5.1. Restrict Accepted Domains = Authoritative Domain

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Exchange should only route mail for which it is both the authoritative domain and the users/mailboxes are present in the organization. Allowing external mail routing on an Edge Transport role opens the Exchange server to both spam abuse and malicious activity.

Solution

Make sure 'Restrict Accepted Domains' is set to Authoritative Domain (default).

See Also

https://workbench.cisecurity.org/files/656