2.2.4 Ensure 'Maximum send size: Connector level' is set to '25'

Information

This policy setting can limit the size of messages that are be sent by the user at the connector level. The message size includes the header, body, and any attachments for the email.

For internal message flow, Exchange Server uses the custom X-MS-Exchange-Organization-OriginalSize message header to record the original message size of the message as it enters the Exchange Server organization. Whenever the message is checked against the specified message size limits, the lower value of the current message size or the original message size header is used. The size of the message can change because of content conversion, encoding, and agent processing.

Rationale:

This setting somewhat limits the impact a malicious user or a computer with malware can have on the Exchange infrastructure by restricting the size of incoming messages.

Impact:

Users will not be able to send messages larger than the limit.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-SendConnector 'Connection to Contoso.com' -MaxMessageSize 25MB

OR

Perform the following actions via the GUI:

Launch the EAC (Exchange Administrative Center).

Go to 'Mail Flow' on the left and click on the 'Send Connectors' tab.

Double-click on the send connector to be modified.

Change the Maximum send message size (MB): to 25 and click Save.

Default Value:

10 MB (10,485,760 bytes)

See Also

https://workbench.cisecurity.org/benchmarks/12442

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5(1)

Plugin: Windows

Control ID: 9c9a0f317dff70008d9e8714d0a84978e54934766f508e0d43bd009c7b3c95be