> Source: [sk25941](https://support.checkpoint.com/results/sk/sk25941)

# sk25941 - Configuring 'Mail Alerts' using 'internal_sendmail' command

| Property | Value |
|----------|-------|
| Solution ID | sk25941 |
| Date Created | 2004-04-16 |
| Last Modified | 2025-07-03 |
| Technical Level | General |
| Products | Security Management Server, SmartConsole, Multi-Domain Security Management Server |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS), R82, R81.20, R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82 |

## Solution

### Introduction

The `internal_sendmail` is an internal Check Point command (built-in into FWD daemon) that directs the Check Point Alerts Daemon on the Security Management Server / Domain Management Server to send an e-mail, using the specified arguments.

It does not require a mail server or mail client to be installed on the Security Management Server / Multi-Domain Security Management Server.

**Notes:**

* The FWD daemon on the Security Management Server / Domain Management Server will send an e-mail to the defined SMTP Server to the TCP port 25.

* When choosing logging actions in rules, or other Security Gateway logging properties, set the action to correspond to the alert you defined in 'Global Properties' \> 'Log and Alert' \> on the 'Alerts' page.

<br />

### Known Limitations

* Alert emails do not support SSL/TLS.

* Alert emails do not support authentication.

  You must configure the applicable SMTP server with the options "Mail Relay" and "No Authentication".

<br />

### Procedure

**IMPORTANT: This procedure is not supported in Smart-1 Cloud and Harmony Endpoint (see [sk183598](https://support.checkpoint.com/results/sk/sk183598)).
For these products, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get assistance.**   

1. In SmartConsole, open **Global Properties \> expand Log and Alert \> click Alerts.**

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk25941/alertR82202501091616211.png)
2. Select the checkbox "**Run mail alert script**" and use this syntax:

   `internal_sendmail -s "SUBJECT" -t IP_ADDRESS_of_SMTP_SERVER -f SENDER_E-MAIL@DOMAIN RECIPIENT1_E-MAIL@DOMAIN RECIPIENT2_E-MAIL@DOMAIN ...`
   **Note:** The e-mail subject must always be enclosed within quotation marks. Multiple recipients must be separated by a space character.

   Example syntax with a sender email:

   `internal_sendmail -s "MySubject" -t 192.168.20.30 -f sender@example.com recepient1@example.com recepient2@example.com`

   Example syntax without a sender email:

   `internal_sendmail -s "MySubject" -t 192.168.20.30 recepient1@example.com recepient2@example.com`
3. **Optional:** Select the checkbox "**Send mail alert to SmartView Monitor**" - when a mail alert is issued, the same alert is also sent to SmartView Monitor.

4. Click **OK** to close the Global Properties window.

5. In the Access Control Policy, define a rule that would generate an alert - in the **Track** column, select **Mail**.

6. Install the Access Control Policy.

Sample log entry in the body of an alert e-mail:
> `27Jul2011 12:37:06 drop MyGW >eth2 useralert rule: 5; rule_uid: {D80B94DC-N325-4866-B67E-99NAZ5F41160}; SmartDefense profile: No Protection; ICMP: Echo Request; src: NS_192.168.30.44; dst: NS_LabSRVa; proto: icmp; ICMP Type: 8; ICMP Code: 0; product: VPN-1 & FireWall-1;`

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
