CheckPoint Email Security in Outlook: Report Phishing and Manage Quarantined Email

Start here

Use CheckPoint Email Security in Outlook to report suspicious email, find quarantined messages, and check restore requests. Quarantine holds messages apart from your mailbox until they are released.

Availability: These steps apply to CCC accounts with the CheckPoint Outlook add-in enabled. Contact ITS if you need access.

These steps follow the Outlook for Windows ribbon shown below. Use your CCC mailbox and the CheckPoint Email Security menu. Other Outlook layouts need separate validation before their click paths are added to this guide.

In this article: Open the portal | Report phishing | Find and restore email | Notices and help

Open the Email Security Portal

  1. Open Outlook and select your CCC mailbox. If the add-in is not visible, select an email so its message tools are available.
  2. On the ribbon, select CheckPoint Email Security. The name may be shortened to CheckPoint Email Securi... in a narrow window.
  3. Choose Email Security Portal from the menu. The portal opens in an Apps pane inside Outlook.

CCC Outlook CheckPoint Email Security menu with Report Phishing and Email Security Portal

Vendor portal Overview with Find quarantined emails and Check on my restore requests

Figures 1 and 2. The CCC Outlook menu and a CheckPoint portal example. The portal layout and counts may differ at CCC.

Choose what you need

  • Find quarantined emails opens the messages held for your account.
  • Check on my restore requests shows requests you have already made and their status.
  • Pop Out, at the bottom of the pane, gives the portal more room. A narrow pane may show a three-line menu for navigation.

Missing the button? Confirm that you are using your CCC mailbox and an account with the add-in enabled, select a message, then close and reopen Outlook. Contact ITS if it is still missing. Do not install a separate add-in or grant new permissions yourself.

References: Accessing the portal from Outlook · Overview example

Report a suspicious email

Report messages that ask you to sign in unexpectedly, send money or gift cards, share private information, or act on an unusual request. An email can be suspicious even when it appears to come from someone you know.

  1. Select the suspicious message in Outlook. Do not click its links, open its attachments, reply, or use a phone number supplied in the message.
  2. Select CheckPoint Email Security on the ribbon, then choose Report Phishing. Use the CheckPoint menu shown in Figure 1.
  3. Follow the on-screen prompts and read the result in the add-in. If no confirmation or result appears, contact ITS with the sender, subject, and approximate time of the report.

Understand the result

CCC uses CheckPoint Email Security > Report Phishing. Read the displayed result and explanation, then follow the guidance below. A submission or automated result does not establish that an ITS analyst has reviewed the message.

Result What to do
Phishing Leave the message alone. Do not restore it or interact with its contents.
Inconclusive Treat the message cautiously. Ask ITS to review it if you need to act on the request.
Clean The analysis did not identify a threat. If the request still seems unusual, verify it through a separate, trusted contact method before acting.

A report result is not a guarantee. If someone tells you they did not send the message, or the request does not make sense, contact ITS even if an automated result says Clean.

After you report a message

Leave the reported message alone. If it is no longer in its original folder, check Deleted Items. Do not move it back or resume a suspicious conversation because a result says Clean. Ask ITS to help recover a legitimate message you still need.

You do not need to prove that an email is malicious before reporting it. When in doubt, report it. If you need to act on an unusual request, verify it through a separate, trusted contact method.

If you already clicked or shared information

Stop interacting with the message and contact the ITS Service Desk at 503-594-3500 promptly. Tell them whether you clicked a link, opened an attachment, entered a password, approved a sign-in, or sent information. Do not send anyone your password or verification code.

Reference: CheckPoint phishing reporting and results

Find and restore a quarantined email

  1. Open Email Security Portal, then choose Find quarantined emails or Quarantine. Select Quarantined Emails to focus on messages still held.
  2. Use the Subject, Sender, or Email Date filters to narrow the list. If nothing appears, clear or widen the filters. Select a message to inspect its details.
  3. Check the sender, subject, and reason it was held. Do not use links or attachments to decide whether it is safe. If you were not expecting it or unsure, leave it in quarantine and ask ITS.

Vendor quarantine list, message details, filters, threat category and restore action

Figure 3. Vendor quarantine example. Use the filters, select a message in the list, and review its subject, date, preview, and threat category. The action button is at the lower right; sample messages and available actions may differ at CCC.

Reference: Viewing quarantined emails and screenshot legend

Use the action offered for that message

Action What it means
Restore The current policy permits a direct release. Use it only for a message you are confident you need and expected.
Request Restore Send the message for review. A submitted request does not mean the message has been approved or delivered.
No available action Do not try another route to bypass the restriction. Contact ITS with the sender, subject, and approximate date.

If asked for a reason, briefly explain why you expected the message. For example: “I requested this document from the sender yesterday.” Submit the request once and check its status in the portal.

Vendor restore request dialog showing reason field and Submit button

Figure 4. Vendor restore-request example. Enter a short reason and select Submit. Use the action and prompt shown for your message.

Check the outcome

Choose Check on my restore requests or Restore Requests. Pending approval means the request is waiting for a decision. Declined means it was not approved. Restored means it has been released. Search Outlook by sender or subject if you do not see it; a restored message may show the release time as its received time.

Vendor Restore Requests list showing Pending Restore Approval and Restored statuses

Figure 5. CheckPoint status example. Read the status beside each message: Pending Restore Approval is still waiting; Restored has been released. These sample messages are from vendor documentation.

References: Portal permissions · Restore dialog · Request status · Restored messages

Recognize notices and get help

CCC quarantine summary

CCC’s quarantine summary is titled “Quarantined and Spam/Junk Email Report” and uses the sender no-reply@checkpoint.com. Recent pilot examples cover the preceding 24 hours and list quarantined messages and Spam/Junk Email separately.

  • Quarantined messages remain held until released. Spam/Junk messages listed in the summary are in Outlook’s Junk Email folder. An empty section means the summary lists no items in that category.
  • Use Email Security Portal to review a message or restore request. Submitting Request Restore asks for a decision; it does not mean the message has been approved or delivered.
  • If you receive a report or restore decision notice, compare it with the portal and what you know about the message. Contact ITS before acting on a conflicting or unexpected result.

Sender addresses, subjects, and logos are recognition clues, not proof of authenticity. They can be copied or forged. You do not need to release every message listed in a summary.

Verify a notice safely

  1. Open Outlook yourself. Use CheckPoint Email Security > Email Security Portal instead of following an unexpected email link.
  2. Look for the relevant message or restore request in the portal. Review the sender, subject, date, and status.
  3. If the notice still seems wrong, report it or contact ITS. Do not reply with your password, a verification code, or private information.

Common questions

I cannot find an expected message. Check Outlook’s Junk Email and Deleted Items as well as the portal. Widen the portal date filter. The portal may not show every blocked or older message; contact ITS if it is still missing.

The preview or restore button is missing. Available actions and message content depend on policy and how long the message is retained. ITS can check the message; do not repeatedly request a release.

I see Trusted Senders or Manager Approvals. These options can appear for some accounts. You do not need them for the steps in this guide. Ask ITS before using a trust or allow-list option to work around a blocked message.

Where to get help

Staff and security concerns: ITS Service Desk, 503-594-3500.
Student help with email or access: Cougar Connect Tech Help Desk, 503-594-6632.

Have the sender, subject, approximate date, error text, and Outlook version ready. Share screenshots through the support channel only after removing unrelated messages and personal information.

References: Quarantine summaries · CCC technology help

Vendor screenshots are © CheckPoint Software Technologies Ltd. Captions identify vendor examples.