2.2.8 Ensure 'External send connector authentication: DNS routing' is set to 'True'

Information

This policy setting determines if DNS is used to route outbound mail via the send connector.

Rationale:

In order to enable mutual Transport Layer Security (TLS) authentication for the domains serviced by this send connector, multiple parameters must be configured. Configuring these parameters enables the use of TLS instead of basic authentication where credentials are sent across the network in plaintext.

The following parameters are addressed in separate recommendations in this benchmark.

DomainSecureEnabled to $true

IgnoreStartTLS to $false

Impact:

The organization's servers will only be able to send e-mail to remote servers that are located through DNS routing. This is the default value.

Warning: If a SmartHosts parameter is specified, the DNSRoutingEnabled parameter must be set to $false.

Solution

To implement the recommended state, execute the following PowerShell cmdlet:

Set-SendConnector 'Connection to Contoso.com' -DNSRoutingEnabled $true

Default Value:

True

See Also

https://workbench.cisecurity.org/benchmarks/12442

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-11

Plugin: Windows

Control ID: 29ddbcd0e6d0ac42501cadd6149cccb8aa79210bd6ae7821c1fcc8f58e9a4bfe