Skip to main content
Version: 2.1.1-preview

ORCA.118.1 - Domains are not being allow listed in an unsafe manner in Anti-Spam Policies.

Overview

Emails coming from allow listed domains bypass several layers of protection within Exchange Online Protection. If domains are allow listed, they are open to being spoofed from malicious actors.

Remediation action

Remove allow listing on domains.

Test Metadata

FieldValue
Test IDORCA.118.1
SeverityHigh
SuiteORCA
CategoryEXO
PowerShell testTest-ORCA118_1
TagsEXO, ORCA, ORCA.118.1

Source

  • Pester test: tests/orca/Test-ORCA118_1.Tests.ps1
  • PowerShell source: powershell/public/orca/Test-ORCA118_1.ps1