Skip to content
arrow_back
search
ISM-1024 policy ASD Information Security Manual (ISM)

Verify Senders for Email Failure Notifications

Only verified senders get notified if their email cannot be delivered.

record_voice_over

Plain language

This control means that when you send an email and it can't be delivered, you'll only get a notification if your identity as the sender can be verified. This is important because it helps to combat email scams and ensures that only genuine users are notified about email issues, preventing harmful activities like spammers from getting useful information about email addresses that work.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Notifications of undeliverable emails are only sent to senders that can be verified via SPF or other trusted means.
policy ASD Information Security Manual (ISM) ISM-1024
priority_high

Why it matters

If undeliverable mail notifications go to unverified senders, attackers can confirm valid addresses and refine spam/phishing campaigns, increasing fraud risk.

settings

Operational notes

Configure NDRs to only notify senders that pass SPF, DKIM/DMARC or other trusted checks; review mail gateway rules and update records regularly.

Mapping detail

Mapping

Direction

Controls