
ãã®è¨äºã¯ãå¼è·å£«ãããã³ã Advent Calendar 2025 ã® 3 æ¥ç®ã®è¨äºã§ãã
ã¯ã©ã¦ããµã¤ã³ SRE ãã¼ã ã®é²è¤ã§ãã
ãã¡ã¼ã«éä¿¡è
ã®ã¬ã¤ãã©ã¤ã³ãã®æ¹è¨ãæ©ã«ãDMARCããªãããªããå
¬éããã¦ããç´ 2 å¹´ãçµéãã¾ããããã¤ãã«ã¯ã©ã¦ããµã¤ã³ããµã¼ãã¹ã§å©ç¨ãã cloudsign.jp ã® DMARC ããªã·ã¼ã quarantine ã«å¤æ´ã§ãã¾ããã
ããã§æ¬è¨äºã§ã¯ãDMARC ããªã·ã¼ã none ãã quarantine ã«å¤æ´ããã¾ã§ã®æµãã説æããå¾ã«ããã®éç¨ã§ã®èª¤ç®ãå¦ã³ãå ±æãã¾ãã ãããã DMARC ããªã·ã¼ã quarantine ã«å¤æ´ããæ¹ã ã®åèã«ãªãã°å¹¸ãã§ãã
- DMARC ããªã·ã¼ã none ãã quarantine ã«å¤æ´ããã¾ã§ã®æµã
- DMARC ã¬ãã¼ãã®åæããªãã¦ã¾ãã
- ã¡ã¼ã«ã®åä¿¡è ã¸ã®å½±é¿ããªãã¦ã¾ãã
- 社å ã¸ã®å½±é¿ããªãã¦ã¾ãã
- ä»å¾ã®å±æ
DMARC ããªã·ã¼ã none ãã quarantine ã«å¤æ´ããã¾ã§ã®æµã
ã¯ã©ã¦ããµã¤ã³ã§ã¯ã大ã¾ãã«æ¬¡ã®æµãã§ DMARC ããªã·ã¼ã quarantine ã«å¤æ´ãã¾ããã
- DMARC ã¬ãã¼ãåæç°å¢ã®æ§ç¯
- DMARC ããªã·ã¼ã®å¤æ´ã«ããå½±é¿ã®äºå調æ»
- DMARC ããªã·ã¼ã®å¤æ´
DMARC ã¬ãã¼ãåæç°å¢ã®æ§ç¯
DMARC ã¬ãã¼ãã¯ã¡ã¼ã«åä¿¡å´ãµã¼ãã¼ããéããã¦ãã XML å½¢å¼ã®ãã¡ã¤ã«ã§ã1ã å®éã«ã¯åºæ¬çã« zip ããã㯠gzip åããããã®ãã¡ã¼ã«ã«æ·»ä»ããã¦éããã¦ãã¾ãã
ã¯ã©ã¦ããµã¤ã³ã®å ´å㯠100 éãè¶ ãã DMARC ã¬ãã¼ããéããã¦ããæ¥ãå¤ããåå¥ã«åæãããã¨ãç¾å®çã§ã¯ããã¾ããã ãã®ãããã¾ã㯠DMARC ã¬ãã¼ãã®åæç°å¢ãæ§ç¯ãã¦ãDMARC ããªã·ã¼ã®å¤æ´ã«ããå½±é¿ãåæã§ããããã«ãã¾ããã
DMARC ã¬ãã¼ãã®åæç°å¢ã¨ãã¦ã¯ SaaS ã OSS ãåè£ã«å ¥ãã¾ãããã¯ã©ã¦ããµã¤ã³ã®å ´åã¯ç¤¾å ãã¼ã¿åºç¤ãåå¨ãã¦ããã®ã§ãã¡ãã鏿ãã¾ããã å ·ä½çã«ã¯ãXML å½¢å¼ããã CSV å½¢å¼ã®æ¹ãæ±ããããã£ããããã¡ã¤ã«å½¢å¼ã夿ããããããå®è£ ããCSV å½¢å¼ã® DMARC ã¬ãã¼ãã社å ãã¼ã¿åºç¤ã«å ¥åããæ§æã¨ãã¦ãã¾ãã ã¾ã社å ãã¼ã¿åºç¤ã§ã¯ããããã¼ From ãã¡ã¤ã³ãªã©ã§å種èªè¨¼çµæãçµãè¾¼ããããã«ããããå種èªè¨¼çµæã®æç³»åå¤åã追跡ã§ããããã«ãã¦ãã¾ãã
