> Source: [sk173972](https://support.checkpoint.com/results/sk/sk173972)

# sk173972 - MTA Issues with Sender Policy Framework (SPF)

| Property | Value |
|----------|-------|
| Solution ID | sk173972 |
| Date Created | 2021-07-21 |
| Last Modified | 2025-04-23 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * This issue occurs in these scenarios when the Mail Transfer Agent (MTA) is active:
  * Scenario A: Anti-Spam and Sender Policy Framework (SPF) are both enabled.
  * Scenario B: Anti-Spam is disabled, but SPF is enabled (in all tested environments).

  In both scenarios, legitimate emails are incorrectly marked as spam.

  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk173972/Detect202107211712331.png)

  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk173972/127_loopback202107211714422.png)
* Activating SPF when MTA is enabled affects the behavior of the Threat Prevention blades as follows: <br />

  * Threat Emulation blade: The system performs a Detect action instead of a Prevent action for malicious files.
  * Threat Extraction: Not triggered when scanning emails.

## Cause

**Scenario A:** Anti-Spam cannot process encrypted emails. These emails are forwarded to the local gateway IP address 127.0.0.1.However, since this IP address is not authorized by SPF, the forwarded emails will be rejected.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
