Microsoft Exchange 2019 Edge Server STIG Version Comparison
Microsoft Exchange 2019 Edge Server Security Technical Implementation Guide
Comparison
There are 1 differences between versions v1 r1 (Jan. 17, 2024) (the "left" version) and v2 r2 (Jan. 30, 2025) (the "right" version).
Check EX19-ED-000133 was changed between these two versions. Green, underlined text was added, red, struck-out text was removed.
The regular view of the left check and right check may be easier to read.
Text Differences
Title
Exchange messages with a malformed From address must be rejected.
Check Content
If this server is in a SIPR Enclave, this requirement is Note: Not Applicable. Note: If third-party anti-spam product is being used, the anti-spam product must be configured to meet the requirement. Open the Exchange Management Shell and enter the following command: Get-SenderIdConfig | Select-Object -Property Name, Identity, SpoofedDomainAction If the value of "SpoofedDomainAction" is not set to "Reject", this is a finding.
Discussion
Sender Identification (SID) is an email anti-spam sanitization process. Sender ID uses DNS MX record lookups to verify the Simple Mail Transfer Protocol (SMTP) sending server is authorized to send email for the originating domain. Failure to implement Sender ID risks that spam could be admitted into the email domain that originates from rogue servers. Most spam content originates from domains where the IP address has been spoofed prior to sending, thereby avoiding detection. For example, messages with malformed or incorrect "purported responsible sender" data in the message header could be (best case) created by using RFI noncompliant software but is more likely to be spam.
Fix
Open the Exchange Management Shell and enter the following command: Set-SenderIdConfig -SpoofedDomainAction Reject