ããã«ã¡ã¯ãã¨ã ã¹ãªã¼ã§SREãã»ãã¥ãªãã£ã«å¾äºãã¦ããå±±æ¬ã§ãã
以åã«ããGmailã®ã¡ã¼ã«èªè¨¼è¦å¶å¼·åã¸ã®å¯¾å¿ã£ã¦çµãã£ã¦ã¾ããï¼ãã¨ããè¨äºãæ¸ããã¦ããã ãã¦ããã¾ãããããã§ã¡ããåºãã ãããDMARCã«ã¤ãã¦æ¸ããã¦ããã ãããã¨æãã¾ãã
Gmailã¸ã®å¯¾å¿ãå®æ½ããã ããªãã°ããã¨ããããããããããªããã©å ¥ãã¦ããã°OKããªã®ã§ãããããããDMARCã¯ä½ã®ããã«åå¨ãã¦ãã¦ã©ã®ããã«æ´»ç¨ã«ããã®ãã¨ããã¨ããã«è§¦ãã¦ããããã¨æãã¾ãã
DMARCã¨ã¯
DMARCã®æ¥æ¬ã«ãããæ®åã¯é²ãã§ããªãã¨è¨ããããã¨ãããã¾ãããã以åã«ãä½ã®ããã«åå¨ããã®ãããã©ã®ãããªåããããã®ããã¨ããã¨ããããç¥ããã¦ããªãé¨åãããã¾ãã
SPF/DKIM
ååã®è¨äºã§è§¦ããSPF/DKIMã«ã¤ãã¦ãããããã¾ãã
- SPF : ã¡ã¼ã«éä¿¡å ã®IPãèªãã¡ã¤ã³ã®DNSã«ç»é²ãã¦ãããã¨ã§ããã®ãã¡ã¤ã³æ¨©å©è ããã®éä¿¡ã§ãããã¨ãæ ä¿ãã
- DKIM : ã¡ã¼ã«ã«ç½²åãä»ä¸ãããã®ç½²åãããç§å¯éµã¨å¯¾ã«ãªãå ¬ééµãèªãã¡ã¤ã³ã®DNSã«ç»é²ãã¦ãããã¨ã§ããã®ãã¡ã¤ã³æ¨©å©è ããã®éä¿¡ã§ãããã¨ãæ ä¿ãã
ã¤ã¾ãã©ã¡ããç®ç㯠èªç¤¾ã®ã¡ã¼ã«ãèªç¤¾ããéããããã¨ãä¿è¨¼ãããã®ã§ãã
ããã¯ãã¡ããæ£ãããã¨ã§ãããããã°ã§ããã®æ¹æ³ã«ã¤ãã¦æ¸ãã¦ãã¾ããããããããã¯ããªããã¾ãã§èªç¤¾ãã¡ã¤ã³ããã¡ã¼ã«ãéã人ãã¡ãã«å¯¾ããç´æ¥çãªé²å¾¡çã«ã¯ãªãã¾ããã
DMARCç»å ´
DMARCã¯SPF/DKIMã使ã£ãæè¡ã§ãããå°ãæ¯è²ãç°ãªãã¾ããSPFãDKIMãã¢ã©ã¤ã³ã¡ã³ããå«ãã¦æ£ããè¨å®ããã°DMARCã¯PASSããã®ã§ãããç®çã¨ããã¨ããã«éããããã¾ãã
- SPF/DKIM â èªç¤¾ã®ã¡ã¼ã«ãèªç¤¾ããéããããã¨ãä¿è¨¼ãã
- DMARC â ãªããã¾ããèªç¤¾ãã¡ã¤ã³ã®ã¡ã¼ã«(DMARCãPASSããªãã¡ã¼ã«)ã«ã¤ãã¦æå¦/éé¢ããããã«æ示ãã§ãã
èªç¤¾ã®ã¡ã¼ã«ã§DMARCãPASSãããåªåã¨ããã®ã¯ãè£ãè¿ãã°DMARCã«PASSããªãã¡ã¼ã«ã¯å½ç©ã ãã¨è¨ãåãããã®åªåã§ãã å®éã«æåãªå¤§æä¼æ¥ãåä¹ãè¿·æã¡ã¼ã«ãåå¨ãããã¾ããè¿·æã¡ã¼ã«ã§ãªããå®éã®ä¼æ¥åãå½ãè©æ¬ºå¸«ããããã¾ããããã®ãããªã¡ã¼ã«ãå¯è½ãªéãåæ¸ããããã«ã§ãã対çãªã®ã§ãã
DMARCã§å®æ½ã§ããããªã·ã¼ä¸ç¨®
