{"id":1344,"date":"2018-01-05T15:23:22","date_gmt":"2018-01-05T13:23:22","guid":{"rendered":"https:\/\/hosterion.ro\/blog\/?p=1344"},"modified":"2018-01-09T09:27:08","modified_gmt":"2018-01-09T07:27:08","slug":"dmarc","status":"publish","type":"post","link":"https:\/\/hosterion.ro\/blog\/dmarc","title":{"rendered":"DMARC: de ce \u0219i cum s\u0103 \u00eel activezi pentru domeniul t\u0103u"},"content":{"rendered":"<p>Ai c\u00e2\u0219tigat o vacan\u021b\u0103 extravagant\u0103, chiar dac\u0103 tu nu te-ai \u00eenscris la extragere. Contul t\u0103u bancar a fost compromis \u0219i trebuie s\u0103 intri pe o pagin\u0103 indicat\u0103 \u00een email, ca s\u0103 \u00ee\u021bi po\u021bi securiza datele.<\/p>\n<p>Dac\u0103 folose\u0219ti servicii de mail, este imposibil s\u0103 nu fi primit cel pu\u021bin o dat\u0103 emailuri de tip phishing sau spam.<\/p>\n<p>Ast\u0103zi, \u00ee\u021bi prezint cum \u00ee\u021bi po\u021bi proteja baza de clien\u021bi \u00eempotriva persoanelor care \u00eencearc\u0103 s\u0103 trimit\u0103 mesaje \u00een numele t\u0103u.<\/p>\n<p><!--more--><\/p>\n<p><strong>1. Ce este DMARC?<\/strong><br \/>\n<strong> 2 Ce tipuri de politici folose\u0219te DMARC?<\/strong><br \/>\n<strong> 3. De ce este important? Ce tipuri de emailuri combate ?<\/strong><br \/>\n<strong> 3.1. Pe scurt, \u0219i \u00een termeni non-tehnici, cum func\u021bioneaz\u0103?<\/strong><br \/>\n<strong> 4. Cum poti activa DMARC pentru contul t\u0103u de g\u0103zduire?<\/strong><br \/>\n<strong> 5. Cum po\u021bi verifica dac\u0103 ai setat corect DMARC?<\/strong><\/p>\n<h2 style=\"text-align: center;\">1. Ce este DMARC?<\/h2>\n<p><strong>DMARC<\/strong> = acronim pentru Domain based message authentication, reporting and conformance.<br \/>\n<strong>Authetication<\/strong> = are la baz\u0103 dou\u0103 metode de autentificare, \u0219i anume SPF (sender policy framework) \u0219i DKIM (DomainKeys Identified Mail)<br \/>\n<strong>Reporting<\/strong> = ob\u021bine vizibilitate pentru emailurile respinse<br \/>\n<strong>Conformance<\/strong> = standardizeaz\u0103 modul \u00een care se gestioneaz\u0103 emailurile respinse prin aplicarea unor politici flexibile, \u0219i anume: <em>none<\/em>, <em>quarantine<\/em> sau <em>reject<\/em>.<\/p>\n<p>DMARC este un protocol de autentificare \u0219i raportare a emailurilor care \u00ee\u021bi protejeaz\u0103 domeniul din a fi folosit pentru trimiterea de mesaje de tip spam sau phishing.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1446 size-full\" src=\"https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2018\/01\/dmarc-ok_rev.png\" alt=\"dmarc\" width=\"946\" height=\"327\" srcset=\"https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2018\/01\/dmarc-ok_rev.png 946w, https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2018\/01\/dmarc-ok_rev-300x104.png 300w, https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2018\/01\/dmarc-ok_rev-768x265.png 768w, https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2018\/01\/dmarc-ok_rev-900x311.png 900w\" sizes=\"auto, (max-width: 946px) 100vw, 946px\" \/><\/p>\n<p>DMARC de asemenea \u00ee\u021bi \u00eembun\u0103t\u0103\u021be\u0219te rata de trimitere a mailurilor \u0219i \u00ee\u021bi scade \u0219ansa de a avea domeniul blacklistat.<\/p>\n<h2 style=\"text-align: center;\">2. <strong>Ce tipuri de politici folose\u0219te DMARC?<\/strong><\/h2>\n<p>\u00cen primul r\u00e2nd, o s\u0103 discut\u0103m despre ce \u00eenseamn\u0103 o politic\u0103 DMARC.<\/p>\n<p>O politic\u0103 DMARC le spune prestatorilor de servicii de email (de ex: Google, Yahoo, Outlook, etc.) \u0219i altor furnizori de servicii de internet care au adoptat DMARC, cum s\u0103 gestioneze emailurile care e\u0219ueaz\u0103 aceast\u0103 verificare.<\/p>\n<p>\u00cen total avem 3 tipuri de politici:<br \/>\n&#8211; <strong>NONE:<\/strong> Toate emailurile vor fi expediate. Vei putea analiza raporturile DMARC pentru a g\u0103si persoana care trimite emailuri \u00een numele t\u0103u. Ulterior, po\u021bi trece la urm\u0103toarea politic\u0103, \u0219i anume Quarantine.