æ¦è¦
é»åã¡ã¼ã«ã®éä¿¡å ãã¡ã¤ã³ãè©ç§°ããã¦ããªãããæ¤è¨¼ããéä¿¡ãã¡ã¤ã³èªè¨¼(Sender Domain Authentication)ã
ãã®éä¿¡ãã¡ã¤ã³èªè¨¼ã«é¢ããM3AAWGããçºè¡ããããã¹ããã©ã¯ãã£ã¹ææ¸ãããã¾ããæ¬è¨äºã§ã¯ãã®æ¦è¦ãã¾ã¨ãã¦ããã¾ãã
â»æ¬è¨äºã¯ãããã¾ã§ç§ã®èªèã«åºã¥ãã¾ã¨ãã§ãã詳細ã«ã¤ãã¦ã¯åæãã確èªé¡ãã¾ãã
SPFãDKIMãDMARCãARCãBIMIã¨ãã£ãéä¿¡ãã¡ã¤ã³èªè¨¼ã俯ç°çã«ã¾ã¨ããè¨äºã¯ãã¡ãã§ãã
- æ¦è¦
- M3AAWG
- éä¿¡ãã¡ã¤ã³èªè¨¼ã«é¢ãããã¹ããã©ã¯ãã£ã¹
- ã¾ã¨ã
M3AAWG
M3AAWG(â»)ã¯ãæ§ã
ãªãããã¯ã¼ã¯ä¸ã®è
å¨ã¸ã®å¯¾çã«ã¤ãã¦ããã¹ããã©ã¯ãã£ã¹çºè¡ããã¼ãã£ã³ã°éå¬ãè¡ã£ã¦ããã°ãã¼ãã«ãªçµç¹ã§ãã
(â»)The Messaging, Malware, and Mobile Anti-Abuse Working Group
é»åã¡ã¼ã«ã®éä¿¡ãã¡ã¤ã³èªè¨¼ã«ã¤ãã¦ãæ±ã£ã¦ãã¾ãã
æ¥æ¬ã«ãããé¢é£çµç¹ã¯JPAAWGã§ãã
éä¿¡ãã¡ã¤ã³èªè¨¼ã«é¢ãããã¹ããã©ã¯ãã£ã¹
M3AAWGã®Webãµã¤ãã§ã¯ããã¹ããã©ã¯ãã£ã¹ãå ¬éããã¦ãã¾ãã
ãã®ä¸ãããæ¬è¨äºã§ã¯ã2020å¹´ã«çºè¡ããã"M3AAWG Email Authentication Recommended Best Practices"ã¨ããææ¸ã«ã¤ãã¦è¨è¼ãã¦ããã¾ãã
9ãã¼ã¸ã§è¦ç¹ãã¾ã¨ããææ¸
ãã¼ã¸æ°ã¯å°ãªããæ¦è¦ã¬ãã«ã§è¦ç¹ãã¾ã¨ãã¦ããã¾ãã
詳細ã«ã¤ãã¦ã¯å¥ã®ææ¸çãåç
§ããããæ§æããã¦ãã¾ãã
âNo auth, no entryâ
"2. Introduction"ã§ã¯ãâNo auth, no entryâã¨ãã表ç¾ãç»å ´ãã¾ãã
é©åãªèªè¨¼(éä¿¡ãã¡ã¤ã³èªè¨¼)ã«æåããé»åã¡ã¼ã«ã®ã¿ãããã®å®å (recipient)ã«é éãããã¨ããèãæ¹ã§ãã
ãã®âNo auth, no entryâãåºãæ®åããéã«ã対å¿ã§ãããããM3AAWGããåãã¹ããã©ã¯ãã£ã¹ãçºè¡ããã¦ãã¾ãã
観ç¹ã¨ãã¦ãDMARC(RFC7489)ã«æ²¿ã£ããçµç¹ãã¡ã¤ã³(organizational domain)ã®ä¿è·ãæããã¦ãã¾ãã
4ã¤ã®èªè¨¼ãããã³ã«
ãã®ææ¸ã¯ã以ä¸ã®4ã¤ã®ãããã³ã«ã«ã¤ãã¦è¨åãã¦ãã¾ã("3. Scope")ã
- SPF (Sender Policy Framework) RFC 7208
- DKIM (Domain Keys Identified Mail) RFC 6376
- DMARC (Domain-based Message Authentication, Reporting, and Conformance) RFC 7489
- ARC (Authenticated Received Chain) RFC 8617
æ¬è¨äºã®ä½ææç¹(2023å¹´4æ)ã§ãä¸è¨RFCãææ°ã®ã¾ã¾ãªã®ã§ãåºæ¬çãªèãæ¹ã«ã¤ãã¦å¤§ããªèªã¿æ¿ãã¯ä¸è¦ãã¨æãã¾ãã