DMARCã®DNSã¬ã³ã¼ãã§ã¯ããªã·ã¼ã®æå®ãå®æ½ããã¾ãã以ä¸ã®ä¸ç¨®ã§ãã
- p=none : DMARCã«PASSããªãã¦ãç¹ã«ä½ãããªã(ã¡ã¼ã«ãµã¼ãã®åºæºã«æ²¿ã£ã¦è¿·æã¡ã¼ã«æ±ããªã©ããããã¨ã妨ããããã§ã¯ãªã)
- p=quarantine : DMARCã«PASSããªããªãéé¢ãã(è¿·æã¡ã¼ã«ãã©ã«ããªã©)
- p=reject : DMARCã«PASSããªãã¡ã¼ã«ã¯æå¦ãã
å®éã«å社ãè¦ã¦ã¿ã¾ããããæããã¨ã ã¹ãªã¼ã¯ none
ãGoogle㯠reject
ãApple㯠quarantine
ã§ãã
$ dig +short txt _dmarc.m3.com "v=DMARC1;p=none;rua=mailto:[email protected];ruf=mailto:[email protected];rf=afrf;pct=1" $ dig +short txt _dmarc.google.com "v=DMARC1; p=reject; rua=mailto:[email protected]" $ dig +short txt _dmarc.apple.com "v=DMARC1; p=quarantine; sp=reject; rua=mailto:[email protected]; ruf=mailto:[email protected];"
ããªã·ã¼ã®å¼·å
ä»åãGmailã§ã®ã¡ã¼ã«èªè¨¼ã§å¤§ééä¿¡ã«ã¯DMARCãå¿
é ã¨ãªãã¾ãããããã¨ããããå
¥ãã¨ããã«ã¤ãã¦ã¯ p=none
ãããã§ãã
ããããæ¬æ¥ã¯ none
ãããå¼·ãããªã·ã¼ã®æ¹ãå¹æçã§ãã
èªç¤¾ã®DMARCããªã·ã¼ã仮㫠reject
ã quarantine
ã«ããã°ãå°ãªãã¨ã対å¿ããã¡ã¼ã«ãµã¼ãã«ããã¦ãæ確ã«ãªããã¾ãã¡ã¼ã«ãå¤å¥ã§ããããã«ãªãã¾ããããã¯ãä¾ãã° [email protected]
ãåä¹ã£ã¦ãã£ãã·ã³ã°ãµã¤ãã«èªå°ãããããªã¹ãã ã¡ã¼ã«ãæé¤ã§ããããã§ããã社å¡ãåä¹ãè©æ¬ºå¸«ã @m3.com ãé¨ã£ãã¡ã¼ã«ãåºãäºãå°é£ã¨ãªãã¾ãã
ãããã¡ã¼ã«ã»ãã¥ãªãã£ã®ç¾ç¶ã§ã®ç®çå°ã§ãã
å¼·åã§ããã
èªç¤¾ã®ã¡ã¼ã«ã§DMARCãPASSãããåªåã¨ããã®ã¯ãè£ãè¿ãã°DMARCã«PASSããªãã¡ã¼ã«ã¯å½ç©ã ãã¨è¨ãåãããã®åªåã§ãã
ä¸ã§ãã®ããã«æ¸ãã¾ããããGmailã®è¦å¶å¼·åã«ä¼´ã£ã¦èªç¤¾ã®ã¡ã¼ã«ãµã¼ãã¹ãå®ç§ã«SPF/DKIMã«å¯¾å¿ã§ããã°ã確å®ã«ãDMARCã«PASSããªãã¡ã¼ã«ã¯å½ç©ãã¨è¨ãåããã¯ãã§ãããããªãã° p=none
ã¨æ¥åã£ã¦ãªãã§ãã£ã㨠p=reject
