4.8 Ensure that SPF records are published for all Exchange Domains

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

For each domain that is configured in Exchange, a corresponding Sender Policy Framework (SPF) record should be created.

Rationale:

SPF records allow Exchange Online Protection and other mail systems know where messages from your domains are allowed to originate. This information can be used to by that system to determine how to treat the message based on if it is being spoofed or is valid.

Impact:

There should be minimal impact of setting up SPF records however, organizations should ensure proper SPF record setup as email could be flagged as spam if SPF is not setup appropriately.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To setup SPF records for Exchange Online accepted domains, perform the following steps:

If all email in your domain is sent from and received by Exchange Online, add the following TXT record for each Accepted Domain:

v=spf1 include:spf.protection.outlook.com -all

If there are other systems that send email in the environment, refer to this article for the proper SPF configuration: https://docs.microsoft.com/en-us/office365/SecurityCompliance/set-up-spf-in-office-365-to-help-prevent-spoofing.

See Also

https://workbench.cisecurity.org/files/4073