2.1.10 Ensure DMARC Records for all Exchange Online domains are published

Information

DMARC, or Domain-based Message Authentication, Reporting, and Conformance, assists recipient mail systems in determining the appropriate action to take when messages from a domain fail to meet SPF or DKIM authentication criteria.

Rationale:

DMARC strengthens the trustworthiness of messages sent from an organization's domain to destination email systems. By integrating DMARC with SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail), organizations can significantly enhance their defenses against email spoofing and phishing attempts.

Impact:

There should be no impact of setting up DMARC however, organizations should ensure appropriate setup to ensure continuous mail-flow.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To add DMARC records, use the following steps:

For each Exchange Online Accepted Domain, add the following record to DNS:

Record: _dmarc.domain1.com
Type: TXT
Value: v=DMARC1; p=none;

This will create a basic DMARC policy that audits compliance

See Also

https://workbench.cisecurity.org/benchmarks/12934

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CSCv7|7.8

Plugin: microsoft_azure

Control ID: 999120f277579fd1820f41daedc42f4ee4d2a8d29e83ab2374369607d8fa2a7b