EX13-EG-000215 - Exchange messages with malformed From address must be rejected.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Sender Identification (SID) is an email antispam sanitization process. Sender ID uses DNS MX record lookups to verify the Simple Mail Transfer Protocol (SMTP) sending server is authorized to send email for the originating domain.

Failure to implement Sender ID risks that spam could be admitted into the email domain that originates from rogue servers. Most spam content originates from domains where the IP address has been spoofed prior to sending, thereby avoiding detection. For example, messages with malformed or incorrect 'purported responsible sender' data in the message header could be (best case) created by using RFI noncompliant software but is more likely to be spam.

Solution

Open the Exchange Management Shell and enter the following command:

Set-SenderIdConfig -SpoofedDomainAction Reject

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Exchange_2013_Y21M12_STIG.zip

Item Details

References: CAT|II, CCI|CCI-001308, Rule-ID|SV-84503r1_rule, STIG-ID|EX13-EG-000215, Vuln-ID|V-69881

Plugin: Windows

Control ID: 95512a22530d9100c18dafbdd366b08dede6b7b48aecbce00f81f4daca28aa88