各位好:
小弟今天收到來自Google的DMARC report
資料如下:
<?xml version="1.0" encoding="UTF-8" ?>
<feedback>
<report_metadata>
<org_name>google.com</org_name>
<email>noreply-dmarc-support@google.com</email>
<extra_contact_info>https://support.google.com/a/answer/2466580</extra_contact_info>
<report_id>95183953529110717</report_id>
<date_range>
<begin>1593907200</begin>
<end>1593993599</end>
</date_range>
</report_metadata>
<policy_published>
<domain>example.com</domain>
<adkim>r</adkim>
<aspf>r</aspf>
<p>quarantine</p>
<sp>quarantine</sp>
<pct>50</pct>
</policy_published>
<record>
<row>
<source_ip>209.85.220.65</source_ip>
<count>1</count>
<policy_evaluated>
<disposition>none</disposition>
<dkim>pass</dkim>
<spf>fail</spf>
</policy_evaluated>
</row>
<identifiers>
<header_from>example.com</header_from>
</identifiers>
<auth_results>
<dkim>
<domain>example.com</domain>
<result>pass</result>
<selector>key</selector>
</dkim>
<spf>
<domain>gmail.com</domain>
<result>pass</result>
</spf>
</auth_results>
</record>
<record>
<row>
<source_ip>209.85.220.41</source_ip>
<count>1</count>
<policy_evaluated>
<disposition>none</disposition>
<dkim>pass</dkim>
<spf>fail</spf>
</policy_evaluated>
</row>
<identifiers>
<header_from>example.com</header_from>
</identifiers>
<auth_results>
<dkim>
<domain>example.com</domain>
<result>pass</result>
<selector>key</selector>
</dkim>
<spf>
<domain>gmail.com</domain>
<result>pass</result>
</spf>
</auth_results>
</record>
</feedback>
DNS dmarc 政策:
type | name | content | TTL |
---|---|---|---|
TXT | example.com | v=spf1 include:spf.improvmx.com ~all | auto |
SPF | example.com | v=spf1 include:spf.improvmx.com ~all | auto |
TXT | _ dmarc | v=DMARC1; p=quarantine; pct=50; rua=mailto:dmarc@example.com; ruf=mailto:dmarc@example.com; fo=1; | auto |
其中,SPF Alignment均為failed 想請問原因及是否有影響?
註:Gmail -> show original均正常
這裡有解釋 fail 可能的成因, 要看你是哪一種狀況:
When SPF or DKIM alignment fails
可以選DMARC check,它會顯示問題在那裡
https://www.proofpoint.com/us/cybersecurity-tools/dmarc-spf-creation-wizard