Description:

This check verifies that DKIM is enabled for each domain.

Why:

This check verifies that DKIM is enabled for each domain. DKIM is one of the trio of Authentication methods (SPF, DKIM and DMARC) that help prevent attackers from sending messages that look like they come from your domain. By enabling DKIM with Office 365, messages that are sent from Exchange Online will be cryptographically signed. This will allow the receiving email system to validate that the messages were generated by a server that the organization authorized and not being spoofed. There should be no impact of setting up DKIM however, organizations should ensure appropriate setup to ensure continuous mail-flow.

Status detail shown in Augmentt: You have N out of M settings applied.

This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.

Scoring: Scored proportionally — the check contributes according to how many of the in-scope items are compliant, so a partially compliant tenant earns partial credit.

Category: Exchange

Microsoft Licensing: Works with Basic licensing

Remediation in Augmentt: Configure directly in Augmentt (Configure tab)

Compliance Frameworks:

  • CISA SCuBA — MS.EXO.3.1

  • NIST CSF 2.0 — PR.PS-01

  • CIS Microsoft 365 Benchmark v6 (Level 1) — 2.1.9

  • CIS Microsoft 365 Benchmark v7 (Level 1) — 2.1.9

  • HIPAA Security Rule — 164.312(e)(2)(i)

  • CMMC Level 1 — SC.L1-b.1.x

  • CMMC Level 2 — SC.L2-3.13.15

Microsoft documentation:

IMPORTANT:

The DKIM security posture will validate DKIM records on domains. The presence of a CNAME record in the domain is a fundamental prerequisite for DKIM. Consequently, since this posture is centered on DKIM, it will only validate those domains that fulfill the basic requirements of DKIM.