ç®æ¬¡
SPFãšã¯ïŒ
SPFïŒSender Policy FrameworkïŒã¯ããã£ãã·ã³ã°æ»æãè¿·æã¡ãŒã«ã§ãã䜿ãããææ³ã§ããã¡ãŒã«ã¹ããŒãã£ã³ã°ãé²ãããã«èšèšãããã¡ãŒã«èªèšŒãããã³ã«ã§ããã¡ãŒã«ã®ãµã€ããŒã»ãã¥ãªãã£ã«ãããŠäžå¯æ¬ ãªèŠçŽ ãšããŠãSPFã¯åä¿¡ã¡ãŒã«ãµãŒããŒããåä¿¡ããã¡ãŒã«ããã®ãã¡ã€ã³ã®ç®¡çè ã«ãã£ãŠèš±å¯ããããã¡ã€ã³ããéä¿¡ããããã®ãã©ããã確èªã§ããããã«ããŸãã
å žåçãªãã£ãã·ã³ã°æ»æã«ãããŠãè åšã¢ã¯ã¿ãŒãéä¿¡è ã®ã¢ãã¬ã¹ãå ¬åŒã®ããžãã¹ã¢ã«ãŠã³ãã被害è ãç¥ã£ãŠãã人ç©ã®ããã«åœè£ ãããããSPFã¯æå¹ãªå¯ŸçãšãªããŸããSPFãå®è£ ããããšã§ãçµç¹ã¯ãã£ãã·ã³ã°ã¡ãŒã«ãè¿·æã¡ãŒã«ãéä¿¡ããè åšã¢ã¯ã¿ãŒã«ãã£ãŠèªèº«ã®ãã¡ã€ã³ãæªçšãããã®ãé²ãããšãã§ããããã«ãã£ãŠã¡ãŒã«ã®é ä¿¡å°éæ§ãšå šäœçãªè©å€ãåäžãããããšãã§ããŸãã
ãµã€ããŒã»ãã¥ãªãã£æè²ãšãã¬ãŒãã³ã°ãå§ããŸããã
ç¡æãã©ã€ã¢ã«ã®ãç³ãèŸŒã¿æé
- åŒç€Ÿã®ãµã€ããŒã»ãã¥ãªã㣠ãšãã¹ããŒãã貎瀟ã«äŒºããã»ãã¥ãªãã£ç°å¢ãè©äŸ¡ããŠãè åšãªã¹ã¯ã蚺æããŸãã
- 24 æé以å ã«æå°éã®æ§æã§ã30 æ¥éãå©çšããã ãããã«ãŒããã€ã³ãã®ãœãªã¥ãŒã·ã§ã³ãå°å ¥ããŸãã
- ãã«ãŒããã€ã³ãã®ãã¯ãããžãŒãå®éã«ãäœéšããã ããŸãã
- çµç¹ãæã€ã»ãã¥ãªãã£ã®è匱æ§ã«é¢ããã¬ããŒãããæäŸããŸãããã®ã¬ããŒãã¯ããµã€ããŒã»ãã¥ãªãã£æ»æã®å¯Ÿå¿ã«çŽã¡ã«ã掻çšããã ãããšãã§ããŸãã
ãã©ãŒã ã«å¿ èŠäºé ããå ¥åã®äžããç³èŸŒã¿ãã ããã远ã£ãŠãæ åœè ãããé£çµ¡ãããŠããã ããŸãã
Proofpointã®æ åœè ããŸããªããé£çµ¡ããããŸãã
SPFã®ä»çµã¿
SPFã®æ žå¿ã¯ã·ã³ãã«ãªæè¡çããã»ã¹ã«ãããŸããåä¿¡ã¡ãŒã«ãµãŒããŒãããã¡ã€ã³ã®ç®¡çè ã«ãã£ãŠèªå¯ããããã¹ããšã¡ãŒã«ã®éä¿¡å ãç §åããæ¹æ³ãæããŸãããã¡ã€ã³ããŒã ã·ã¹ãã ïŒDNSïŒã¬ã³ãŒãã«ã¯ããã¡ã€ã³ã®èªå¯ãããéä¿¡ãã¹ããšIPã¢ãã¬ã¹ã®ãªã¹ããèšèŒãããŠããŸãã
ã¡ãŒã«ãåä¿¡ãããšãSPFãããã³ã«ã«ãããåä¿¡ãµãŒããŒã¯ç¹å®ã®ãã¡ã€ã³ããã®ã¡ãŒã«ã§ãããšäž»åŒµããã¡ãŒã«ããã®ãã¡ã€ã³ã®ææè ãèªå¯ãããã®ãã©ãããæ€èšŒã§ããŸããæ€èšŒããããšãã¡ãŒã«ã¯åãå ¥ããããŸããæ€èšŒã«å€±æããå Žåããã®ã¡ãŒã«ã¯ã¹ããŒãã£ã³ã°ãšèŠãªãããéåžžã¯ã¹ãã ãšããŠããŒã¯ããããæåŠãããŸãã
