Hi Pan,
Looks like you have the perfect flow above so should realitically work, the only thing I can think of that would be preventing the block rule is conditions in your rule/response not matching, so it will generate an incident saying 'FYI' but no block as didn't meet criteria.
The most common one for this is for example if your rule states find SMTP traffic to this email address - Severity 'medium', if your response rule says 'Block action to email address - Severity 'high'
The block response will never actually happen, as the response rule says it might be classed as high severity (typically used for multiple rules) and your rule is only triggering medium incidents,
I hope this helps,
If not, let me know and I'll try help further but everything appears to be ok set up wise,