Check: DTOO224 - Outlook
Microsoft Outlook 2007:
DTOO224 - Outlook
(in versions v4 r16 through v4 r15)
Title
Disable the feature of adding recipients of sent eMail to the 'save sender's list. (Cat II impact)
Discussion
Sometimes users will send e-mail messages to request that they be taken off a mailing list. If the e-mail recipient is then automatically added to the Safe Senders List, future e mail messages from that address will no longer be sent to the users Junk E-mail folder, even if it would otherwise be considered junk. By default, recipients of outgoing messages are not added automatically to individual users' Safe Senders Lists. However, users can change this configuration in the Outlook 2007 user interface.
Check Content
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Junk E-mail “Add e-mail recipients to users' Safe Senders Lists” will be set to “Disabled”. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail Criteria: If the value JunkMailTrustOutgoingRecipients is REG_DWORD = 0, this is not a finding.
Fix Text
The policy value for User Configuration -> Administrative Templates -> Microsoft Office Outlook 2007 -> Tools \ Options -> Preferences -> Junk E-mail “Add e-mail recipients to users' Safe Senders Lists” will be set to “Disabled”.
Additional Identifiers
Rule ID: SV-18655r1_rule
Vulnerability ID: V-17558
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |