Skip to main content

MAL — Email & Threat Protection

Email authentication and malware protections. 31 controls in total — 30 automatic, 1 attested.

How to read

Result: ✅ Pass · ⚠️ Warning · ❌ Fail · N/A Not evaluated. Status: Auto = Controlio measures it app-only · Attested = the customer marks it. Lv: L1 basic, L2 advanced.

ControlWhat it checksResult criteriaStatus
MAL-01 SPF record (all domains)
L1
Checks whether your email is protected against spoofed sending in your name, across all domains.✅ Valid on all domains · ❌ Any missingAuto
N/A if no data
MAL-02 DMARC record (all domains)
L1
Checks whether spoofed email is blocked by completing SPF/DKIM validation, across all domains.✅ Valid on all domains · ❌ Any missingAuto
N/A if no data
MAL-03 Automatic email forwarding block
L1
Checks whether incoming email is auto-forwarded outside the organization. It prevents data leakage.✅ Forwarding off · ⚠️ On up to 5 mailboxes, no rule, auto-forward off · ❌ More than thatAuto
N/A if no data
MAL-04 Legacy SMTP authentication disabled
L1
Checks the open door that legacy email protocols leave to brute-force and spam attacks.✅ Off for everyone · ⚠️ On for up to 5 users · ❌ On for more than 5 usersAuto
N/A if no data
MAL-07 Meeting lobby (organization only)
L1
Checks whether outside people can join meetings directly without passing through the lobby.✅ Organization only can join · ❌ Outsiders can join tooAuto
N/A if no data
MAL-09 Outbound email spam filter
L1
Checks the filter that stops a compromised account from sending spam outside.✅ Configured · ❌ Not configuredAuto
N/A if no data
MAL-10 Safe Attachments policy
L1
Checks whether malicious email attachments are scanned and blocked.✅ Enabled · ❌ DisabledAuto
Requires Microsoft 365 E3; N/A without Global Reader or data
MAL-11 Safe Links policy
L1
Checks whether clicks on malicious links in email are blocked.✅ Enabled · ❌ DisabledAuto
Requires Microsoft 365 E3; N/A without Global Reader or data
MAL-12 DKIM signing (all domains)
L1
Checks the digital signature against email forgery across all domains.✅ Configured on all domains · ❌ Any missingAuto
N/A if no data
MAL-13 Impersonation protection
L1
Checks the protection against phishing attacks that impersonate senior executives.✅ Enabled · ❌ DisabledAuto
Requires Defender for Office 365 P2; N/A without Global Reader or data
MAL-15 Modern authentication (Exchange)
L1
Checks the modern authentication that stops legacy auth from bypassing multi-step verification.✅ Enabled · ❌ DisabledAuto
N/A if no data
MAL-16 Mailbox audit logging
L1
Checks whether mailbox access is logged. It makes breach detection possible.✅ On · ❌ OffAuto
N/A if no data
MAL-17 Dangerous file extension filter
L1
Blocks harmful file extensions from arriving by email and being run by mistake. It lowers ransomware risk.✅ Enabled · ❌ DisabledAuto
N/A if no data
MAL-18 Safe Attachments (unknown threat analysis)
L2
Checks whether unknown malware is analyzed in an isolated environment.✅ Enabled · ❌ DisabledAuto
Requires Defender for Office 365 P1; N/A without Global Reader or data
MAL-19 Safe Attachments (SharePoint/OneDrive/Teams)
L2
Checks whether malicious files shared in SharePoint, OneDrive and Teams are scanned.✅ Enabled · ❌ DisabledAuto
Requires Defender for Office 365 P1; N/A without Global Reader or data
MAL-20 Outbound spam admin notification
L1
Checks whether the admin is alerted if a compromised account starts sending spam outside.✅ Notification on · ❌ OffAuto
N/A if no data
MAL-21 Extended file extension filter
L2
Checks whether rare dangerous extensions beyond the default list are also blocked.✅ Extended list applied · ❌ Default only / incompleteAuto
N/A if no data
MAL-22 No IP allow list in the connection filter
L1
Stops IPs on an allow list from bypassing spam and phishing checks.✅ Allow list empty · ❌ IP allow list definedAuto
N/A if no data
MAL-23 Connection filter safe list disabled
L1
Stops an unmanaged whitelist from bypassing the security scan.✅ Off · ❌ OnAuto
N/A if no data
MAL-24 No allowed sender domain list on inbound email
L1
Stops allowed sender domains from bypassing spam and phishing checks.✅ No allowed domain · ❌ Allowed domain definedAuto
N/A if no data
MAL-25 Outbound email message limits
L1
Checks the limits that cap bulk spam sending from a compromised account.✅ Limits configured · ❌ Not configuredAuto
N/A if no data
MAL-26 Break-glass account monitoring
L1
Checks whether use of emergency admin accounts is monitored.Attested
Customer attestation (not measured automatically)
MAL-27 Priority account protection
L1
Checks the protection against targeted phishing (whaling) aimed at senior executives.Auto
Requires Defender for Office 365 P2; reviewed manually (not measured automatically)
MAL-28 Strict protection profile for priority accounts
L1
Checks whether Microsoft's strictest security profile is applied to priority accounts.✅ Strict protection applied · ❌ Not appliedAuto
Requires Defender for Office 365 P2; N/A without Global Reader or data
MAL-30 Automatic threat purge for Teams (ZAP)
L1
Checks whether links later found malicious in Teams messages are removed automatically.✅ Enabled · ❌ DisabledAuto
Requires Defender for Office 365 P2; N/A without Global Reader or data
MAL-31 Mailbox audit bypass disabled
L1
Checks that no mailbox bypasses the audit log.✅ No mailbox bypasses auditing · ❌ A mailbox has bypass onAuto
N/A if no data
MAL-32 Transport rules add no domain whitelist
L1
Checks that transport rules do not bypass the spam filter for specific domains.✅ No filter-bypassing rule · ❌ A filter-bypassing rule existsAuto
N/A if no data
MAL-33 External sender tagging
L1
Checks whether email from outside is visually tagged. It makes spoofed email easier to spot.✅ Tagging on · ❌ OffAuto
N/A if no data
MAL-34 MailTips warnings (end users)
L1
Checks whether critical warnings, such as an external recipient or a large distribution group, are shown to the user.✅ On · ❌ OffAuto
N/A if no data
MAL-35 Restricting extra cloud storage in Outlook on the web
L2
Checks whether third-party cloud storage links (Dropbox, Google Drive and the like) are restricted in Outlook on the web.✅ Restricted · ❌ Left openAuto
N/A if no data
MAL-36 Direct Send submissions rejected
L2
Stops mail sent by connecting directly from outside and appearing to come from inside.✅ Rejected · ❌ AllowedAuto
N/A if no data