ãªã©ã«ããã°ããã¯ãã§ãã
ãããã§ããªãã®ã¯ãå¿
ãããå
¨ã¦ã®æ£ããã¡ã¼ã«ãSPF/DKIMã«å¯¾å¿ã§ãã¦ããªããããããªãã®ã§èªä¿¡ããªãã¨ããäºã§ããã¡ã¼ã«ãéä¿¡ããå´ã¯åæã«éä¿¡ãã¦ãã¾ãããç¸æã®ã¡ã¼ã«ããã¯ã¹ã§è¿·æã¡ã¼ã«ãã©ã«ãã«å
¥ã£ã¦ãã¾ã£ã¦ããã¨ããã°ãããã¯æ¤ç¥ã§ãã¾ãããã ãããèªä¿¡ããªããã®ã§æè¡ã§ãã¾ãããã¨ã ã¹ãªã¼ã«éããã°ãã¼ãã«ã«å±éãã¦ããå ´åã«ã¯ãm3.com
ã使ã£ã¦ããã®ãå½å
ã«éããªãã£ãããã¾ãã®ã§ãå
¨ä½çãªå½±é¿ãåºã¦ãã¾ãã
ã¡ãªã¿ã«ãããã©ã«ãã§ã¯DMARCã®ããªã·ã¼ã¯ãµããã¡ã¤ã³ã«ç¶æ¿ããã¾ããusa.m3.com
ãªã©ã¨ãã£ããã¡ã¤ã³ã«ã¤ãã¦ã m3.com
ã®ããªã·ã¼ããã®ã¾ã¾ç¶æ¿ããã¾ãããããããããå°ãå ´åã«ã¯ããªã·ã¼ãä¸æ¸ããããããªè¨å®ãå¯è½ã§ããã§ãã®ã§ããµããã¡ã¤ã³ãã¨ã«åå²ããéç¨ããªããã¦ããå ´åã¯å½±é¿åº¦ãå°ããããªããé²è¡ãããäºãå¯è½ã§ãã
DMARCã¬ãã¼ã
å½±é¿ãããããããªãããæè¡ã§ããªãã¨ãã£ã¦ããã¨ãã¤ã¾ã§ãã£ã¦ãå®æ½ã§ããªãã®ã§ããããã®ããã«DMARCã¬ãã¼ãã¨å¼ã°ãããã®ãç¨æããã¦ãã¾ãã
RUA/RUFã®äºç¨®ã®ã¬ãã¼ã
$ dig +short txt _dmarc.m3.com "v=DMARC1;p=none;rua=mailto:[email protected];ruf=mailto:[email protected];rf=afrf;pct=1"
DMARCã®æå®ã®ä¸ã§ ruf
ã rua
ã¨ãããã®ãããã¾ãããã® f
ã®æ¹ã失æã¡ã¼ã«ã a
ã®æ¹ãéç´æ
å ±ã®ã¡ã¼ã«ã§ããDMARCã«å¯¾å¿ããã¡ã¼ã«ãµã¼ããæ¥ã
ã @m3.com ããã®ã¡ã¼ã«ããã§ãã¯ãã¦ã¬ãã¼ãã¨ãã¦éä¿¡ãã¦ãããã®ã§ãããã®ã¬ãã¼ãããã§ãã¯ãããã¾ããå¤ãã®ã¡ã¼ã«ãéä¿¡ãã¦ããå ´åã¨ã¦ã大éã«åä¿¡ãããã¨ã«ãªãã¾ãã®ã§ãåä¿¡å
ã®ã¡ã¼ã«ã¢ãã¬ã¹ã¯æ³¨æãã¦ãã ããã
念ã®ããã§ãããRUAã¬ãã¼ãã®XMLã«ã¯å人æ å ±ãæ©å¯æ å ±ã¯ä¸åå«ã¾ãã¦ãã¾ããã(ã¡ã¼ã«ãéä¿¡ããå ã®ãã¡ã¤ã³åãªã©ã¯å«ã¾ãã¾ãã) RUFã¬ãã¼ãã«ãåºæ¬çã«ã¯å«ã¾ãã¾ããããããå°ã詳細ãªæ å ±ãããã¾ãã
ãã®ã¬ãã¼ãã使ã£ã¦æ¬¡ã®ç¢ºèªãã§ãã¾ãã
- èªç¤¾ããéä¿¡ããã¡ã¼ã«ã§SPF/DKIM/DMARCã§å¤±æãã¦ãããã®ã¯ãªããï¼
- ãªããã¾ããã®ä»ã横è¡ãã¦æªããã¡ã¼ã«ãé£ã³äº¤ã£ã¦ããªããï¼
