Skip to main content
Version: 2.1.1-preview

ORCA Exchange Online Tests

These tests validate Exchange Online security configuration checks from ORCA.

Tests

Test IDTitleSeverityCategory
ORCA.100Bulk Complaint Level threshold is between 4 and 6.MediumEXO
ORCA.101Bulk is marked as spam.MediumEXO
ORCA.102Advanced Spam filter options are turned off.MediumEXO
ORCA.103Outbound spam filter policy settings configured.MediumEXO
ORCA.104High Confidence Phish action set to Quarantine message.HighEXO
ORCA.105Safe Links Synchronous URL detonation is enabled.MediumEXO
ORCA.106Quarantine retention period is 30 days.MediumEXO
ORCA.107End-user spam notification is enabled.LowEXO
ORCA.108DKIM signing is set up for all your custom domains.MediumEXO
ORCA.108.1DNS Records have been set up to support DKIM.MediumEXO
ORCA.109Senders are not being allow listed in an unsafe manner.MediumEXO
ORCA.110Internal Sender notifications are disabled.MediumEXO
ORCA.111Anti-phishing policy exists and EnableUnauthenticatedSender is true.HighEXO
ORCA.112Anti-spoofing protection action is configured to Move message to the recipients' Junk Email folders in Anti-phishing policy.MediumEXO
ORCA.113AllowClickThrough is disabled in Safe Links policies.MediumEXO
ORCA.114No IP Allow Lists have been configured.HighEXO
ORCA.115Mailbox intelligence based impersonation protection is enabled in anti-phishing policies.MediumEXO
ORCA.116Mailbox intelligence based impersonation protection action set to move message to junk mail folder.MediumEXO
ORCA.118.1Domains are not being allow listed in an unsafe manner in Anti-Spam Policies.HighEXO
ORCA.118.2Domains are not being allow listed in an unsafe manner in Transport Rules.HighEXO
ORCA.118.3Your own domains are not being allow listed in an unsafe manner in Anti-Spam Policies.MediumEXO
ORCA.118.4Your own domains are not being allow listed in an unsafe manner in Transport Rules.MediumEXO
ORCA.119Similar Domains Safety Tips is enabled.InfoEXO
ORCA.120.1Zero Hour Autopurge Enabled for Phish.MediumEXO
ORCA.120.2Zero Hour Autopurge Enabled for Malware.MediumEXO
ORCA.120.3Zero Hour Autopurge Enabled for Spam.MediumEXO
ORCA.121Supported filter policy action used.LowEXO
ORCA.123Unusual Characters Safety Tips is enabled.InfoEXO
ORCA.124Safe attachments unknown malware response set to block messages.HighEXO
ORCA.139Spam action set to move message to junk mail folder or quarantine.LowEXO
ORCA.140High Confidence Spam action set to Quarantine message.HighEXO
ORCA.141Bulk action set to Move message to Junk Email Folder.MediumEXO
ORCA.142Phish action set to Quarantine message.MediumEXO
ORCA.143Safety Tips are enabled.InfoEXO
ORCA.156Safe Links Policies are tracking when user clicks on safe links.MediumEXO
ORCA.158Safe Attachments is enabled for SharePoint and Teams.MediumEXO
ORCA.179Safe Links is enabled intra-organization.MediumEXO
ORCA.180Anti-phishing policy exists and EnableSpoofIntelligence is true.MediumEXO
ORCA.189Safe Attachments is not bypassed.MediumEXO
ORCA.189.2Safe Links is not bypassed.HighEXO
ORCA.205Common attachment type filter is enabled.MediumEXO
ORCA.220Advanced Phish filter Threshold level is adequate.MediumEXO
ORCA.221Mailbox intelligence is enabled in anti-phishing policies.MediumEXO
ORCA.222Domain Impersonation action is set to move to Quarantine.MediumEXO
ORCA.223User impersonation action is set to move to Quarantine.HighEXO
ORCA.224Similar Users Safety Tips is enabled.InfoEXO
ORCA.225Safe Documents is enabled for Office clients.MediumEXO
ORCA.226Each domain has a Safe Link policy applied to it.MediumEXO
ORCA.227Each domain has a Safe Attachments policy applied to it.MediumEXO
ORCA.228No trusted senders in Anti-phishing policy.HighEXO
ORCA.229No trusted domains in Anti-phishing policy.MediumEXO
ORCA.230Each domain has a Anti-phishing policy applied to it, or the default policy is being used.MediumEXO
ORCA.231Each domain has a anti-spam policy applied to it, or the default policy is being used.MediumEXO
ORCA.232Each domain has a malware filter policy applied to it, or the default policy is being used.HighEXO
ORCA.233Domains are pointed directly at EOP or enhanced filtering is used.MediumEXO
ORCA.233.1Domains are pointed directly at EOP or enhanced filtering is configured on all default connectors.MediumEXO
ORCA.234Click through is disabled for Safe Documents.MediumEXO
ORCA.235SPF records is set up for all your custom domains.MediumEXO
ORCA.236Safe Links is enabled for emails.MediumEXO
ORCA.237Safe Links is enabled for teams messages.MediumEXO
ORCA.238Safe Links is enabled for office documents.MediumEXO
ORCA.239No exclusions for the built-in protection policies.HighEXO
ORCA.240Outlook is configured to display external tags for external emails.MediumEXO
ORCA.241Anti-phishing policy exists and EnableFirstContactSafetyTips is true.MediumEXO
ORCA.242Important protection alerts responsible for AIR activities are enabled.HighEXO
ORCA.243Authenticated Receive Chain is set up for domains not pointing to EOP/MDO, or all domains point to EOP/MDO.MediumEXO
ORCA.244Policies are configured to honor sending domains DMARC.MediumEXO