M365EXO-019: DMARC aggregate report contact configured (MS.EXO.4.3)
- Platform
- Entra ID / M365
- Category
- Advanced Threat Protection
- Severity
- Medium
- Zero Trust pillar
- Applications & Workloads (weight 1)
- Golden fixtures
- 3
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- baseline
What it checks
SCuBA MS.EXO.4.3 requires that the DMARC aggregate report contact (RUA) include reports@dmarc.cyber.dhs.gov for federal executive-branch agencies, and more generally that an aggregate report destination be configured. Aggregate reports give domain owners visibility into who is sending mail as their domain, which is essential for safely advancing to p=reject and detecting spoofing campaigns.
Recommended value
DMARC record includes an rua= aggregate report destination; federal executive-branch agencies include reports@dmarc.cyber.dhs.gov
Remediation
Add an rua= tag to each DMARC record pointing to a monitored mailbox or report-processing service so aggregate reports are collected and reviewed. Federal executive-branch departments and agencies must include reports@dmarc.cyber.dhs.gov in the RUA field per BOD 18-01. Ensure the receiving mailbox or service is actively monitored so spoofing trends are acted upon.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| clean | PASS |
| known-bad | FAIL |
| throttled | Not Assessed |
Framework mappings
- CISA SCuBA
- MS.EXO.4.3v1, MS.EXO.4.4v1
- NIST SP 800-53
- SI-8, AU-6
- MITRE ATT&CK
- T1566.001