SPFã¯çµç¹ã®ã¡ãŒã«ã»ãã¥ãªãã£æ å¢ã广çã«æ¹åã§ããŸãããSPFåäœã§ã¯ååã§ã¯ãããŸãããSPFã¯ãDKIMãDMARCãªã©ã®ä»ã®æè¡ãšçµã¿åãããå€å±€çãªã¡ãŒã«ã»ãã¥ãªãã£ã¢ãããŒãã®äžéšã§ããã¹ãã§ãã
SPFã®éèŠæ§
SPFã¯ã¡ãŒã«ã»ãã¥ãªãã£ããŒã«ãšããŠéåžžã«éèŠãªåœ¹å²ãæãããŸããäžèœãªè§£æ±ºçã§ã¯ãããŸããããSPFã¯ä»¥äžã®ãããªå¹æããããŸãã
- ã¡ãŒã«ã¹ããŒãã£ã³ã°ã®é²æ¢: SPFã¯ãã¡ã€ã³ãã¹ããŒãã£ã³ã°ããä¿è·ããã¹ãã ãã£ã«ã¿ãŒãããªãã®ãã¡ã€ã³ããã©ãã¯ãªã¹ãã«èŒãããªã¹ã¯ã軜æžããŸãã
- ã¡ãŒã«é ä¿¡å°éæ§ã®åäž: SPFã«ãã£ãŠã¡ãŒã«ãæ€èšŒããããšã§ãã¹ãã ãšããŠæ±ãããå¯èœæ§ãæžå°ããé ä¿¡å°éæ§ãåäžããŸãã
- ãã¡ã€ã³ã®è©å€åäž: æå¹ãªSPFã¬ã³ãŒãã¯ãã€ã³ã¿ãŒããããµãŒãã¹ãããã€ããŒïŒISPïŒãã¡ãŒã«ã¯ã©ã€ã¢ã³ãã«ããããã¡ã€ã³ã®è©å€ãé«ããã¡ãŒã«ã®æ£åžžãªé ä¿¡ãä¿é²ããŸãã
- ãã£ãã·ã³ã°æ»æå¯Ÿç: SPFã¯ãè åšã¢ã¯ã¿ãŒãããªãã®ãã¡ã€ã³ããéä¿¡ãããããã«èŠããããŠã¡ãŒã«ãéãããšãé²ãããããã£ãã·ã³ã°ã¡ãŒã«ãšã®æŠãã«ãããŠéèŠã§ãã
- ã³ã³ãã©ã€ã¢ã³ã¹ã®ãµããŒã: ã¡ãŒã«ã³ãã¥ãã±ãŒã·ã§ã³ãèŠå¶ãããŠããæ¥çã§ã¯ãSPFã¬ã³ãŒãã¯ã¡ãŒã«ã³ãã¥ãã±ãŒã·ã§ã³ã®æ£åœæ§ã確ç«ããŠãã³ã³ãã©ã€ã¢ã³ã¹ã®ç¢ºä¿ãæ¯æŽããŸãã
SPFã¬ã³ãŒããšã¯ïŒ
SPFã¬ã³ãŒããšã¯ãããªãã®ãã¡ã€ã³ã«ä»£ãã£ãŠã¡ãŒã«ã®éä¿¡ãèš±å¯ãããŠããã¡ãŒã«ãµãŒããŒãèå¥ããDNSã¬ã³ãŒãã®äžçš®ã§ããSPFã¬ã³ãŒãã®ç®çã¯ãã¹ãããŒããã¡ã€ã³ã«é¢é£ã¥ããããã¡ãŒã«ã¢ã«ãŠã³ããåœé ããŠããFromãã¢ãã¬ã¹ã䜿çšããŠã¡ãã»ãŒãžãéä¿¡ããã®ãé²ãããšã§ãã
æè¡çã«ã¯ãSPFã¬ã³ãŒãã¯ãã¡ã€ã³ã®DNSã«ããããšã³ããªã§ããã®ãã¡ã€ã³ã®ã¡ãŒã«éä¿¡ãèš±å¯ãããIPã¢ãã¬ã¹ãšãã¹ãåãæå®ããŸããã¡ãŒã«ãåä¿¡ããéãã¡ãŒã«ãµãŒããŒã¯éä¿¡ãã¡ã€ã³ã®SPFã¬ã³ãŒãã確èªãããã®ã¡ãŒã«ãæ£åœãªãã®ã§ããããšã確èªã§ããŸããã¡ãŒã«ã®éä¿¡å ãèš±å¯ããããµãŒããŒã®ãªã¹ãã«å«ãŸããŠããã°ããã®ã¡ãã»ãŒãžã¯SPFãã§ãã¯ã«åæ ŒããŸããããã§ãªãå Žåãã¡ãŒã«ã®é ä¿¡ã¯å€±æããã¹ãã ãšããŠããŒã¯ããããæåŠãããŸãã
SPFã¬ã³ãŒããæã€ããšã¯ã¡ãŒã«èªèšŒã®éèŠãªéšåã§ããããã«ããã管çè ã¯ãã£ãã·ã³ã°ã¡ãŒã«ãæå³ããã被害è ã«å±ãã®ããããã¯ããããšãã§ããŸãã
SPFã¬ã³ãŒãã®å¿ èŠæ§