DMARC ããªã·ã¼ã®å¤æ´ã«ããå½±é¿ã®äºå調æ»
ã¯ã©ã¦ããµã¤ã³ã¯å¥ç´æ¸ãå§ãã¨ããæ¸é¡ãä»ããåæç· çµãå®ç¾ãããµã¼ãã¹ã§ãããåæç· çµã®éç¨ã§ã¯æ¸é¡ã®éä¿¡è ã¨åä¿¡è ãåå¨ãã¾ãã æ¸é¡ã®åä¿¡è ãã¯ã©ã¦ããµã¤ã³ã®ã¢ã«ã¦ã³ããä¿æãã¦ããªãå ´åãããã®ã§ãä¾ãã°æ¸é¡ãéä¿¡ããããã¨ã¯ã¡ã¼ã«ã§éç¥ãã¦ãã¾ãã
DMARC ããªã·ã¼ã quarantine ã«å¤æ´ããã¨ãDMARC èªè¨¼ã«å¤±æããã¡ã¼ã«ã¯åºæ¬çã«è¿·æã¡ã¼ã«ãã©ã«ãã«æ¯ãåãããã¾ãã ã¯ã©ã¦ããµã¤ã³ã®å ´åã¯ããããã¯ã©ã¦ããµã¤ã³å©ç¨è ã®å¥ç´è¡çºãé å»¶ããã¦ãã¾ãå¯è½æ§ãããã®ã§äºå調æ»ã宿½ãã¾ããã çµæã¨ãã¦ã1 æ¥ããã 5000 éãè¶ ããã¡ã¼ã«ã«å½±é¿ãä¸ãããã¨ããã£ããããDMARC ããªã·ã¼ã®å¤æ´ã¯æ éã«é²ãã¦ãããã¨ã«ãã¾ããã
DMARC ããªã·ã¼ã®å¤æ´
DMARC ããªã·ã¼ã®å¤æ´ã¯ããªãªã¼ã¹ææ³ã«ã«ããªã¢ãªãªã¼ã¹ãæ¡ç¨ãããã¨ã§æ éã«é²ãã¦ããã¾ããã DMARC ã§ã¯è¨å®ã® pct= ãã©ã¡ã¼ã¿ã¼ã«ãã£ã¦ããªã·ã¼ã®é©ç¨çãæå®ã§ãã¾ã2ã ãã®ãããé©ç¨çãæ®µéçã«å¼ãä¸ãã¦ãããã¨ã§ DMARC ããªã·ã¼ã®å¤æ´ã«ããå½±é¿ãã³ã³ããã¼ã«ãããã¨ãæå³ããããã§ãã
å ·ä½çã«ã¯ãquarantine ããªã·ã¼ã®é©ç¨çã¨é©ç¨æéã¯ä¸è¡¨ã®ã¨ããè¨ç»ãã¦ãã¾ããã
| é©ç¨ç | é©ç¨æé |
|---|---|
| 0% | - |
| 5% | 14 æ¥é |
| 10% | 14 æ¥é |
| 20% | 14 æ¥é |
| 100% | - |
ãããå®éã«ã¯ãå¾è¿°ããå½±é¿ãè¸ã¾ãã¦ä¸è¡¨ã®ã¨ããã¨ãªãã¾ããã é©ç¨ç 5% ã®æ®µéã§ã¯å½±é¿ãã»ã¨ãã©ç¢ºèªã§ããªãã£ãã®ã§ãé©ç¨æéã縮ãã¤ã¤é©ç¨ç 10% ã®æ®µéãã¹ããããã¦ãã¾ãã æ¯ãè¿ã£ã¦ã¿ãã¨ãé©ç¨çã¯è¨ç»éã 5% ãã 10% ã«å¼ãä¸ããæ¹ãè¯ãã£ãããããã¾ããã
| é©ç¨ç | é©ç¨æé |
|---|---|
| 0% | - |
| 5% | 5 æ¥é |
| 20% | 42 æ¥é |
| 50% | 13 æ¥é |
| 100% | - |
DMARC ã¬ãã¼ãã®åæããªãã¦ã¾ãã
DMARC ã¬ãã¼ããåæããã°ãquarantine ããªã·ã¼ãé©ç¨ãããã¡ã¼ã«ã® DMARC èªè¨¼å¤±æçãæ¸¬ããã ãããã転éã«ãã£ã¦ DMARC èªè¨¼ã«å¤±æãã¦ããæ£å½ãªã¡ã¼ã«ãç¹å®ã§ããã ãããã¨ãå½åã¯ããèãã¦ãã¾ããã ããããããåç´ã§ã¯ããã¾ããã§ããã
以ä¸ã«ç¤ºã DMARC ã¬ãã¼ãã®ä¾ãè¸ã¾ãã¦ããã®çç±ã説æãã¾ãã
<?xml version="1.0" encoding="UTF-8" ?> <feedback> <report_metadata> <!-- çç¥ --> </report_metadata> <policy_published> <!-- çç¥ --> </policy_published> <record> <row> <policy_evaluated> <disposition>quarantine</disposition> <dkim>pass</dkim> <spf>pass</spf> </policy_evaluated> </row> <identifiers> <envelope_from>mail.cloudsign.jp</envelope_from> <header_from>cloudsign.jp</header_from> </identifiers> <auth_results> <!-- çç¥ --> </auth_results> </record> </feedback>
ãquarantine ããªã·ã¼ãé©ç¨ãããã¡ã¼ã«ã® DMARC èªè¨¼å¤±æçãæ¸¬ããã ããã
DMARC ã¬ãã¼ãã® feedback > record > row > policy_evaluated ã«ã¯ DMARC èªè¨¼ã®çµæã示ããã¦ãã¾ãã
disposition ãã¡ã¼ã«ã«é©ç¨ããã DMARC ããªã·ã¼ãdkim ã DKIM Alignment ã®çµæãspf ã SPF Alignment ã®çµæã§ãã
ãã®ä»æ§ãããquarantine ããªã·ã¼ã®ã«ããªã¢ãªãªã¼ã¹ä¸ã¯ãæ¬¡ã®æ¡ä»¶ããã¹ã¦æºãããã®ããDMARC èªè¨¼ã«å¤±æããéé¢å¯¾è±¡ã¨ãªã£ãã¡ã¼ã«ãã§ããã¨å¤æã§ããã¯ãã§ãã
dispositionãquarantineã§ããdkimãfailã§ããï¼DKIM Alignment ã Fail ã§ããï¼spfãfailã§ããï¼SPF Alignment ã Fail ã§ããï¼
ãã®å¤±æçãç£è¦ãããã¨ã§ãã«ããªã¢ãªãªã¼ã¹ã®ç¶ç¶å¯å¦ã夿ã§ããã¨è¸ãã§ãã¾ããã
