_Security/Admin_Guide/Topics/introduction/introduction-to-Email-Security.html)
- [RFC 7489: DMARC](https://www.rfc-editor.org/rfc/rfc7489.html)

## Frequently asked questions

### Is Avanan email security a secure email gateway?

No. Avanan is documented as API-based inline protection for supported SaaS applications. A generic secure email gateway article may describe a different routing model, so evaluate Avanan against its documented integration and the organization's actual configuration.

### Does Avanan support Microsoft 365 and Gmail?

Yes. Check Point's current Avanan introduction lists Microsoft Exchange Online and Gmail under supported applications for Email Protection. Support for a named application does not reveal the policies, license, or operational state of a particular tenant.

### Does Avanan replace SPF, DKIM, and DMARC?

No. Avanan's documented role is threat protection for supported SaaS applications. SPF, DKIM, and DMARC address sender-domain authentication and policy, so they should be assessed separately from an inbox-protection product.

### Can Avanan remove a message after delivery?

Yes. Check Point states that Avanan can remove and modify emails post-delivery if needed. Whether that occurs for a particular message depends on the organization's configuration and evidence, so the product description alone cannot confirm an outcome.

### Can a public check show an Avanan tenant's policies?

No. Public checks can examine published sender-domain records, but they cannot show a tenant's Avanan policy, security events, quarantined messages, licensing, or a specific message verdict. Those require authorized organization evidence.
