ç¾ä»£ã®ãã¸ãã¹ãå人ã®éä¿¡ã®å¤ãã¯ãé»åã¡ã¼ã«ã«ãã£ã¦è¡ããã¦ãã¾ããããããã¡ã¼ã«ãæªç¨ãããã£ãã·ã³ã°è©æ¬ºãã¹ãã ã¡ã¼ã«ããªããã¾ãæ»æï¼Spoofingï¼ã¯å¹´ã å¢å ãã¦ããã伿¥ãå人ã®ã»ãã¥ãªãã£ãè ããã¦ãã¾ããããããè å¨ã«å¯¾æããããã«éçºãããã®ããDMARCï¼Domain-based Message Authentication, Reporting, and Conformanceï¼ã¨ããã¡ã¼ã«èªè¨¼ã®ä»çµã¿ã§ãã
ãã®è¨äºã§ã¯ãDMARCã®ä»çµã¿ãã¡ãªãããå®éã®å°å ¥æ¹æ³ã«ã¤ãã¦ãããããã解説ãã¾ãã
DMARCã¨ã¯ï¼
DMARCã¯ãé»åã¡ã¼ã«ãéä¿¡å ã®æ£å½ãªãã¡ã¤ã³ããéä¿¡ããããã©ããã確èªããããã®ãããã³ã«ã§ããããã«ããããªããã¾ããè©æ¬ºã¡ã¼ã«ãæ¤åºãã鲿¢ãããã¨ãã§ãã¾ãã
DMARCã¯ä»¥ä¸ã®2ã¤ã®æè¡ãåºç¤ã¨ãã¦æ©è½ãã¾ãï¼
-
SPFï¼Sender Policy Frameworkï¼
éä¿¡ãã¡ã¤ã³ã許å¯ãããIPã¢ãã¬ã¹ããã®ã¡ã¼ã«éä¿¡ã§ãããã確èªããã -
DKIMï¼DomainKeys Identified Mailï¼
é»åã¡ã¼ã«ã®å å®¹ãæ¹ããããã¦ããªãããæ¤è¨¼ãããã¸ã¿ã«ç½²åæè¡ã
ãããã®æè¡ã¨DMARCãçµã¿åããããã¨ã§ãéä¿¡è ãããã«å³å¯ã«èªè¨¼ããä¿¡é ¼æ§ã®é«ãã¡ã¼ã«éä¿¡ãå®ç¾ãã¾ãã
DMARCã®ä»çµã¿
DMARCã®åä½ã¯ä»¥ä¸ã®ã¹ãããã§é²è¡ãã¾ãï¼
-
ã¡ã¼ã«éä¿¡æã®èªè¨¼ãã§ãã¯
åä¿¡ã¡ã¼ã«ãµã¼ãã¼ã¯ãSPFãDKIMã®è¨å®ã確èªããã¡ã¼ã«ãéä¿¡å ã¨ãã¦ä¸»å¼µãã¦ãããã¡ã¤ã³ããæ£å½ãªæ¹æ³ã§éä¿¡ããã¦ããããæ¤è¨¼ãã¾ãã -
ããªã·ã¼ã«åºã¥ãå¦ç
DMARCã«ã¯ä»¥ä¸ã®ããªã·ã¼ï¼Policyï¼ãè¨å®ã§ãã¾ãï¼- noneï¼æ¤è¨¼çµæãè¨é²ããã ãã§ãç¹ã«å¶éããããªãã
- quarantineï¼å¤±æããã¡ã¼ã«ãã¹ãã ãã©ã«ãã«ç§»åã
- rejectï¼å¤±æããã¡ã¼ã«ãåä¿¡æå¦ããã
-
ã¬ãã¼ãã®éä¿¡
ã¡ã¼ã«ã®èªè¨¼çµæããã¡ã¤ã³ç®¡çè ã«éä¿¡ãããªããã¾ãæ»æã誤æ¤ç¥ã®ç¶æ³ãå¯è¦åãã¾ãã
DMARCãå°å ¥ããã¡ãªãã
1. ãªããã¾ãã¡ã¼ã«ã®é²æ¢
DMARCãè¨å®ãããã¨ã§ããã¡ã¤ã³ãæªç¨ããã¡ã¼ã«è©æ¬ºï¼ãªããã¾ãï¼ãé²ããã¨ãã§ãã¾ããããã«ããããã©ã³ãã¤ã¡ã¼ã¸ã®ä¿è·ã顧客ã®ä¿¡é ¼ç¶æã«ã¤ãªããã¾ãã
2. ã¹ãã ã¡ã¼ã«ã®åæ¸