SPFã¬ã³ãŒãã¯ãçµç¹ã®å ¬åŒã¡ãŒã«ãµãŒããŒãšããžãã¹ã«ä»£ãã£ãŠã¡ãŒã«ãéä¿¡ã§ãããã¡ã€ã³ã®IPã¢ãã¬ã¹ãå«ãDNSãšã³ããªã§ããSPFã¬ã³ãŒãã¯ãã©ã®ã¡ãŒã«ãµãŒããŒããã¡ã€ã³ã®ã¡ãŒã«éä¿¡ãèš±å¯ãããŠããããæå®ããŠãã¡ãŒã«ãã¹ãã ãšããŠããŒã¯ãããå¯èœæ§ãæžå°ãããŸããããã¯ã¡ãŒã«ã®é ä¿¡å°éæ§ãåäžãããã¡ãŒã«ãåä¿¡è ã®åä¿¡ãã¬ã€ã«å±ããã¹ãã ãã©ã«ãã«æ¯ãåããããªãããã«ããŸãã
SPFã¬ã³ãŒããç¶æããããšã¯ããã¡ã€ã³ã®è©å€ãå®ãããã«äžå¯æ¬ ã§ããSPFã¬ã³ãŒãããªãããšãçç±ã§ãã¡ã€ã³ãã¹ãã éä¿¡ã«äœ¿çšãããå Žåãæ£åœãªã¡ãŒã«ããããã¯ãããããã¹ãã ãã©ã«ãã«å ¥ã£ãŠããŸã£ããããå¯èœæ§ãããããã¡ã€ã³ã®è©å€ãæãªãå¯èœæ§ããããŸãã
ãµãŒãããŒãã£ã®ã¡ãŒã«ã·ã¹ãã ïŒäŸïŒGoogle SuiteïŒã䜿çšããŠã¡ãŒã«ã管çããŠããå Žåãéä¿¡è ãããªãã®ããžãã¹ã«ä»£ãã£ãŠã¡ãã»ãŒãžãéä¿¡ããæš©éãããããšãåä¿¡ã¡ãŒã«ãµãŒããŒã«äŒããSPFã¬ã³ãŒããå¿ èŠã§ããSPFã¬ã³ãŒãããªãå Žåãåä¿¡è ã®ã¡ãŒã«ãµãŒããŒã¯ãã®ã¡ãã»ãŒãžããã£ãã·ã³ã°æ»æã®å¯èœæ§ããããšåä¿¡è ã«èŠåããå ŽåããããŸããäžéšã®ããžãã¹ã¡ãŒã«ãµãŒããŒã§ã¯ãã·ã¹ãã ãã¡ãã»ãŒãžãç Žæ£ããããçŽæ¥åä¿¡è ã®ã¹ãã åä¿¡ãã¬ã€ã«éä¿¡ããããããããåä¿¡è ããã®ã¡ãã»ãŒãžãåãåããªãå¯èœæ§ããããŸãã
å€ãã®åä¿¡è ã¯ã¹ãã ãã©ã«ãã®ã¡ãã»ãŒãžãèªãŸãªããããäŒæ¥ã¯é¡§å®¢ãæœåšçãªãªãŒããšã®ã³ãã¥ãã±ãŒã·ã§ã³ã«å°é£ãæ±ããããšã«ãªããŸãã倧æã®ã¡ãŒã«ã·ã¹ãã ã®å€ãã¯ãã§ã«SPFæ€åºãçµã¿èŸŒãã§ããããããã¹ãŠã®ãã¡ã€ã³ææè ã¯DNSãµãŒããŒã«ã¬ã³ãŒãã远å ããŠãã¡ãŒã«ã¡ãã»ãŒãžãåä¿¡è ã®åä¿¡ãã¬ã€ã«å±ãããã«ããæéãåãã¹ãã§ããGoogleãHotmailãYahooãªã©ã®å人åããµãŒãããŒãã£ã¡ãŒã«ã·ã¹ãã ã¯ãã§ã«SPFã¬ã³ãŒããçµã¿èŸŒãã§ãããããå人ã®ã¡ãŒã«ã¢ã«ãŠã³ãã«ã¬ã³ãŒãã远å ããå¿ èŠã¯ãããŸããã
SPFã¬ã³ãŒãã®ä»çµã¿
ãã¹ãŠã®ãã¡ã€ã³ã¯DNSãµãŒããŒã䜿çšããŠããããŠã§ããµãŒããŒã®IPã¢ãã¬ã¹ããŠãŒã¶ãŒããã©ãŠã¶ãŠã£ã³ããŠã«å ¥åãã䜿ãããããã¡ã€ã³åã«ãªã³ã¯ãããŠããŸããSPFã¬ã³ãŒãã¯ãã¡ãŒã«èªèšŒã«äœ¿çšãããDNSã¬ã³ãŒãã®äžçš®ã§ãã¡ãŒã«éä¿¡è ãç¹å®ã®ãã¡ã€ã³ã«ä»£ãã£ãŠã¡ãŒã«ãéä¿¡ããæš©éãããããšãæ€èšŒããŸãã以äžã¯ãSPFã¬ã³ãŒãã®ä»çµã¿ã®æŠèŠã§ãã
- èªå¯ããããµãŒããŒã®å®çŸ©: SPFã¬ã³ãŒãã«ã¯éåžžãIPã¢ãã¬ã¹ããã¡ã€ã³åãªã©ã®èå¥åãå«ãŸããŠããããããããã¡ã€ã³ã«ä»£ãã£ãŠã¡ãŒã«ãéä¿¡ããããšãèš±å¯ãããã¡ãŒã«ãµãŒããŒããã¡ã€ã³ãæç¢ºã«ç€ºããŸãã