ã¨ãããå®éã«ã¬ãã¼ãã確èªãã¦ã¿ãã¨ãdisposition ã quarantine ã¨ãªã£ã¦ãããã¼ã¿ãã»ã¨ãã©è¦å½ããã¾ããã
ãã®ãããquarantine ããªã·ã¼ãé©ç¨ãããã¡ã¼ã«ãèå¥ã§ãããDMARC ã¬ãã¼ãããã«ããªã¢ãªãªã¼ã¹ã®å½±é¿ãæ£ç¢ºã«æ¸¬ããã¨ã¯æå¿µããããå¾ã¾ããã§ããã
ãã®ä»£ããã«ãquarantine ããªã·ã¼ã®é©ç¨ãåå ã¨æãããåãåããã®ä»¶æ°ã®å¤åããå½±é¿ãæ¦è¦³ãããã¨ã«ãã¾ããã
ã転éã«ãã£ã¦ DMARC èªè¨¼ã«å¤±æãã¦ããæ£å½ãªã¡ã¼ã«ãç¹å®ã§ããã ããã
DMARC ã¬ãã¼ãã® feedback > record > identifiers > envelope_from ã«ã¯ãã¡ã¼ã«ãããã¼ã®ã¨ã³ããã¼ã From ãã¡ã¤ã³ãè¨è¼ããã¾ãã
ã¨ã³ããã¼ã From ãã¡ã¤ã³ã mail.cloudsign.jp ã§ããå ´åããã®ã¡ã¼ã«ã®å¤ãã¯ãã¯ã©ã¦ããµã¤ã³ããéä¿¡ããã転éããããã¨ãªãåä¿¡è
ã®ã¡ã¼ã«ããã¯ã¹ã«å±ããæ£å½ãªã¡ã¼ã«ãã¨èãããã¾ãã
䏿¹ã§ã¨ã³ããã¼ã From ãã¡ã¤ã³ã mail.cloudsign.jp ã§ã¯ãªãå ´åããã®ã¡ã¼ã«ã¯æ¬¡ã®ã©ã¡ããã§ããã¨èãããã¾ãã
- ãããã¼ From ãè©ç§°ãã¦ã¯ã©ã¦ããµã¤ã³ã«ãªããã¾ããã¡ã¼ã«
- ã¯ã©ã¦ããµã¤ã³ããéä¿¡ããããã転éããã¦åä¿¡è ã®ã¡ã¼ã«ããã¯ã¹ã«å±ããæ£å½ãªã¡ã¼ã«
quarantine ããªã·ã¼ã®é©ç¨ã«ãã£ã¦ããªããã¾ãã¡ã¼ã«ãéé¢ãããã®ã¯æå¾ éãã§ãããåä¿¡è å´ã§è»¢éãããã¡ã¼ã«ãéé¢ãããã®ã¯å°ãã¾ãã ãã®ãããåä¿¡å´ã§ã®è»¢éãåå ã§éé¢ãããã¡ã¼ã«ãæ¸ãããã¨ãã§ããªããæ¤è¨ãã¾ããã å ·ä½çã«ã¯ãåä¿¡è ã顧客ã§ããå ´åã«éããã¾ãããæ¬¡ã®æ¡ä»¶ããã¹ã¦æºããã¡ã¼ã«ã¯ãããã£ãã¡ã¼ã«ã§ããå¯è½æ§ãé«ãã§ãã
- DMARC èªè¨¼ã«å¤±æãã¦ãã
feedback > record > identifiers > envelope_fromãmail.cloudsign.jpã§ã¯ãªãfeedback > record > identifiers > envelope_fromã顧客ã®ä¿æãããã¡ã¤ã³ã§ãã
ãã®ãã¨ããã顧客ãç¹å®ãã¦åå¥ã«ãµãã¼ãã§ããã°ã転éãåå ã§éé¢ãããã¡ã¼ã«ãæ¸ããã¦ãããã¨èãã¾ããã
ããããå®éã®ãã¼ã¿ãè¦ã¦ã¿ã㨠envelope_from ã空å¤ã§ããã¬ã³ã¼ãã 99ï¼
