2.4.5 Ensure 'SMTP automated banner response' is set to '220 SMTP Server Ready'

Information

This policy setting specifies a custom SMTP 220 banner which is displayed to remote messaging servers that connect to the receive connector.

Rationale:

The default value could disclose information that can be used by a third-party to determine operating system and product release levels on the target server. This information can then be used for an attack.

Impact:

N/A

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-ReceiveConnector -Identity <'IdentityName'> -Banner '220 SMTP Server Ready'

Default Value:

220 <ServerName> Microsoft ESMTP MAIL service ready at <RegionalDay-Date-24HourTimeFormat><RegionalTimeZoneOffset>

See Also

https://workbench.cisecurity.org/benchmarks/12442

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 96d0beb9810b5f6accbc97449cd4b7eb2536f4456014fdd1895f5188013b43a9