To lower the chance of spoofed or modified emails from valid domains, implement DMARC policy and verification, starting with implementing the Sender Policy Framework (SPF) and the DomainKeys Identified Mail (DKIM) standards.
| Capability ID | Capability Description | Mapping Type | ATT&CK ID | ATT&CK Name | Notes |
|---|---|---|---|---|---|
| CIS-9.5 | Implement DMARC | mitigates | T1667 | Email Bombing |
Comments
ATT&CK explicitly discusses DMARC, SPF, and DKIM on the Email bombing technique page, including how enabling these mechanisms within an organization (through policies such as DMARC) may enable recipients (intra-org and cross domain) to perform similar message filtering and validation to mitigate this technique.
References
|
| CIS-9.5 | Implement DMARC | mitigates | T1566.002 | Spearphishing Link |
Comments
DMARC may materially reduces phishing campaigns that rely on spoofed or unauthenticated sender domains. DMARC may reduce link-led spearphishing at the sender-authentication and mail acceptance time. It does not inspect the attachment itself though.
References
|
| CIS-9.5 | Implement DMARC | mitigates | T1566.001 | Spearphishing Attachment |
Comments
DMARC may materially reduces phishing campaigns that rely on spoofed or unauthenticated sender domains. DMARC may reduce attachment-led spearphishing when the campaign depends on spoofed sender trust and domain authentication failure. It does not inspect the attachment itself though.
References
|
| CIS-9.5 | Implement DMARC | mitigates | T1566 | Phishing |
Comments
DMARC may materially reduces phishing campaigns that rely on spoofed or unauthenticated sender domains.
References
|
| CIS-9.5 | Implement DMARC | mitigates | T1684 | Social Engineering |
Comments
Social engineering is broadly defined as influencing users into actions while minimizing technical indicators, DMARC can be a meaningful control against the email-spoofing branch of this broader technique.
References
|
| CIS-9.5 | Implement DMARC | mitigates | T1684.001 | Impersonation |
Comments
DMARC may not stop all impersonation, but it reduces a major subset where trust is created through control of the visible sender identity and aligned sending domain.
References
|
| CIS-9.5 | Implement DMARC | mitigates | T1684.002 | Email Spoofing |
Comments
ATT&CK explicitly discusses DMARC, SPF, and DKIM on the Email Spoofing technique page, including how weak or absent DMARC leaves spoofed messages deliverable and how DMARC-enabled filtering mitigates the behavior
References
|