DMARCã¬ãã¼ãã®ç¢ºèªãã¼ã«
XMLãªã®ã§ããã®ã¾ã¾ç®ã§çºãã¦ãã¡ãã£ã¨æå³ããããã¾ããã
以ä¸ã¯Microsoftããéä¿¡ããã¦ããRUAã¬ãã¼ãã®ããä¸é¨ã§ãã
<?xml version="1.0"?> <feedback xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"> <version>1.0</version> <report_metadata> <org_name>Enterprise Outlook</org_name> <email>[email protected]</email> <report_id>b64757d736234cc382af6df3d7049a5b</report_id> <date_range> <begin>1700956800</begin> <end>1701043200</end> </date_range> </report_metadata> <policy_published> <domain>m3.com</domain> <adkim>r</adkim> <aspf>r</aspf> <p>none</p> <sp>none</sp> <pct>1</pct> <fo>0</fo> </policy_published> <record> <row> <source_ip>35.76.16.148</source_ip> <count>1</count> <policy_evaluated> <disposition>none</disposition> <dkim>pass</dkim> <spf>pass</spf> </policy_evaluated> </row> <identifiers> <envelope_to>XXXX.co.jp</envelope_to> <envelope_from>bounce.m3.com</envelope_from> <header_from>m3.com</header_from> </identifiers> <auth_results> <dkim> <domain>m3.com</domain> <selector>awsmail-20180830</selector> <result>pass</result> </dkim> <spf> <domain>bounce.m3.com</domain> <scope>mfrom</scope> <result>pass</result> </spf> </auth_results> </record> ...
ããè¦ãã¨ãªãã¨ãªãæå³ã¯ãããã¾ãããé常ã«å¤§éãªã®ã§å ¨ã¦ããã§ãã¯ããããã«ã¯ããã¾ãããããã解決ããããã«ã¯DMARCã®ã¬ãã¼ã解æãã¼ã«ã使ããã¨ã«ãªãã¾ããåä¿¡ããã¬ãã¼ãã¡ã¼ã«ãèªåçã«ãã¼ã«ã«æµãè¾¼ãã§â¦ãã¨ãããã¨ã§ãã æåã®ãã¼ã«ãå¤ãã¨æãã¾ããã¡ãã£ã¨æåã§è¦ã¦ã¿ãã¬ãã«ãªãã°ä»¥ä¸ã®ãã®ã§ãè¯ãã¨æãã¾ããã©ã¡ããã¢ã¡ãªã«ã®ä¼æ¥ã®æä¾ãããã®ã§ãã
