1.7 Ensure 'Nonexistent recipients' is set to 'True'

Information

This parameter is used to decide if messages whose recipient doesn't exist in the organization are blocked. When this parameter is set to $true, the Recipient Filter Agent blocks these messages.

Note: The Set-RecipientFilterConfig cmdlet must be enabled

Rationale:

Spam originators may use a technique that involves first creating fabricated names, and then monitors for rejected emails due to non-existent recipients. Emails with names who are not rejected are then used for future spam mailings. To deprive the spam originator of valuable information, it is recommended to receive all messages, then evaluate and dispose of them as deemed necessary.

Impact:

Some legitimate messages might be blocked.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-RecipientFilterConfig -RecipientValidationEnabled $true

Default Value:

False

See Also

https://workbench.cisecurity.org/benchmarks/12442

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-8(2)

Plugin: Windows

Control ID: c10da0042d1975297a891c17ac8816a4055234ece7390f1cc17805ccc3ce7bac