After implementing email authentication for my domain, I started receiving DMARC reports. These reports contain vital information about email authentication status and potential security issues. This article examines the contents of these reports and discusses the importance of email security enhancement.
Analyzing DMARC Reports: Unexpected Discoveries
Despite sending only 1-2 emails per week, I received DMARC reports at a higher frequency. Here's an analysis of one such report:
Report Analysis
Report Metadata:
- Organization: docomo.ne.jp
- Report ID: 0fa82be0508dfbf0734d46e8472e525e
- Date Range: September 26-27, 2024
Published Policy:
- Domain: aqz.jp
- DKIM Configuration: s (strict)
- SPF Configuration: r (relaxed)
- DMARC Policy: none
- Policy Application Rate: 100%
Identified Issues:
- Multiple IP addresses sending emails (e.g., 49.72.81.163, 49.64.241.80)
- DKIM and SPF failures across all records
- SPF results showing "permerror" (permanent error)
Evaluation Results:
- All messages show disposition as "none" due to DMARC policy settings
- No actual restrictions applied due to "none" policy
Investigation of Spoofing Attempts
Further investigation of the source IPs revealed concerning patterns:
IP Analysis Results
- Network Attribution: China Telecom network
- Geographic Location: Jiangsu Province, China
- Network Range: 49.64.0.0 - 49.95.255.255
- Contact Information:
- Abuse Contact:
↗ Original-Artikel auf dev.to lesenVollständiger Original-BerichtAusführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf dev.to.
SOCIAL SHARE CARD GENERATOR