- SPFã¬ã³ãŒãã®æ€èšŒ: ã¡ãŒã«ãå°çãããšãåä¿¡ãµãŒããŒã¯éä¿¡è ã®ãã¡ã€ã³ã«é¢é£ããSPFã¬ã³ãŒãã確èªããŸããéä¿¡ãµãŒããŒã®IPã¢ãã¬ã¹ãSPFã¬ã³ãŒãã®èš±å¯ãããã¢ãã¬ã¹ãšæ¯èŒããŸãã
- èªèšŒçµæ: SPFã¬ã³ãŒãã®ã«ãŒã«ã«åºã¥ããŠãåä¿¡ãµãŒããŒã¯ã¡ãŒã«ã®æ£åœæ§ã倿ããŸããçµæã¯ãåãå ¥ãããäžå¯©ãšããŠããŒã¯ãããããããã¯å®å šã«æåŠããããŸã§æ§ã ã§ãã
- äžæ£é²æ¢: SPFã䜿çšããããšã§ããã¡ã€ã³ææè ã¯ã¡ãŒã«ã¹ããŒãã£ã³ã°ããã£ãã·ã³ã°ãã身ãå®ããŸããããã«ãããèªåã®ãã¡ã€ã³ããã®ã¡ãŒã«ã ãšäž»åŒµããã¡ãŒã«ã確ãã«èªå¯ããããµãŒããŒããéä¿¡ãããŠããããšã確èªããäžæ£è¡çºã軜æžããŸãã
SPFã¬ã³ãŒããé©åã«æ©èœããã«ã¯ãç¹å®ã®ãã©ãŒããããšå€ãå¿ èŠã§ãããå€ãã®å Žåãã¡ã€ã³ç®¡çè ã«ããèšå®ã«äŸåããŸããSPFã¯ã¡ãŒã«èªèšŒã®äžèŠçŽ ã«éãããDKIMãDMARCãªã©ã®ä»ã®æšæºãšé£æºããŠæ©èœããŸãã
SPFã¬ã³ãŒãã®äŸïŒSoftFailãšHardFailïŒ
SPFã¬ã³ãŒãã«ã¯ãIPã¢ãã¬ã¹ä»¥å€ã®æ å ±ãå«ãŸããŠããŸããéä¿¡è ã®IPãèš±å¯ãããIPã¢ãã¬ã¹ã®ãªã¹ããšäžèŽããªãå Žåã«ãåä¿¡ãµãŒããŒãã©ã®ããã«å¯Ÿå¿ãã¹ãã«ã€ããŠã®æç€ºãå«ãŸããŠããŸããIPã¢ãã¬ã¹ã«ã¯IPv4ãšIPv6ããããããSPFã¬ã³ãŒãã§ã¯äž¡æ¹ã®ããŒãžã§ã³ãå®çŸ©ã§ããŸããåã¡ãŒã«ã¡ãã»ãŒãžã«ã¯2ã€ã®ãããããŒãããããŸããã¡ãŒã«ã¡ãã»ãŒãžã®äžéšã«è¡šç€ºãããå¯èŠããããŒãšãéè¡šç€ºã®æè¡çããããŒã§ããåããããŒã«ã¯ãfromãã¡ãŒã«ã¢ãã¬ã¹ãå«ãŸããŠããŸããå¯èŠããããŒã«è¡šç€ºããããã®ïŒãããããŒfromããŸãã¯ããã¬ã³ããªãŒfromããšãåŒã°ããïŒãšãã¡ãŒã«ã®éè¡šç€ºã®æè¡çããããŒã«å«ãŸããããšã³ãããŒãfromãã¢ãã¬ã¹ïŒReturn-PathãmfromãšããŠãç¥ãããïŒã§ãã以äžã¯åããããŒã®äŸã§ãã
ãŠãŒã¶ãŒã«è¡šç€ºãããããããŒïŒ

æè¡çãªé衚瀺ããããŒïŒ

SPFã¬ã³ãŒãã®å¥ã®äŸã¯ä»¥äžã§ãã
v=spf1 ip4:48.213.51.127 ip6:2a05:d018:e3:8c00:bb71:dea8:8b83:851e include:authorized-domain.com -all
SPFã¬ã³ãŒãã®ä»ã®å ·äœçãªäŸã«ã¯ä»¥äžããããŸãã
SoftFailïŒ ãã®äŸã§ã¯ãæå®ãããIPã¢ãã¬ã¹ããã®ã¡ãŒã«ãèš±å¯ããŸãããæœåšçã«äžå¯©ãªãã®ãšããŠããŒã¯ããŸãã
v=spf1 ip4:192.0.2.0/24 ~all