ææ°ã®è£è¶³äºé ã¨ãã¦ãRFC 7489ãObsoletesããäºå®ã®æ¬¡æDMARC(DMARCbisã2023å¹´4ææç¹ã§Internet-Draft)ã®çå®ãé²ãã¨ãããã«ç¸äºéç¨æ§ã«é¢ããèæ ®äºé çãã¾ã¨ãããã¦ããã¨æãã¾ããæ©ä¼ãããã°å¥è¨äºã«ã¾ã¨ãã¾ãã
SenderãIntermediaryãReceiverããããã«å¯¾ããæ¨å¥¨äºé
"4. Executive Summary: A Checklist"ã§ã¯ãSenderãIntermediaryãReceiverã¨ãã3ã¤ã®åé¡ã«æ²¿ã£ã¦æ¨å¥¨äºé ããã§ãã¯ãªã¹ãå½¢å¼ã§ã¾ã¨ãããã¦ãã¾ãã
ç¶ãã¦ã"5. Authentication Recommendation Discussion"ã§ããã詳細ã解説ããã¦ãã¾ãã
SenderãIntermediaryãReceiverã®å®ç¾©
3ã¤ã®åé¡ã¯ä»¥ä¸ã§ããRFCã®è¡¨ç¾ãèæ ®ããã¦ãã¾ãã
Senders (labeled in RFC 5598 as Authors or Originators)
- ãã©ã³ããªã¼ãã¼(æèããçµç¹ãã¡ã¤ã³ã¨ãã¦)ãã¡ã¼ã«ããã¯ã¹ãã¡ã¼ã«ãµã¼ãã¹ã®ãããã¤ãã¼ãå«ã¿ã¾ãã
- ãã ãã人ãã人ã«éä¿¡ãããã¡ã¼ã«ã®éä¿¡è ã¯å«ã¾ãªã(ãã®éä¿¡è èªèº«ããã¡ã¤ã³ããã©ã³ãã®ãªã¼ãã¼ã§ãªãéã)ã
- æ¬è¨äºã§ã¯ã"éä¿¡ãããã¡ã¤ã³å´"ã¨å¼ã³ã¾ãã
Intermediaries (as a catch-all for the RFC 5598 terms Mediators, Relays, or Gateways)
- é»åã¡ã¼ã«ã®è»¢éãµã¼ãã¹ãã¡ã¼ãªã³ã°ãªã¹ããµã¼ãã¹ãçãå«ã¿ã¾ãã
- ä¸è¬çãªã¡ã¼ã«ããã¯ã¹ãããã¤ãã¼ã転éæ©è½ãæä¾ãã¦ããå ´åã«ã該å½ãã¾ãã
- æ¬è¨äºã§ã¯ã"ä¸ç¶è
"ã¨å¼ã³ã¾ãã
Receivers
- é»åã¡ã¼ã«ã®å®å (recipient)ã®ããã«ãé»åã¡ã¼ã«ãåä¿¡ãæ ¼ç´(ã¹ãã¢)ãããã¡ã¤ã³ã®ãã¨ã§ãã
- é»åã¡ã¼ã«ã®å®å (recipient)èªä½ã¯ãReceiversã«ã¯è©²å½ãã¾ããã
- æ¬è¨äºã§ã¯ã"åä¿¡ããå´"ã¨å¼ã³ã¾ãã
Sender (éä¿¡ãããã¡ã¤ã³å´) ã®ãã¹ããã©ã¯ãã£ã¹
SPFãDKIMãDMARCã使ç¨ããããè¨è¼ããã¦ãããããããã®ãã¹ããã©ã¯ãã£ã¹ã®åç §å ãæãããã¦ãã¾ãã
ARCã®ä½¿ç¨ã«ã¤ãã¦ã¯è¨åããã¦ãã¾ãããIntermediariesã®æ¹ã§ç»å ´ãã¾ãã
è£è¶³ã¨ãã¦ãDMARCã«é¢ãã以ä¸ã®è¨è¼ã«ã¤ãã¦ã¯ãçæãå¿ è¦ã§ãã
Policy statements should be âp=rejectâ where possible, âp=quarantineâ otherwise.
- âp=noneâ, âsp=noneâ, and pct<100 should only be viewed as transitional states, with the goal of removing them as quickly as possible.
Policy should be set for balance between protection benefits of a ârejectâ or âquarantineâ policy setting and the potential loss of legitimate mail due to missing or broken signing.