ãå ãã¦ããã転éã®æç¡ãç¥ããã¨ããå°é£ã§ããã
ããã«ãããDMARC ã¬ãã¼ãã®åæã«åºã¥ããè½åçãªé¡§å®¢ãµãã¼ããã§ããã¨ããç®è«è¦ãå¤ãããã¨ã«ãªãã¾ãã
ã¡ã¼ã«ã®åä¿¡è ã¸ã®å½±é¿ããªãã¦ã¾ãã
ãDMARC èªè¨¼ã«å¤±æãã¦ããã¡ã¼ã«ã¯è¿·æã¡ã¼ã«ãã©ã«ãã«æ¯ãåããããã ãã ãããã¨äºæ¸¬ãã¦ãã¾ããã ããããå®éã«ã¯å°ãæ§åãéãã¾ããã
DMARC èªè¨¼ã«å¤±æããéã®æåã¯ã¡ã¼ã«åä¿¡å´ãµã¼ãã¼ã®å®è£ ã«ä¾åãã¾ãããquarantine ããªã·ã¼ã§ããã°ãåºæ¬çã«ã¯è¿·æã¡ã¼ã«ãã©ã«ãã¸ã®æ¯ãåãã§æ¸ãã¨æãè¾¼ãã§ãã¾ããã ãã®ãããã«ããªã¢ãªãªã¼ã¹ã«éãã¦ã¯ããéè¦ãã¡ã¼ã«ã»ãã¥ãªãã£å¼·åã«ã¨ããªãDMARCããªã·ã¼å¤æ´ã®ãç¥ãããã§ãã¡ã¼ã«ãåä¿¡ãã¬ã¤ã«è¦å½ãããªãå ´åã¯ãè¿·æã¡ã¼ã«ãã©ã«ããã確èªãã ãããã¨ããæ¨ã®æ¡å ããã¦ãã¾ããã ãªãã顧客ã«ã¯åå 容ãã¡ã¼ã«ã§ãéç¥ãã¦ãã¾ãã
ã¨ãããã«ããªã¢ãªãªã¼ã¹ãéå§ããã¨ã顧客ãããã¡ã¼ã«ãè¿·æã¡ã¼ã«ãã©ã«ãã«ããå±ãã¦ããªããã¨ããåãåãããåãããã¨ã«ãªãã¾ããã çµæã¨ãã¦ããã£ãã®ã¯ãä¸é¨ã®ã¡ã¼ã«ãããã¤ãã¼ãã»ãã¥ãªãã£è£½åã§ã¯ã¡ã¼ã«æ¤ç«æ©è½ã§éé¢ãããã¡ã¼ã«ãã¦ã¼ã¶ã¼ã®ç®ã«è§¦ããå ´æã¸å±ããªãã±ã¼ã¹ãããã¨ãããã¨ã§ããã
ãã¡ã¼ã«ãè¿·æã¡ã¼ã«ãã©ã«ãã«ãå±ãã¦ããªããã¨ããäºè±¡ãæ³å®ã§ãã¦ããªãã£ããã¨ã«ãããã¯ã©ã¦ããµã¤ã³å©ç¨è ã®å¥ç´è¡çºãé å»¶ããã¦ãã¾ã£ãå¯è½æ§ãããã¾ãã 幸ããªãã¨ã«ãé大ãªåé¡ã«çºå±ããã¨ããäºå®ã¯ç¢ºèªããã¦ããªãã§ãããæããæ®ãã¾ããã
æ¯ãè¿ã£ã¦ã¿ãã¨ã顧客ããåãåãããåãã¦ãã¡ã¼ã«éä¿¡å´ã§è§£æ±ºã§ãããã¨ããªããããæ¬¡ã®æ¡å ãéç¥ããæ¹ãè¯ãã£ãããããã¾ããã
- ã¡ã¼ã«åä¿¡å´ãµã¼ãã¼ã®ç®¡çè ã«å¯¾ãã確èªãä¿ãæ¡å
- ã¡ã¼ã«åä¿¡å´ãµã¼ãã¼ã®ç®¡çè åãã®æ¡å
社å ã¸ã®å½±é¿ããªãã¦ã¾ãã
ãDMARC ããªã·ã¼ã®å¤æ´ã¯å¨ç¥ã§ãã¦ããã®ã§ãåãåãããæ¥å¢ãããã¨ã¯ãªãã ãããã¨æ¥½è¦³è¦ãã¦ãã¾ããã ããããäºæ³ã«åãã¦å¤ãã®åãåãããåããçµæã¨ãªãã¾ããã