HardFailïŒ ãã®SPFã¬ã³ãŒãäŸã§ã¯ãæå®ãããIPã¢ãã¬ã¹ããã®ã¡ãŒã«ã®ã¿ãèš±å¯ããä»ã®ãã¹ãŠã®ã¡ãŒã«ãæåŠããŸãã
v=spf1 ip4:192.0.2.0/24 -all
ãªãã€ã¬ã¯ãã¡ã«ããºã ïŒ ãã®äŸã§ã¯ãå¥ã®ãã¡ã€ã³ã®SPFã¬ã³ãŒãã«ãªãã€ã¬ã¯ãããŸãã
v=spf1 redirect=_spf.example.com
äžèšã®SPFã¬ã³ãŒãã®åã³ã³ããŒãã³ããåè§£ãããšãæåã®ã³ã³ããŒãã³ãã§ãããv=spf1ãã¯ãSPFãšã³ããªã®ããŒãžã§ã³ã瀺ããŠããŸããããŒãžã§ã³ã¯ãä»ã®ãšããåžžã«SPF1ãšãªããåä¿¡è ã®ã¡ãŒã«ãµãŒããŒãSPFæ å ±ãæäŸããTXTã¬ã³ãŒããèå¥ããããã®æ¹æ³ãæäŸããŸãã
ãip4ããšãip6ãã®é ç®ã¯ãèš±å¯ãããã¡ãŒã«ãµãŒããŒã®IPv4ã¢ãã¬ã¹ãšIPv6ã¢ãã¬ã¹ã§ããè€æ°ã®IPã¢ãã¬ã¹ãèšèŒããå Žåã¯ãåIPã¢ãã¬ã¹ãã¹ããŒã¹ã§åºåããip4 ãŸã㯠ip6 ãšãããã¬ãã£ãã¯ã¹ãšã³ãã³ã䜿çšããŸããäŸãã°ã以äžã®SPFã¬ã³ãŒãã¯ã2ã€ã®IPv4ã¢ãã¬ã¹ãèªå¯ããããµãŒããŒãšããŠå®çŸ©ããŠããŸãã
v=spf1 ip4:48.213.51.127 ip4:31.217.43.153 ip6:2a05:d018:e3:8c00:bb71:dea8:8b83:851e include:authorized-domain.com -all
ãincludeããã£ã¬ã¯ãã£ãã¯ãå®çŸ©ããããµãŒãããŒãã£ãŒãã¡ã€ã³ãããªãã®çµç¹ã«ä»£ãã£ãŠã¡ãŒã«ãéä¿¡ã§ããããšã瀺ããŸããäŸãã°ããµãŒãããŒãã£ãããã€ããŒã䜿çšããŠãã«ã¯ããŒã±ãã£ã³ã°ã¡ãŒã«ãéä¿¡ãããšããŸãããã®ãµãŒãããŒãã£ã¡ãŒã«ãããã€ããŒãSPFã¬ã³ãŒãã«å«ããããšã§ãåä¿¡è ã®ã¡ãŒã«ãµãŒããŒãã¡ãã»ãŒãžãæåŠããããè¿·æã¡ãŒã«ãã©ã«ãã«å ¥ãããããããšããªããªããŸãã
æåŸã«ãã-allããã£ã¬ã¯ãã£ãã¯éèŠã§ãéä¿¡è ãèªå¯ãããIPã¢ãã¬ã¹ã䜿çšããŠããªãå Žåã«äœ¿çšããããªã·ãŒããåä¿¡è ãµãŒããŒã«æç€ºããŸããã-allããã£ã¬ã¯ãã£ãã¯ãåä¿¡è ãµãŒããŒã«ãã©ã°ããfailãã«èšå®ããããæç€ºããŸããä»ã«2ã€ã®ãªãã·ã§ã³ããããŸããã-allããã£ã¬ã¯ãã£ãã¯ãsoft failããšãªããåä¿¡è ã®åä¿¡ç®±ã«å±ããŸãããæªæã®ããã¡ãã»ãŒãžã§ããå¯èœæ§ããããšããèŠåãæ®ãããŸããã+allããã£ã¬ã¯ãã£ãã¯ãããããã»ãã¥ãªãã£å¶éãç¡èŠããŠãåä¿¡è ãµãŒããŒã«ã¡ãã»ãŒãžããpassãã«èšå®ããããæç€ºããŸããåŸè ã®èšå®ã¯ãå®å šã§ãªãããªã·ãŒãšã¿ãªããããããé¿ããå¿ èŠããããŸãã
SPFã¬ã³ãŒãã®èšå®æ¹æ³
SPFã¬ã³ãŒãã®äœææ¹æ³ã¯ãDNSãã¹ãã«ãã£ãŠç°ãªããŸãããã¡ã€ã³ç»é²æ¥è ã®DNSãµãŒããŒã䜿çšããŠããå Žåãéåžžãç»é²æ¥è ã¯DNSãšã³ããªã远å ããã³åé€ã§ããããã·ã¥ããŒããæäŸããŠããŸãããã®ããã·ã¥ããŒãã§SPFã¬ã³ãŒãã远å ããŸãã