ã§ã¯å®éã«ãMicrosoftããæ¥ãRUAã¬ãã¼ããå¾è ã®ãµã¤ã(dmarcian)ã§å¦çãã¦ã¿ã¾ãããã®ãµã¤ãã§ã¯ã¬ãã¼ãããããã«å¯è¦åãã¦ããã¾ãããã ãã10MBãä¸éã§ãã®ã§å¤ãããå ´åã¯é©å½ã«åºåã£ã¦ãã ãããè¤æ°ã®ã¬ãã¼ããã¡ã¤ã«ãã¢ãããã¼ãã§ãã¾ãã
念ã®ããXMLã®è¦ç´ ã®ãã¡envelope-toãsalt+hashåãã¦é ãã¦<envelope_to>b94fdc2eac3669a489d7ff566c40c4ee6729d8dc.com</envelope_to>
ã®ãããªå½¢ã«ãã¦ããã¢ãããã¼ããã¾ãããå®éã«ã¢ãããã¼ããããã®ã¯ãããFromãã¡ã¤ã³ãenvelope-fromãéä¿¡å
IPãDKIMãã¡ã¤ã³ãDKIMã»ã¬ã¯ã¿ãããã§ããéä¿¡å
ã¯Microsoftã¡ã¼ã«ã使ã£ã¦ããã¨ã¯ãããå¤ç¨®å¤æ§ã®ãã¡ã¤ã³ã¨ãªãã¾ãããããé ãã¦ããã¾ããã
ã¬ãã¼ãURLãçæããã¾ãã®ã§ããã¯ã·ã§ã¢å¯è½ã§ããåºãå
¬éããã¾ãã確èªãçµãã£ããæ¶ãã¦ããã¨è¯ãã§ãããã
ãã®å ´åã¯Threat/Unknownã®ã¿ã(赤ãã¨ãã)ãé¸æãã¦ä¸èº«ãããè¦ã¦ã¿ã¾ãã
ããã¯ãSPF/DKIMã Pass
ã㤠fail-unaligned
ã§ããç°¡åã«è¨ãã°ã次ã®ç¶æ
ã§ãã
- ãããFrom㯠m3.com(å ã m3.comã®ã¬ãã¼ãã§ãã®ã§ãããªãã¾ã)
- envelope-fromã¨ãã¦
willap.jp
ã使ã£ã¦ãã¦ãwillap.jp
ã®SPFã«åè´ãã¾ã(ã¤ã¾ããWiLL Mailã§ã) dkim1._domainkey.willap.jp
ã¨ããDKIMã®ã»ã¬ã¯ã¿ã«å¯¾å¿ããéµã§ç½²åãå®æ½ããã¦ãã¾ã
SPF/DKIMã¨ãã«åé¡ããã¾ããããããããã¡ã¤ã³ã¨ä¸ä¸è´ã§ãã(ã¤ã¾ããã¢ã©ã¤ã³ã¡ã³ããã§ãã¯ã§å¤±æãã¦ãã¾ãã)
ã©ãå¤æããã
ãã®ãããªã¡ã¼ã«ãã¬ãã¼ãããã¦ããã¨ãã¦ã次ã®ã©ã¡ããã§ãã
- 誰ãæªã人ã m3.com ãåä¹ã£ã¦ WiLL Mailã§éä¿¡ãã¦ãã
- M3ã§è¨å®ãã¦WiLL Mailã§éä¿¡ãã¦ããããDKIMã®è¨å®ãä½æè ç½²åã«ãã¦ããªã
WiLL Mailã¯envelope-fromã [email protected]
ã¨ãªãã¾ãããDKIMã¯å¤æ´å¯è½ã§ãã
ããããã¯ãã®å¤æ´ãããªã®ã§ã©ãã®é¨ç½²ããã®ã¡ã¼ã«ãéä¿¡ãã¦ããã®ããæ¢ãã¨ãããã¨ã«ãªã£ã¦ããã®ã§ãã
ãããä»®ã«åè
ã ã¨ããããããã¯ããã§åé¡ã§ãããéä¿¡ã§ãã以ä¸ã¯ç´æ¥çã«ã¯æåºãã§ãã¾ããã
ããã m3.com ããéä¿¡ãã¦ããã¡ã¼ã«ããæ²æ»
