> Source: [sk140214](https://support.checkpoint.com/results/sk/sk140214)

# sk140214 - How to allow users to send the original e-mail to their mailbox through the UserCheck portal for Threat Extraction

| Property | Value |
|----------|-------|
| Solution ID | sk140214 |
| Date Created | 2018-11-13 |
| Last Modified | 2021-10-20 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) starting from Take 203

If you choose not to upgrade:

It is possible to allow end users to send the original e-mail to their mailbox through the "Approve" page of the UserCheck portal. A new text box and a "Send" button will be added to the UserCheck "Approve" page of Threat Extraction.

Users can write their e-mail addresses in the text box (the address should be the same as that written in the original e-mail). Users will receive the original e-mail in the mailbox.

### **To enable this feature**:

1. Add the $send_original_mail$ to the UserCheck Approve page of Threat Extraction. Note that the original page cannot be modified and should be cloned.

![](https://sc1.checkpoint.com/sc//SolutionsStatics/NEW_SK_NOID1542120191687/11811130651. insert field.png)

![](https://sc1.checkpoint.com/sc//SolutionsStatics/NEW_SK_NOID1542120191687/21811130651. New field view.png)

2. Assign the newly created UserCheck page to Threat Extraction.

![](https://sc1.checkpoint.com/sc//SolutionsStatics/NEW_SK_NOID1542120191687/31811130653. Assign new approve page.png)

3. Install the Threat Prevention policy.

### **To disable this feature**:

1. Remove the $send_original_mail$ from the UserCheck Approve page of Threat Extraction or restore the original Approve page from the engine settings page.
2. Install the Threat Prevention policy.

**Notes**:

* The user must be one of the original recipients.
* The strings used in the feature can be changed in: *opt/CPUserCheckPortal/phpincs/conf/L10N/portal_en.php*
* For malicious files, users should be allowed to access original files. Otherwise, the file will be blocked by Threat Emulation.

![](https://sc1.checkpoint.com/sc//SolutionsStatics/NEW_SK_NOID1542120191687/41811130656. Allow to access original filkes.png)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