SPFã¬ã³ãŒããäœæããæé ã¯ã以äžã®éãã§ãã
- ã¡ãŒã«ã®éä¿¡ã«äœ¿çšãããIPã¢ãã¬ã¹ãåéãã: ãã¡ã€ã³ããã¡ãŒã«ãéä¿¡ããããã«äœ¿çšãããã¹ãŠã®ã¡ãŒã«ãµãŒããŒãšãã®IPã¢ãã¬ã¹ã®ãªã¹ããäœæããŸãã
- SPFã¬ã³ãŒããäœæãã: åéããIPã¢ãã¬ã¹ã䜿çšããŠãã©ã®ãµãŒããŒãããªãã®ãã¡ã€ã³ã«ä»£ãã£ãŠã¡ãŒã«ãéä¿¡ããæš©éãããããæå®ããŸããSPFã¬ã³ãŒãã¯ããã®æ å ±ãå«ãDNS TXTã¬ã³ãŒãã§ãã
- SPFã¬ã³ãŒããDNSã«å ¬éãã: SPFã¬ã³ãŒããäœæãããããããDNSã«å ¬éããå¿ èŠããããŸããããã«ã¯ãDNS TXTã¬ã³ãŒãããã¡ã€ã³ãããã€ããŒã«è¿œå ããããšãå«ãŸããŸãã
- SPFã¬ã³ãŒãããã¹ããã: SPFã¬ã³ãŒããå ¬éããåŸãæ£ããèšå®ãããŠããããšã確èªããããã«ãã¹ãããŸããããã¯ããªã³ã©ã€ã³ã§å©çšå¯èœãªSPFã¬ã³ãŒããã¹ãããŒã«ã䜿çšããŠè¡ãããšãã§ããŸãã
SPFã¬ã³ãŒãã®äœæãç°¡çŽ åããã«ã¯ãSPFã¬ã³ãŒããžã§ãã¬ãŒã¿ãŒãå©çšã§ããŸãã
ã¡ãŒã«ãããã€ããŒããåä¿¡è ã«ã¡ãã»ãŒãžãéä¿¡ããããšã§ãæ°ãã倿Žç¹ããã¹ãããããšãã§ããŸããäŸãã°ãGoogle Suiteã䜿çšããŠããŠããã¡ã€ã³ã®SPFã¬ã³ãŒãã远å ããå Žåãããžãã¹ã¢ã«ãŠã³ãããå人ã¢ã«ãŠã³ãã«ã¡ãã»ãŒãžãéä¿¡ããŠãã¹ãããããšãã§ããŸããSPFã«ãã¯ã¢ããã®çµæã倿ããã«ã¯ãã¡ãŒã«ããããŒã確èªããå¿ èŠããããŸãã
äŸãã°ãGmailã®ããããŒã¯ãè¿ä¿¡ã¢ã€ã³ã³ã®æšªã«ãããã®ä»ã®ã¢ã€ã³ã³ãã¯ãªãã¯ãããã¡ãã»ãŒãžã®ãœãŒã¹ã衚瀺ãã¡ãã¥ãŒãªãã·ã§ã³ãã¯ãªãã¯ããããšã§è¡šç€ºã§ããŸããããããŒãŠã£ã³ããŠãéããããããŒã®äžéšã«SPFã«ãã¯ã¢ããã®çµæã衚瀺ãããŸããæ¬¡ã®ç»åã¯ãGmailã®äŸã§ãã

SPFã¬ã³ãŒãããã¹ããŠããããããã®ã¡ãã»ãŒãžã¯Gmailã§æ£åœãªã¡ãŒã«ãšã¿ãªãããåä¿¡è ã®åä¿¡ãã¬ã€ã«å±ããããšã«æ³šç®ããŠãã ãããSPFã«å€±æããã¬ã³ãŒãã¯ãè¿·æã¡ãŒã«ãã©ã«ãããæ¢ãããšãã§ããGmailãèŠåã¡ãã»ãŒãžã§ã©ãã«ä»ãããŠããããšã«æ°ã¥ãã§ãããã
ãã£ãã·ã³ã°æ»æãè åšã¢ã¯ã¿ãŒã«ãšã£ãŠäž»èŠãªææ®µã§ããç¶ãããããSPFã¬ã³ãŒãããã®ä»ã®ã¡ãŒã«ã»ãã¥ãªãã£ã¯ãæªæã®ããã¡ãã»ãŒãžãåä¿¡ããéã«ãŠãŒã¶ãŒã«èŠåãçºããã®ã«åœ¹ç«ã¡ãŸããSPFã¬ã³ãŒãã䜿çšãããšãæ»æè ã¯ããªãã®ãã¡ã€ã³ãå©çšããŠãçã£ã被害è ã«å¯ŸããŠãã£ãã·ã³ã°ãã£ã³ããŒã³ã仿ããããšãã§ããªããªããŸããããã«ãããããªãã®ããžãã¹ã®è©å€ãšããŠãŒã¶ãŒã被害è ã«ãªãããšãé²ãããšãã§ããŸãã
