EMAIL-003: DMARC Policy Audit

Platform
Google Workspace
Category
Advanced Threat Protection
Severity
Critical
Zero Trust pillar
Applications & Workloads (weight 2)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Domain-based Message Authentication, Reporting and Conformance (DMARC) policy must be set to reject or quarantine for all domains. A DMARC policy of none provides no protection against spoofing

Recommended value

DMARC policy set to reject or quarantine for all domains

Remediation

Publish DMARC TXT record at _dmarc.<domain> with p=reject or p=quarantine. Start with p=none for monitoring, then escalate to quarantine and finally reject

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EMAIL-003
ScenarioExpected verdict
cleanPASS
known-badFAIL
throttledNot Assessed

Framework mappings

NIST SP 800-53
SI-8, SC-7
CIS Benchmark
2.3
CISA SCuBA
GWS.GMAIL.4.1v1, GWS.GMAIL.4.2v1
MITRE ATT&CK
T1566.001, T1566.002, T1036.005