Skip to content
arrow_back
search
ISM-0567 policy ASD Information Security Manual (ISM)

Restrict Email Relay to Specific Domains

Ensure email servers only relay emails within their own domains to prevent misuse.

record_voice_over

Plain language

This control ensures your email server only sends or accepts emails from your specific organisation's domain, like yourcompany.com, including subdomains. It prevents outsiders from using your email server without permission, which could lead to spam or fraudulent emails being sent from your address, damaging your reputation and clogging up your system.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Email servers only relay emails destined for or originating from their domains (including subdomains).
policy ASD Information Security Manual (ISM) ISM-0567
priority_high

Why it matters

If relay isn’t restricted to your own domains/subdomains, attackers can abuse the server as an open relay for spam/phishing, damaging your organisation’s reputation.

settings

Operational notes

Review SMTP logs for unauthorised relay attempts and regularly verify allowed sender/recipient domains (incl. subdomains) so relay rules stay aligned to current domain settings.

Mapping detail

Mapping

Direction

Controls