Skip to main content
Version: 2.1.0

ORCA.111 - Anti-phishing policy exists and EnableUnauthenticatedSender is true.

Overview

When the sender email address is spoofed, the message appears to originate from someone or somewhere other than the actual source. It is recommended to enable unauthenticated sender tagging in Office 365 Anti-phishing policies. The feature apply a '?' symbol in Outlook's sender card if the sender fails authentication checks.

Remediation action

Enable unauthenticated sender tagging in Anti-phishing policy.

Test Metadata

FieldValue
Test IDORCA.111
SeverityHigh
SuiteORCA
CategoryEXO
PowerShell testTest-ORCA111
TagsEXO, ORCA, ORCA.111

Source

  • Pester test: tests/orca/Test-ORCA111.Tests.ps1
  • PowerShell source: powershell/public/orca/Test-ORCA111.ps1