å€ãã®äŒæ¥ã¯ãåŸæ¥å¡ãæ¶è²»è ã察象ãšããé»åã¡ãŒã«è©æ¬ºã®ãã¬ãŒãã³ã°ã«æè³ããŠããŸãããããããã®ãããªæè³ã«ãããããããBECïŒBusiness Email CompromiseïŒ: ä¿¡é Œã§ããäŒæ¥ã®IDã«ãªãããŸããåŸæ¥å¡ãéšããé«åºŠãªæšçåãã€å°éã®æ»æãã¯ã¬ãã³ã·ã£ã«ãã£ãã·ã³ã°è©æ¬ºã«éšããã人ãåŸãçµ¶ã¡ãŸããããããŠããããã®æ»æã¯å¹æçã§ãããã©ã€ãŸã³ã«ãããšããã£ãã·ã³ã°ã¡ãŒã«ã®30%ã¯æšçãšãªã£ããŠãŒã¶ãŒãéå°ãããã®ãã¡ã®12%ã¯æªæã®ããæ·»ä»ãã¡ã€ã«ãã¯ãªãã¯ããŠããŸãã
ãªãããŸãã¡ãŒã«ã«å¯Ÿããé²åŸ¡ã¯ã人ã§ã¯ãªããã¡ãŒã«èªèšŒãåžžã«ç¬¬äžç·ã§ããã¹ãã§ããSPFã¯ãåä¿¡ç®±ã«å±ãåã«æªè³ªãªã¡ãã»ãŒãžãèå¥ããŠãããã¯ããããšã§ãæšçãšãªãåä¿¡è ã®åœãŠæšéãæé€ããŸããããããSPFã ãã§ã¯ãåŸæ¥å¡ã顧客ãçã£ããã£ãã·ã³ã°ã¡ãŒã«ããããã¯ããã«ã¯ååã§ã¯ãããŸãããããã«ã¯ããã€ãã®å€§ããªèª²é¡ããããŸãã
- 粟床: ããªãã®ãã©ã³ãã«ä»£ãã£ãŠã¡ãŒã«ãéä¿¡ãããã³ããŒã¯ãé »ç¹ã«å€æŽãããæ°ãå¢ããŸãã ãããã®å€æŽããªã¢ã«ã¿ã€ã ã§ææ¡ã§ããªããã°ã SPFã¬ã³ãŒãã¯å€ããªã£ãŠããŸããŸãã
- èæ§: SPFã¯ãã¡ãŒã«ãããã€ããŒãé ä¿¡ã®å€æã«äœ¿çšãã倿°ã®ã·ã°ãã«ã®ã²ãšã€ã§ãã SPFã倱æãããšããŠããã¡ãŒã«ããããã¯ãããããšãä¿èšŒããããã§ã¯ãããŸããã
- å 責: ã¡ãŒã«ã転éããããšãSPFã¬ã³ãŒãã¯å£ããŠããŸããŸãã
- ä¿è·: SPFã¯ããŠãŒã¶ãŒãã¡ãŒã«ã¯ã©ã€ã¢ã³ãã«è¡šç€ºããããããããŒfromãã¢ãã¬ã¹ãè©ç§°ããä¿è·ãããã®ã§ã¯ãããŸããããµã€ããŒç¯çœªè ã¯ããšã³ãããŒãfromãã¢ãã¬ã¹ã«ææããŠãããã¡ã€ã³ãå«ããããšã§SPFãééããããšãã§ããç®ã«èŠããFromã¢ãã¬ã¹ã«æ£èŠã®ãã©ã³ãã®ãã¡ã€ã³ãåœè£ ããããšãã§ããŸãã
幞ãã«ããä»ã®ã¡ãŒã«èªèšŒæè¡ã§ãããã£ãæ¬ ç¹ãè£ãããšãã§ããŸãã
SPFã®å¶é
SPFã¯ã¡ãŒã«èªèšŒã«ãããŠéèŠãªããŒã«ã§ããããã®å¶éãçè§£ããããšãåæ§ã«éèŠã§ãã
- DNSã«ãã¯ã¢ããã®å¶é: SPF仿§ã§ã¯ãSPFã¬ã³ãŒããå®å šã«è§£æ±ºããããã®DNSã«ãã¯ã¢ããåæ°ã10åã«å¶éããŠããŸãããã®å¶éã¯ãµãŒãã¹æåŠïŒDoSïŒæ»æãé²ãããã®ãã®ã§ãããincludeã¢ãã£ãã¡ã€ã¢ãç¡åå¥ã«äœ¿çšãããŠãŒã¶ãŒã«åé¡ãåŒãèµ·ããå¯èœæ§ããããŸãã
- æåæ°ã®å¶é: SPFã¬ã³ãŒãã«ã¯ãåäžã®æååã«255æåã®å¶éããããŸããããã¯DNS TXTã¬ã³ãŒãã®åºæã®å¶éã§ãã