DMARCã«ãã£ã¦ä¸æ£ãªã¡ã¼ã«ããã£ã«ã¿ãªã³ã°ããããããåä¿¡ããã¯ã¹å ã®ã¹ãã ã¡ã¼ã«ãæ¸å°ãã¾ãã
3. ã»ãã¥ãªãã£ã®åä¸
䏿£ãªã¡ã¼ã«ã鲿¢ããããã¨ã§ããã£ãã·ã³ã°è©æ¬ºããã«ã¦ã§ã¢ã®è¢«å®³ãªã¹ã¯ãå¤§å¹ ã«è»½æ¸ã§ãã¾ãã
4. éææ§ã®åä¸
ã¬ãã¼ãæ©è½ã«ãããã©ã®IPã¢ãã¬ã¹ããã¡ã¼ã«ãéä¿¡ããã¦ããããææ¡ã§ãã䏿£å©ç¨ã®æ©æçºè¦ãå¯è½ã§ãã
DMARCã®è¨å®æ¹æ³
DMARCãå°å ¥ããã«ã¯ã以ä¸ã®æé ãå®è¡ãã¾ãï¼
1. SPFã¨DKIMã®è¨å®
DMARCãæå¹ã«ããåã«ãSPFã¨DKIMãæ£ããè¨å®ãã¾ãããããã¯DNSï¼Domain Name Systemï¼ã®TXTã¬ã³ã¼ãã¨ãã¦ç»é²ãã¾ãã
2. DMARCã¬ã³ã¼ãã®ä½æ
DNSã«DMARCç¨ã®TXTã¬ã³ã¼ãã追å ãã¾ãã以ä¸ã¯ä¾ã§ãï¼
- v=DMARC1ï¼DMARCãã¼ã¸ã§ã³
- p=rejectï¼ããªã·ã¼ï¼none, quarantine, rejectï¼
- ruaï¼éè¨ã¬ãã¼ããåãåãã¡ã¼ã«ã¢ãã¬ã¹
- rufï¼è©³ç´°ã¬ãã¼ããåãåãã¡ã¼ã«ã¢ãã¬ã¹
3. ããªã·ã¼ã®æ®µéçãªå¼·å
- ãã¹ã段éï¼ã¾ãã¯
p=none
ãè¨å®ããç¾ç¶ã®ã¡ã¼ã«éç¨ã«å½±é¿ããªããã¨ã確èªãã¾ãã - å®éç¨æ®µéï¼åé¡ããªããã°ã
p=quarantine
ãp=reject
ã«ããªã·ã¼ãå¼·åãã¾ãã
4. ã¬ãã¼ãã®ç£è¦
宿çã«ã¬ãã¼ãã確èªãã䏿£ãªéä¿¡å ãè¨å®ã®åé¡ãåæãã¾ãã
å°å ¥æã®æ³¨æç¹
-
æ£å½ãªéä¿¡å ã®ç»é²æ¼ã
SPFãDKIMã®è¨å®ã§æ£å½ãªã¡ã¼ã«ãµã¼ãã¼ãæ¼ããªãç»é²ããªãã¨ãæ£è¦ã®ã¡ã¼ã«ãå¼¾ããããªã¹ã¯ãããã¾ãã -
段éçãªå°å ¥
䏿°ã«ããªã·ã¼ã峿 ¼åããã¨ãã¡ã¼ã«ãåä¿¡ãããªãåé¡ãçºçããå¯è½æ§ããããããæ éã«ãã¹ãããªããé²ãããã¨ãéè¦ã§ãã
ã¾ã¨ã
DMARCã¯ãSPFãDKIMã¨é£æºãããªããã¾ãã¡ã¼ã«ãã¹ãã ã¡ã¼ã«ã广çã«é²æ¢ããå¼·åãªã»ãã¥ãªãã£ãã¼ã«ã§ãã伿¥ãçµç¹ãDMARCãå°å ¥ãããã¨ã§ããã©ã³ãã®ä¿¡é ¼æ§ãåä¸ããã顧客ã徿¥å¡ããµã¤ãã¼æ»æããä¿è·ãããã¨ãã§ãã¾ãã
ç¹ã«ãè¿å¹´ã®ãµã¤ãã¼è å¨ã®å¢å ãèããã¨ãDMARCã®ãããªæè¡ã¯åãªããªãã·ã§ã³ã§ã¯ãªããå¿ é ã®ã»ãã¥ãªãã£å¯¾çã¨è¨ãã¾ããã¾ã å°å ¥ãã¦ããªãå ´åã¯ããã®æ©ä¼ã«ãã²æ¤è¨ãã¦ã¿ã¦ã¯ãããã§ããããï¼