Description:

This check verifies that DKIM is enabled for each domain.

Why:

This check verifies that DKIM is enabled for each domain. DKIM is one of the trio of Authentication methods (SPF, DKIM and DMARC) that help prevent attackers from sending messages that look like they come from your domain. By enabling DKIM with Office 365, messages that are sent from Exchange Online will be cryptographically signed. This will allow the receiving email system to validate that the messages were generated by a server that the organization authorized and not being spoofed. There should be no impact of setting up DKIM however, organizations should ensure appropriate setup to ensure continuous mail-flow.

Status detail shown in Augmentt: You have N out of M settings applied.

This check reports a count rather than a simple pass/fail. It is Configured when every in-scope item is compliant, Partially Configured when some are, and Not Configured when none are.

Scoring: Scored proportionally — the check contributes according to how many of the in-scope items are compliant, so a partially compliant tenant earns partial credit.

Category: Exchange

Microsoft Licensing: Works with Basic licensing

Secure Score Impact: Not verified. No Microsoft Secure Score control could be confirmed for this setting from published sources. See the note in README.md before publishing this field.

Remediation in Augmentt: Configure directly in Augmentt (Configure tab)

Compliance Frameworks:

  • CISA SCuBA — MS.EXO.3.1

  • NIST CSF 2.0 — PR.PS-01

  • CIS Microsoft 365 Benchmark v6 (Level 1) — 2.1.9

  • CIS Microsoft 365 Benchmark v7 (Level 1) — 2.1.9

  • HIPAA Security Rule — 164.312(e)(2)(i)

  • CMMC Level 1 — SC.L1-b.1.x

  • CMMC Level 2 — SC.L2-3.13.15

Microsoft documentation:

IMPORTANT:

The DKIM security posture will validate DKIM records on domains. The presence of a CNAME record in the domain is a fundamental prerequisite for DKIM. Consequently, since this posture is centered on DKIM, it will only validate those domains that fulfill the basic requirements of DKIM.


_KB status: already published as "DKIM" — update the existing step in place._

_Source: Augmentt native check. Check ID dkim (module 23)._

Sourced for this page:

  • Secure Score — No Microsoft Secure Score control name is published for this setting and Augmentt does not read one.


Draft metadata — apply these as Stonly tags in the console, then delete this block. The Stonly API cannot set tags, so they are recorded here instead.
Tags: posture-check · compliance-audit · Exchange Online · Exchange · M365 Basic · CIS M365 v6 L1 · CIS M365 v7 L1 · NIST CSF 2.0 · HIPAA · CISA SCuBA · CMMC Level 1 · CMMC Level 2