Skip Navigation

IIST-SV-000160: Require authentication for an SMTP relay

An IIS server configured to be an SMTP relay must require authentication.
To check compliance with IIST-SV-000160, interview your System Administrator about the role of the IIS 10.0 web server.
If the IIS 10.0 web server is running SMTP relay services, have the SA provide supporting documentation about how the server is hardened. A DoD-issued certificate, and specific allowed IP address should be configured.
If the IIS web server is not running SMTP relay services, this is not applicable.
If the IIS web server running SMTP relay services without TLS enabled, your server is not compliant.
If your server is not compliant, configure the relay server with a specific allowed IP address from the same network as the relay and implement TLS.