ããæã« DMARCè¨å®ãå¤æ´ã㦠reject
ãªã©ã«ãããã¨ã§DMARCã«å¯¾å¿ããã¡ã¼ã«ãµã¼ãã§æå¦ããããã¨ãã§ããã¨ããããã§ãã
ã¡ã¼ã«è»¢é
ä»ã«ãã¬ãã¼ãã«æ¤åºãããæªããã¡ã¼ã«ãããã¤ãããã¾ãã
ä¾ãã°åããããªWiLL Mailããã®ã¡ã¼ã«éä¿¡ã§ããããã¯æã
ã®ç®¡çããªãIP(ãã®éå¼ã㯠XXXX.go.jp
) ããã®éä¿¡ã¨ãªã£ã¦ãããenvelope-fromã§ãã willap.jp
ã¨ã¯ä¸è´ãã¾ããã
æè¨ã¯ã§ãã¾ãããããããã㯠XXXX.go.jp
ã§åããã¡ã¼ã«ãMicrosoftã«è»¢éããã®ã§ããããããã®ããã«éä¿¡IPãå¤åãã¦ãã¾ã£ãã¨ãSPFã¯è»¢éã«å¼±ãã®ã§ãã®ãããªãã¨ãçºçãã¾ããDKIMã«ã¤ãã¦ã転éã§ãããçãå¤åããéã«ãé»åç½²åã¨ããã¦ãã¾ããã¨ãããã¾ãã(DKIMã¯ããããããã£ã®ä¸èº«ã«ç½²åãã¾ãã®ã§ããããæ¸ãæããããã¨æ¹ããã¨å¤æããã¾ãã)
ãã®ãããªãã®ã¯ãããªãã«æ£è¦ããã¾ãããç´æ¥çã«ã¯æåºãã§ãã¾ããã®ã§ä»åã¯é観ãã¦ãã¾ãã
ä»å¾
ã¨ã ã¹ãªã¼ã§ãDMARCã«ã¤ãã¦ããã¡ããèæ
®ãã¦ãã¾ãããç¾ç¶ã§ã¯ p=none
ã«ãªã£ã¦ããã¨ããç¶æ
ã§ãã
ããã¯åé¡ã®ããã¡ã¼ã«ã®åå¨ãç¥ã£ã¦ãããããªã®ã§ãããåé¡ã®ããã¡ã¼ã«ãä»åã®Gmail対å¿ã§ä¸æãããã¨ãã¦ãã¾ãã
Gmail対å¿ã®ããã¤ãã«ã¯ããã«DMARCã®å¼·åãå³ã£ã¦ããã ããã¨ãä¸çãããªããã¾ãã¡ã¼ã«ãå°ãã§ãæ¸ãã¨ãããã¨ã§ãã®ã§ãç¹ã«å½±é¿åãããã¡ã¤ã³ããæã¡ã®ä¼ç¤¾ã®æ¹ã ã¯ã©ãã©ãå¼·åãã¦ããã ããã¨å°ãã§ãä¸çããããªãããã§ãã
ç§ã¯ç¾å¨ã¯æåã®ãµã¼ãã¹ã使ã£ã¦ããããã§ã¯ããã¾ãããããã®ãããªãµã¼ãã¹ãå¤ã ããã¾ãã®ã§ããã®æ¤è¨ãè¯ããã¨æãã¾ãã
ã¾ã¨ã
- æ¥å¹´2æããGmailã¸ã®å¤§ééä¿¡ã¯è¦å¶ãå§ã¾ã â Gmailのメール認証規制強化への対応って終わってますか? - エムスリーテックブログ
- DMARCã¸ã®å¯¾å¿ãå¿ é ã«ãªãããã©ãDMARCã£ã¦ããããä½ãªãã ã£ãï¼
- DMARCã¯SPF/DKIMã«å¯¾å¿ãã¦ãããªããã¡ã¼ã«ãæé¤ããããã®ä»çµã¿ã
- DMARCã¬ãã¼ãã使ã£ã¦èªãã¡ã¤ã³ã®ã¡ã¼ã«ã®å¯¾å¿ç¶æ³ãè¿·æã¡ã¼ã«ç¶æ³ã確èªã§ãã
- DMARC対å¿ã§ä¸çããããªã
We are hiring!
ã¨ã ã¹ãªã¼ããã®ã°ã«ã¼ãä¼ç¤¾ã§ã¯å¸¸ã«ç´ æµãªã¨ã³ã¸ãã¢ãåéãã¦ããã¾ãï¼ èå³ããã°ãã²ãè¶ããã ããï¼