- äžå®å šãªè§£æ±ºç: SPFã¯å®å šãªãšã³ãããŒãšã³ãã®æå·åãæäŸãããé¡äŒŒãã¡ã€ã³ã䜿çšãããã£ãã·ã³ã°æ»æãããä¿è·ããŸããããã®ãããSPFã¯ããå æ¬çãªã¡ãŒã«èªèšŒãœãªã¥ãŒã·ã§ã³ã®äžéšã«éããŸããã
- SPFã¬ã³ãŒãã®ç¶æãå°é£: SPFã¬ã³ãŒãã®ç¶æã¯ãç¹ã«è€éãªã¡ãŒã«ã€ã³ãã©ãæã€çµç¹ã«ãšã£ãŠå°é£ãªå ŽåããããŸããçµç¹ãããå€ãã®ã¡ãŒã«ãµãŒããŒããµãŒãããŒãã£ã®ã¡ãŒã«ãµãŒãã¹ã远å ãããšãSPFã¬ã³ãŒããææ°ã®ç¶æ ã«ä¿ã€ããšãé£ãããªãå¯èœæ§ããããŸãã
- äžé©åãªã¡ãŒã«è»¢éã«ããSPFèªèšŒã®ç Žå£ã®å¯èœæ§: äžé©åãªã¡ãŒã«è»¢éã¯SPFèªèšŒãç Žå£ããå¯èœæ§ããããŸããã¡ãŒã«ãSPFã¬ã³ãŒãã§èš±å¯ãããŠããªããµãŒããŒãéããŠè»¢éãããå Žåããã®ã¡ãŒã«ã¯SPFèªèšŒã«å€±æããå¯èœæ§ããããŸãã
- å€§èŠæš¡çµç¹ã§ã¯è€æ°ã®SPFã¬ã³ãŒããå¿ èŠãªå Žåããã: è€æ°ã®ãã¡ã€ã³ãæã€å€§èŠæš¡çµç¹ã§ã¯ãè€æ°ã®SPFã¬ã³ãŒããå¿ èŠãšãªãã管çãå°é£ã«ãªãå ŽåããããŸãã
ãããã®å¶éã«ãããããããSPFã¯äŸç¶ãšããŠã¡ãŒã«ã¹ããŒãã£ã³ã°ããã£ãã·ã³ã°æ»æãé²ãã®ã«åœ¹ç«ã€äžå¯æ¬ ãªã»ãã¥ãªãã£ãããã³ã«ã§ãã
SPFã«å¯ŸããProofpointã®ãœãªã¥ãŒã·ã§ã³
ãŸãå§ãã«ãProofpointã®DMARCäœæããŒã«ã詊ããŠã¿ãŠãã ãããããã¯çµç¹ããã¡ã€ã³ã®DMARCã¬ã³ãŒããäœæããã®ãæ¯æŽããç¡æã®ãªã³ã©ã€ã³ããŒã«ã§ãããã®ããŒã«ã§ã¯ããã¡ã€ã³ã®DMARCã¬ã³ãŒããšSPFã¬ã³ãŒãã確èªã§ããŸãã
ãã®ããŒã«ã¯Proofpointã®Email Fraud DefenseïŒã¡ãŒã«è©æ¬ºé²åŸ¡ïŒã®äžéšã§ãSPFãšDMARCããµããŒãããå æ¬çãªã¡ãŒã«ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã§ããã¡ãŒã«ã¹ããŒãã£ã³ã°ããã£ãã·ã³ã°ãªã©ã®ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°æ»æããä¿è·ããŸãããã¡ã€ã³ã®DMARCãšSPFã¬ã³ãŒãã確èªããŠãæ£åœãªéä¿¡è ãç¹å®ããé©åã«èªèšŒãããŠããããšã確èªããããã»ã¹ãåçåããŠããŸãã
Email Fraud Defenseã¯ã誰ãããªãã®ãã¡ã€ã³ã«ä»£ãã£ãŠã¡ãŒã«ãéä¿¡ããŠããããå¯èŠåããæ£åœãªéä¿¡è ãæ¿èªããæªæ¿èªã®ã¡ãã»ãŒãžããããã¯ããããšãã§ããŸããçŽæçãªã¬ããŒãã£ã³ã°ããŒã¿ã«ãéããŠã¢ã¯ãã£ããã£ã確èªããProofpointã®ã³ã³ãµã«ã¿ã³ããšã®å®æçãªäŒè°ã掻çšããŠãã¡ãŒã«ã»ãã¥ãªãã£æ å¢ã匷åã§ããŸãã