惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 三生石上(FineUI控件)
S
SegmentFault 最新的问题
Jina AI
Jina AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
美团技术团队
V
Visual Studio Blog
人人都是产品经理
人人都是产品经理
博客园 - 叶小钗
有赞技术团队
有赞技术团队
GbyAI
GbyAI
宝玉的分享
宝玉的分享
腾讯CDC
M
MIT News - Artificial intelligence
博客园 - 【当耐特】
Google DeepMind News
Google DeepMind News
月光博客
月光博客
MyScale Blog
MyScale Blog
Last Week in AI
Last Week in AI
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 司徒正美
Recent Announcements
Recent Announcements
MongoDB | Blog
MongoDB | Blog

Check Point Blog

Reading the Signals in the OWASP LLM Top 10 2026 - Check Point Blog Ransomware Didn't Slow Down in Q2 2026. It Just Spread Out. - Check Point Blog July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens - Check Point Blog State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit - Check Point Blog Lazarus Hackers Exploit Windows Zero-Day in Fake Job Scam Native AI Security Comes to Claude: Why Anthropic's Inference Hooks Matter - Check Point Blog Claude AI Security: How Anthropic Inference Hooks Enable Real-Time Protection The Top Exposure Management Questions Security Leaders Ask (Part 1) - Check Point Blog Black Hat 2026: Check Point Research Takes the Stage - Check Point Blog Check Point Joins the Open Secure AI Alliance to Advance Open, Measurable and Enterprise-Ready AI Security - Check Point Blog Three AI security disclosures, fourteen days: what the warnings signs are telling us - Check Point Blog When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context - Check Point Blog Your VLAN Isn’t an Air Gap: Six Hard Truths From the New CI Fortify Guidance - Check Point Blog Check Point Named a Visionary Leader in the 2026 Frost Radar™ for Enterprise Risk Mitigation and Management Platforms - Check Point Blog AI Escaped a Sandbox. That is Not What Should Worry You - Check Point Blog Introducing the Industry's First AI Network Firewall - Check Point Blog Attackers Are Turning Microsoft's Trusted Login System Into Their Latest Phishing Weapon - Check Point Blog AI Agent Security Just Had Its Catalyst Moment - Check Point Blog Your AI Governance Policy Should Survive Your Next Model Change - Check Point Blog The Branding and Attribution Behind Cybercrime - Check Point Blog Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report - Check Point Blog Security Advisory - Action Required - July 2026 Security Update - Check Point Blog What the 2026 Exposure Gap Report Reveals About Remediation - Check Point Blog Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention - Check Point Blog The State of Hybrid SASE: Built-In vs. Bolted-On - Check Point Blog AI Appreciation Day: Let's Be Honest About What We're Appreciating - Check Point Blog AI Security Is Never Finished: Building the Continuous Red Teaming Loop  - Check Point Blog AI Security Threats in 2026: Annual Insights from Check Point Research - Check Point Blog AI Agents are Only As Effective as Their Harness - Check Point Blog Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security - Check Point Blog How Check Point Email Security Stopped a Student Job Scam Before It Reached the Inbox - Check Point Blog Redefining the CISO Contract: From Securing the Business to Securely Doing Business - Check Point Blog
Prevention Before the Inbox: Reading the Microsoft Defend...
lizwu@checkpoint.com · 2026-06-25 · via Check Point Blog

Check Point Email Security is built to stop threats before they reach the mailbox. It works inline and pre-delivery: it hooks into Microsoft 365 mail flow through transport rules and the API, holds and analyzes each message in real time, and quarantines malicious mail before it is delivered. The malicious message never lands. By design, Check Point Email Security calls the Microsoft Graph API sparingly. Because the goal of email protection should happen before delivery, ideally leaving little left to act on post delivery. Check Point Email Security deploys without an MX record change, so the MX records stays pointed at the native gateway.

Understanding and respecting the architecture of Check Point Email Security is the key to reading Microsoft’s Defender for Office 365 performance-benchmarking page. The context of API benchmarking is very important when interpreting this graph:

Check Point’s limited API activity should be understood in the context of its architecture: the lack of activity here complements Check Point Email Security, proving our design that does not holistically rely on API calls for protection.

The contributors of this Microsoft article likely meant well, and they are doing their best to showcase the value of ICES platforms integrating into the Defender platform. However, the lack of attention to detail for the second year in a row is disappointing. Where the value of this graph concerning Check Point is lost, is they obviously did not check the Check Point Quarantine for the cumulative Pre and Post Delivery catches; it is apparent that they only derived data points based on Graph API activity which Check Point is specifically designed to minimize.

What the benchmark counts

On the page’s ICES track, a “catch” is a Microsoft Graph API action. In Microsoft’s own words, “ICES vendors use the Microsoft Graph API to move emails to folders such as junk, promotional, or deleted items,” and “a message moved by an ICES vendor is counted as a catch.” A message can only be moved once it has already been delivered, so the metric counts post-delivery cleanup, and it does not factor in pre-delivery protection at all.

Check Point Email Security sits in an unusual place. It behaves like a secure email gateway, inline and stopping mail before delivery, while integrating through the API like an ICES platform. The page filed it on the ICES track and scored it on post-delivery moves alone. Pre-delivery prevention was not counted at all. Had it been, the seemingly low score would look very different, because the threats Check Point stops upstream never become a post-delivery “catch” to tally.

What the other outcomes show

Independent analysis bears that out. In Gartner’s Critical Capabilities for Email Security (1 December 2025, data as of 3 October 2025), Check Point ranked #1 of 14 vendors for Core Email Protection, Gartner’s measure of inbound email security, with a score of 3.49. The tools Microsoft’s page highlights ranked below it: Darktrace 2nd (3.34), Abnormal 5th (3.19), Microsoft Defender tied 8th (3.15), and KnowBe4 11th (2.99) [5]. Check Point is also named a Leader in Gartner’s December 2025 Magic Quadrant for Email Security.

What Email Security should optimize for

The category label, ICES or SEG, describes how a tool connects, not where it stops a threat. What an organization invests in a platform for is a security outcome: accurate filtering, ideally before the inbox. A post-delivery metric tells you who cleaned up after mail arrived. Check Point Email Security is built as a Pre-Delivery Email Security platform that also provides post-delivery accountability.