M365EXO-019: DMARC aggregate report contact configured (MS.EXO.4.3)

Platform
Entra ID / M365
Category
Advanced Threat Protection
Severity
Medium
Zero Trust pillar
Applications & Workloads (weight 1)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

SCuBA MS.EXO.4.3 requires that the DMARC aggregate report contact (RUA) include reports@dmarc.cyber.dhs.gov for federal executive-branch agencies, and more generally that an aggregate report destination be configured. Aggregate reports give domain owners visibility into who is sending mail as their domain, which is essential for safely advancing to p=reject and detecting spoofing campaigns.

Recommended value

DMARC record includes an rua= aggregate report destination; federal executive-branch agencies include reports@dmarc.cyber.dhs.gov

Remediation

Add an rua= tag to each DMARC record pointing to a monitored mailbox or report-processing service so aggregate reports are collected and reviewed. Federal executive-branch departments and agencies must include reports@dmarc.cyber.dhs.gov in the RUA field per BOD 18-01. Ensure the receiving mailbox or service is actively monitored so spoofing trends are acted upon.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for M365EXO-019
ScenarioExpected verdict
cleanPASS
known-badFAIL
throttledNot Assessed

Framework mappings

CISA SCuBA
MS.EXO.4.3v1, MS.EXO.4.4v1
NIST SP 800-53
SI-8, AU-6
MITRE ATT&CK
T1566.001