1.4 Ensure 'Blank sender field' is configured

Information

When the Sender Filter Agent takes on messages from blocked senders or domains, the Action parameter is what is used when deciding what to do with these messages.

Rationale:

Anonymous emails (messages with blank sender fields) cannot be replied to. Emails that are sent with blank sender fields could be trying to hide their true origin and allows them to avoid responses and possibly spam receivers of the message. It is less risky and more resource-efficient to filter these messages upon receipt rather than forwarding them to be evaluated and risking possible infection.

Impact:

Anonymous emails are automatically rejected

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-SenderFilterConfig -Action Reject -BlankSenderBlockingEnabled $true

Default Value:

Action Reject

BlankSenderBlockingEnabled False

See Also

https://workbench.cisecurity.org/benchmarks/12442

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-8a.

Plugin: Windows

Control ID: 91c703ba6f6d34e0e93add14436ddb85b06cb583d75712970a810105909e769a