CIS Controls CIS-9.5

To lower the chance of spoofed or modified emails from valid domains, implement DMARC policy and verification, starting with implementing the Sender Policy Framework (SPF) and the DomainKeys Identified Mail (DKIM) standards.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CIS-9.5 Implement DMARC mitigates T1667 Email Bombing
Comments
ATT&CK explicitly discusses DMARC, SPF, and DKIM on the Email bombing technique page, including how enabling these mechanisms within an organization (through policies such as DMARC) may enable recipients (intra-org and cross domain) to perform similar message filtering and validation to mitigate this technique.
References
    CIS-9.5 Implement DMARC mitigates T1566.002 Spearphishing Link
    Comments
    DMARC may materially reduces phishing campaigns that rely on spoofed or unauthenticated sender domains. DMARC may reduce link-led spearphishing at the sender-authentication and mail acceptance time. It does not inspect the attachment itself though.
    References
      CIS-9.5 Implement DMARC mitigates T1566.001 Spearphishing Attachment
      Comments
      DMARC may materially reduces phishing campaigns that rely on spoofed or unauthenticated sender domains. DMARC may reduce attachment-led spearphishing when the campaign depends on spoofed sender trust and domain authentication failure. It does not inspect the attachment itself though.
      References
        CIS-9.5 Implement DMARC mitigates T1566 Phishing
        Comments
        DMARC may materially reduces phishing campaigns that rely on spoofed or unauthenticated sender domains.
        References
          CIS-9.5 Implement DMARC mitigates T1684 Social Engineering
          Comments
          Social engineering is broadly defined as influencing users into actions while minimizing technical indicators, DMARC can be a meaningful control against the email-spoofing branch of this broader technique.
          References
            CIS-9.5 Implement DMARC mitigates T1684.001 Impersonation
            Comments
            DMARC may not stop all impersonation, but it reduces a major subset where trust is created through control of the visible sender identity and aligned sending domain.
            References
              CIS-9.5 Implement DMARC mitigates T1684.002 Email Spoofing
              Comments
              ATT&CK explicitly discusses DMARC, SPF, and DKIM on the Email Spoofing technique page, including how weak or absent DMARC leaves spoofed messages deliverable and how DMARC-enabled filtering mitigates the behavior
              References