Organization should implement email security protections
Medium
Azure
General
manual-cis-email-protection
How to fix it
Implement email security controls including SPF, DKIM, DMARC, and anti-phishing protections. Enable attachment sandboxing and URL filtering where available.
How to verify
- Verify SPF, DKIM, and DMARC records exist for primary domains
- Confirm email filtering/sandboxing is enabled
- Verify DMARC policy is set to quarantine or reject
Compliance frameworks
Is your environment compliant with this rule?
CGPulse checks it — and 621 others — against your Azure and AWS accounts with read-only access.
Related Azure rules
- Action Group should be enabled
- Activity Log Alert should be enabled
- AKS cluster logs should be sent to Log Analytics
- AKS cluster must enable RBAC
- AKS cluster must enable RBAC
- AKS cluster should be a private cluster
- AKS cluster should disable local accounts
- AKS cluster should enable Azure RBAC for Kubernetes