MAL — Email & Threat Protection
Email authentication and malware protections. 31 controls in total — 30 automatic, 1 attested.
How to read
Result: ✅ Pass · ⚠️ Warning · ❌ Fail · N/A Not evaluated. Status: Auto = Controlio measures it app-only · Attested = the customer marks it. Lv: L1 basic, L2 advanced.
| Control | What it checks | Result criteria | Status |
|---|---|---|---|
MAL-01 SPF record (all domains) L1 | Checks whether your email is protected against spoofed sending in your name, across all domains. | ✅ Valid on all domains · ❌ Any missing | Auto N/A if no data |
MAL-02 DMARC record (all domains) L1 | Checks whether spoofed email is blocked by completing SPF/DKIM validation, across all domains. | ✅ Valid on all domains · ❌ Any missing | Auto N/A if no data |
MAL-03 Automatic email forwarding block L1 | Checks whether incoming email is auto-forwarded outside the organization. It prevents data leakage. | ✅ Forwarding off · ⚠️ On up to 5 mailboxes, no rule, auto-forward off · ❌ More than that | Auto N/A if no data |
MAL-04 Legacy SMTP authentication disabled L1 | Checks the open door that legacy email protocols leave to brute-force and spam attacks. | ✅ Off for everyone · ⚠️ On for up to 5 users · ❌ On for more than 5 users | Auto N/A if no data |
MAL-07 Meeting lobby (organization only) L1 | Checks whether outside people can join meetings directly without passing through the lobby. | ✅ Organization only can join · ❌ Outsiders can join too | Auto N/A if no data |
MAL-09 Outbound email spam filter L1 | Checks the filter that stops a compromised account from sending spam outside. | ✅ Configured · ❌ Not configured | Auto N/A if no data |
MAL-10 Safe Attachments policy L1 | Checks whether malicious email attachments are scanned and blocked. | ✅ Enabled · ❌ Disabled | Auto Requires Microsoft 365 E3; N/A without Global Reader or data |
MAL-11 Safe Links policy L1 | Checks whether clicks on malicious links in email are blocked. | ✅ Enabled · ❌ Disabled | Auto Requires Microsoft 365 E3; N/A without Global Reader or data |
MAL-12 DKIM signing (all domains) L1 | Checks the digital signature against email forgery across all domains. | ✅ Configured on all domains · ❌ Any missing | Auto N/A if no data |
MAL-13 Impersonation protection L1 | Checks the protection against phishing attacks that impersonate senior executives. | ✅ Enabled · ❌ Disabled | Auto Requires Defender for Office 365 P2; N/A without Global Reader or data |
MAL-15 Modern authentication (Exchange) L1 | Checks the modern authentication that stops legacy auth from bypassing multi-step verification. | ✅ Enabled · ❌ Disabled | Auto N/A if no data |
MAL-16 Mailbox audit logging L1 | Checks whether mailbox access is logged. It makes breach detection possible. | ✅ On · ❌ Off | Auto N/A if no data |
MAL-17 Dangerous file extension filter L1 | Blocks harmful file extensions from arriving by email and being run by mistake. It lowers ransomware risk. | ✅ Enabled · ❌ Disabled | Auto N/A if no data |
MAL-18 Safe Attachments (unknown threat analysis) L2 | Checks whether unknown malware is analyzed in an isolated environment. | ✅ Enabled · ❌ Disabled | Auto Requires Defender for Office 365 P1; N/A without Global Reader or data |
MAL-19 Safe Attachments (SharePoint/OneDrive/Teams) L2 | Checks whether malicious files shared in SharePoint, OneDrive and Teams are scanned. | ✅ Enabled · ❌ Disabled | Auto Requires Defender for Office 365 P1; N/A without Global Reader or data |
MAL-20 Outbound spam admin notification L1 | Checks whether the admin is alerted if a compromised account starts sending spam outside. | ✅ Notification on · ❌ Off | Auto N/A if no data |
MAL-21 Extended file extension filter L2 | Checks whether rare dangerous extensions beyond the default list are also blocked. | ✅ Extended list applied · ❌ Default only / incomplete | Auto N/A if no data |
MAL-22 No IP allow list in the connection filter L1 | Stops IPs on an allow list from bypassing spam and phishing checks. | ✅ Allow list empty · ❌ IP allow list defined | Auto N/A if no data |
MAL-23 Connection filter safe list disabled L1 | Stops an unmanaged whitelist from bypassing the security scan. | ✅ Off · ❌ On | Auto N/A if no data |
MAL-24 No allowed sender domain list on inbound email L1 | Stops allowed sender domains from bypassing spam and phishing checks. | ✅ No allowed domain · ❌ Allowed domain defined | Auto N/A if no data |
MAL-25 Outbound email message limits L1 | Checks the limits that cap bulk spam sending from a compromised account. | ✅ Limits configured · ❌ Not configured | Auto N/A if no data |
MAL-26 Break-glass account monitoring L1 | Checks whether use of emergency admin accounts is monitored. | Attested Customer attestation (not measured automatically) | |
MAL-27 Priority account protection L1 | Checks the protection against targeted phishing (whaling) aimed at senior executives. | Auto Requires Defender for Office 365 P2; reviewed manually (not measured automatically) | |
MAL-28 Strict protection profile for priority accounts L1 | Checks whether Microsoft's strictest security profile is applied to priority accounts. | ✅ Strict protection applied · ❌ Not applied | Auto Requires Defender for Office 365 P2; N/A without Global Reader or data |
MAL-30 Automatic threat purge for Teams (ZAP) L1 | Checks whether links later found malicious in Teams messages are removed automatically. | ✅ Enabled · ❌ Disabled | Auto Requires Defender for Office 365 P2; N/A without Global Reader or data |
MAL-31 Mailbox audit bypass disabled L1 | Checks that no mailbox bypasses the audit log. | ✅ No mailbox bypasses auditing · ❌ A mailbox has bypass on | Auto N/A if no data |
MAL-32 Transport rules add no domain whitelist L1 | Checks that transport rules do not bypass the spam filter for specific domains. | ✅ No filter-bypassing rule · ❌ A filter-bypassing rule exists | Auto N/A if no data |
MAL-33 External sender tagging L1 | Checks whether email from outside is visually tagged. It makes spoofed email easier to spot. | ✅ Tagging on · ❌ Off | Auto N/A if no data |
MAL-34 MailTips warnings (end users) L1 | Checks whether critical warnings, such as an external recipient or a large distribution group, are shown to the user. | ✅ On · ❌ Off | Auto N/A if no data |
MAL-35 Restricting extra cloud storage in Outlook on the web L2 | Checks whether third-party cloud storage links (Dropbox, Google Drive and the like) are restricted in Outlook on the web. | ✅ Restricted · ❌ Left open | Auto N/A if no data |
MAL-36 Direct Send submissions rejected L2 | Stops mail sent by connecting directly from outside and appearing to come from inside. | ✅ Rejected · ❌ Allowed | Auto N/A if no data |