ã«ããªã¢ãªãªã¼ã¹ã«éãã¦ã¯åè¿°ã®ã¨ããæ¡å ã®æ²è¼ã¨ã¡ã¼ã«éç¥ããã¦ãã¾ããããã«ããªã¢ãªãªã¼ã¹ã奿©ã¨ãã¦ãã¡ã¼ã«é¢é£ã®åãåãããé常æã¨æ¯è¼ãã¦æå¤§ 30ï¼ ãå¢å ãããã¨ã«ãªãã¾ããã æ´ãªãå¢å ã¯åãåããã«å¯¾å¿ããã¡ã³ãã¼ã®ç¨¼åãé¼è¿«ããã¦ãã¾ã䏿¹ã§ãDMARC ããªã·ã¼ã®å¤æ´ã¯ãªããã¾ãã¡ã¼ã«ã対çããç®çã§ãããã¨ããåãæ»ãã®ãæã¾ããããã¾ããã
ãã®ãããã«ããªã¢ãªãªã¼ã¹ã§ quarantine ããªã·ã¼ã®é©ç¨çãå¼ãä¸ããééãå½åã®äºå®ããé·ãåããã¨ã鏿ãã¾ããã çµæã¨ãã¦ã¯åãåããæ°ã®å¹³æºåã«ç¹ãã£ãã¨èããããç¡äºã« quarantine ããªã·ã¼ã®é©ç¨çã 100% ã¾ã§å¼ãä¸ãããã¨ãã§ãã¾ããã
æ®æ®µããã®å¤å²ã«ãããåãåããã«å ããä»åã®åãåããã«ãå°½åãã¦ãããã¡ã³ãã¼ã«ã¯å¿ããæè¬ãã¦ãã¾ãã æ¹ãã¦ãããã¨ããããã¾ããã
ä»å¾ã®å±æ
次㯠DMARC ããªã·ã¼ã reject ã«å¤æ´ãã¦ããããã¨ããã§ãã3 ãquarantine ã«å¤æ´ã§ãããã¨ã§å®ç¾å¯è½ã«ãªã£ããã¨ãããã¾ãã ããããBIMI ã®å°å ¥ã§ãã
BIMI ã¨ã¯ãã¡ã¼ã«ãããã¤ãã¼ã®åä¿¡ãã¬ã¤ä¸ã§ãéä¿¡å ã®åæ¨ç»é²ããããã´ç»åã表示ãããæè¡ã§ãã ãDMARC ããªã·ã¼ã quarantine 以ä¸ã§ãããã¨ããå°å ¥æ¡ä»¶ã ã£ãã®ã§ãããã¯ã©ã¦ããµã¤ã³ã§ãå°å ¥ãå¯è½ã«ãªãã¾ããã
BIMI ã®ãµãã¼ãç¶æ³ã¯ã¡ã¼ã«ãããã¤ãã¼ã«ãã£ã¦æ§ã ã§ãã4ããã´ç»åã®è¡¨ç¤ºã¯æ£å½ãªã¡ã¼ã«ã§ãããã¨ã®è¨¼æã® 1 ã¤ã«ããªããã¦ã¼ã¶ã¼ã®å®å¿æã«ã¤ãªããã¾ãã ä»å¾ã¯ãã®å°å ¥ã«åããåãçµã¿ãé²ãã¦ããããã¨èãã¦ãã¾ãã
- æ¸å¼ã®è©³ç´°ãåè¦ç´ ã®æå³ã«ã¤ãã¦ã¯ä»æ§ãåç §ãã¦ãã ããï¼RFC7489 Appendix C. DMARC XML Schema↩
-
ä¾ãã° DMARC è¨å®ã
p=quarantine; pct=10ã§ããå ´å 10% ã®ã¡ã¼ã«ã« quarantine ããªã·ã¼ãé©ç¨ããã¾ãã↩ - reject ãé©ç¨ãããã¡ã¼ã«ã¯ãDMARC èªè¨¼ã«å¤±æããã¨ã¡ã¼ã«åä¿¡å´ãµã¼ãã¼ã§åä¿¡æå¦ããããã¨ãæå¾ ããã¾ãã↩
- BIMI ã®æ¨æºåå£ä½ã BIMI ã®ãµãã¼ãç¶æ³ãå ¬éãã¦ãã¾ãï¼MailBox Provider↩