"p=reject" ã âp=quarantine(pct=100)â ã¨ããããè¨åããã¦ãã¾ãã(DMARC Enforcement)ãä¸ç¨æã«ãã®ãããªããªã·ã¼ãä¸å¾é©ç¨ãããã¨ã¯ "éä¿¡ããã¡ã¼ã«ãå±ããªã" ã¨ãã£ããã©ãã«ã®çºçãæ¸å¿µããã¾ããä¸è¬çã«ã¡ã¼ãªã³ã°ãªã¹ãã·ã¹ãã ã¨ã®ç¸äºéç¨æ§ã®åé¡çãããã¾ãã
ãªããåè¿°ã®æ¬¡æDMARC(DMARCbisã2023å¹´4ææç¹ã§Internet-Draft)ã§ã¯ãã©ã®ãããªå ´åã«Senderã "p=reject" ã âp=quarantine(pct=100)â ãé©ç¨ãã¹ããã«ã¤ãã¦ããã詳ããè¨è¿°ãããã¨äºæ³ãã¦ãã¾ããæ©ä¼ãããã°å¥è¨äºã«ã¾ã¨ãã¾ãã
Intermediaries (ä¸ç¶è ) ã®ãã¹ããã©ã¯ãã£ã¹
ARCã®ä½¿ç¨ã¨ãDMARC reportã®çæãããããè¨è¼ããã¦ãã¾ãã
ããã¯ãä¸ç¶è ãSPFãDKIMãDMARCã®æ¤è¨¼ãè¡ããã¨ãæå³ãã¾ã(AARãããã®çæãDMARC reportã®çæã®ãã)ã
ã¾ããã¡ã¼ãªã³ã°ãªã¹ãçã®ãµã¼ãã¹ã«ããã¦ãä¸ç¶æã«è¡ãããã¡ãã»ã¼ã¸å 容ã®å¤æ´ãæå°éã¨ããããè¨è¼ããã¦ãã¾ãã
While M3AAWG recognizes that alteration may be unavoidable for intermediaries such as mailing list servers, it nevertheless recommends that such alteration be kept to a minimum.
ãªã¹ã¯ã®è»½æ¸çã¨ãã¦ãFromãããã®å¤æ´ãä¾ã¨ãã¦æãããã¦ãã¾ãã â»ãã®ææ³ã常ã«æ£ããã¨ããæå³ã§ã¯ããã¾ããã
ä¾ï¼Fromãããã[email protected]
ã®ã¡ã¼ã«ãã¡ã¼ãªã³ã°ãªã¹ããµã¼ããä¸ç¶ããéã«ã[email protected]
ã«æ¸ãæãããã¨ã§ãDMARCèªè¨¼ã®å¤±æãåé¿ãã
Receiver (åä¿¡ããå´) ã®ãã¹ããã©ã¯ãã£ã¹
SPFãDKIMãDMARCã®æ¤è¨¼ãDMARC reportã®çæãã¾ãå¿ è¦ã«å¿ãARCã®æ¤è¨¼ãããããè¨è¼ããã¦ãã¾ãã
éä¿¡å
ãã¡ã¤ã³ã®DMARCã®ããªã·ã¼ã "p=reject" ã§ããå ´åã«ã¯ãããã«å¾ãããè¨è¼ããã¦ãã¾ãã
ãªãã(Receiverå´ã®ãã¼ã«ã«ããªã·ã¼çã«ãã)ããªã·ã¼ãä¸æ¸ãããå ´åã«ã¯ãDMARC report ã«ãããè¨è¼ããç¹ã«ã¤ãã¦ã触ãããã¦ãã¾ãã
ä¸è¨ã«ã¤ãã¦ã¯ãåºæ¬çãªå 容ãã¨æãã¾ãã
ãã ããåè¿°ã®ããã«ã¡ã¼ãªã³ã°ãªã¹ãã·ã¹ãã ã¨ã®ç¸äºéç¨æ§ã®åé¡çã«ããã"p=reject" ã®ãã¡ã¤ã³ããã®ã¡ã¼ã«ã®DMARCèªè¨¼ã失æããéã«ãæ¬å½ã«æå¦ãããã©ãã㯠Receiver ã®å¤æ次第ã«ãªãã¨ããç¹ã«ã¤ãã¦ã¯ãåæ§ã«æ³¨æãå¿ è¦ã§ãã
ã¾ã¨ã
æ¬è¨äºã§ã¯ãM3AAWGããçºè¡ããããã¹ããã©ã¯ãã£ã¹ææ¸ã®æ¦è¦ãã¾ã¨ãã¦ã¿ã¾ããã
é»åã¡ã¼ã«ã¯é·ã使ããã¦ããæè¡ã§ã¯ããã¾ãããã¾ã å¤ãã£ã¦ããç¹ãå¤ããã§ãã