Skip to main content
Version: 2.1.0

ORCA.118.3 - Your own domains are not being allow listed in an unsafe manner in Anti-Spam Policies.

Overview

Emails coming from allow listed domains bypass several layers of protection within Exchange Online Protection. When allow listing your own domains, an attacker can spoof any account in your organisation that has this domain. This is a significant phishing attack vector.

Remediation action

Remove allow listing on domains belonging to your organisation.

Test Metadata

FieldValue
Test IDORCA.118.3
SeverityMedium
SuiteORCA
CategoryEXO
PowerShell testTest-ORCA118_3
TagsEXO, ORCA, ORCA.118.3

Source

  • Pester test: tests/orca/Test-ORCA118_3.Tests.ps1
  • PowerShell source: powershell/public/orca/Test-ORCA118_3.ps1