Azure virtual machine allows direct SMTP access from the Internet
- CCPA ,
- ISO/IEC 27001 ,
- Microsoft Cloud Security Benchmark ,
- Mitre ATT&CK v12 ,
- New Zealand Information Security Manual ,
- NIST 800-53 ,
- Orca Best Practices ,
- UK Cyber Essentials
DescriptionSimple Mail Transfer Protocol (SMTP) is an Internet standard communication protocol for electronic mail transmission. Mail servers and other message transfer agents use SMTP to send and receive mail messages. The SMTP port (25) is open on your virtual machine and allows all incoming traffic from the Internet. In order to keep security best practices, you should restrict access to be only from allowed IP addresses.
Configure networking rule to allow incoming SMTP traffic from allowed IP addresses only.