<br \/>\n&#8211; <strong>QUARANTINE:<\/strong> Dac\u0103 folose\u0219ti aceast\u0103 politic\u0103, toate emailurile care e\u0219ueaz\u0103 validarea DMARC vor fi marcate ca \u0219i spam, \u0219i vor fi filtrate automat de serverul destina\u021bie (de obicei ajung \u00een folderul SPAM\/JUNK).<br \/>\n&#8211; <strong>REJECT:<\/strong> Prin folosirea acestei politici, anun\u021bi serverul destina\u021bie c\u0103 \u00een cazul \u00een care DMARC e\u0219ueaz\u0103, s\u0103 resping\u0103 emailul, f\u0103r\u0103 a mai fi filtrat. Dac\u0103 vei folosi aceast\u0103 metod\u0103, nimeni nu va putea s\u0103 trimit\u0103 emailuri \u00een numele t\u0103u.<br \/>\nEste foarte important s\u0103 te asiguri c\u0103 totul este \u00een regul\u0103 \u00een set\u0103rile tale (SPF \u0219i DKIM). Altfel, po\u021bi ajunge \u00een situa\u021bia \u00een care \u0219i emailurile legitime s\u0103 fie respinse de serverul destina\u021bie.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1445 size-full\" src=\"https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2018\/01\/dmarc_policy_rev.png\" alt=\"dmarc\" width=\"1421\" height=\"380\" srcset=\"https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2018\/01\/dmarc_policy_rev.png 1421w, https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2018\/01\/dmarc_policy_rev-300x80.png 300w, https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2018\/01\/dmarc_policy_rev-768x205.png 768w, https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2018\/01\/dmarc_policy_rev-1024x274.png 1024w, https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2018\/01\/dmarc_policy_rev-900x241.png 900w, https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2018\/01\/dmarc_policy_rev-1280x342.png 1280w\" sizes=\"auto, (max-width: 1421px) 100vw, 1421px\" \/><\/p>\n<h2 style=\"text-align: center;\">3. <strong>De ce este important? Ce tipuri de mailuri combate ?<\/strong><\/h2>\n<p>\u0218tiai c\u0103\u00a0 aproximativ 60% din volumul global de emailuri trimise sunt emailuri de tip SPAM sau PHISHING?<\/p>\n<div id=\"attachment_1403\" style=\"width: 1130px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-1403\" class=\"wp-image-1403 size-full\" src=\"https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2017\/12\/Spam_world_EN.png\" alt=\"DMARC spam\" width=\"1120\" height=\"736\" srcset=\"https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2017\/12\/Spam_world_EN.png 1120w, https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2017\/12\/Spam_world_EN-300x197.png 300w, https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2017\/12\/Spam_world_EN-768x505.png 768w, https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2017\/12\/Spam_world_EN-1024x673.png 1024w, https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2017\/12\/Spam_world_EN-900x591.png 900w\" sizes=\"auto, (max-width: 1120px) 100vw, 1120px\" \/><p id=\"caption-attachment-1403\" class=\"wp-caption-text\">Procentaje mailuri de tip SPAM din volumul global de mailuri trmise in Q2 si Q3 2017<\/p><\/div>\n<p>Pe l\u00e2ng\u0103 emailurile legitime trimise de tine, este foarte posibil ca cineva de asemenea s\u0103 trimit\u0103 mesaje email cu expeditor falsificat. Persoanele r\u0103u inten\u021bionate \u00ee\u0219i pot masca identitatea \u0219i pot trimite emailuri de tip phishing sau spam, \u00een numele t\u0103u.<\/p>\n<p>Ambele emailuri vor fi expediate, dar \u00een cazul \u00een care ai activ DMARC, doar emailurile legitime vor ajunge la destina\u021bie.<\/p>\n<p>Conform unui studiu recent realizat de Kaspersky Labs, top 3 branduri care au fost \u021binta atacurilor de tip phishing sunt Facebook, Microsoft si Yahoo!:<\/p>\n<table>\n<tbody>\n<tr>\n<td>Facebook<\/td>\n<td>7.96<\/td>\n<\/tr>\n<tr>\n<td>Microsoft Corporation<\/td>\n<td>7.79<\/td>\n<\/tr>\n<tr>\n<td>Yahoo!<\/td>\n<td>4.79<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>De asemenea, conform rapoartelor emise de Kaspersky Labs, top 3 \u021b\u0103ri afectate de phishing sunt:<\/p>\n<table>\n<tbody>\n<tr>\n<td>Brazilia<\/td>\n<td>19.95%<\/td>\n<\/tr>\n<tr>\n<td>Australia<\/td>\n<td>16.51%<\/td>\n<\/tr>\n<tr>\n<td>Noua Zeeland\u0103<\/td>\n<td>15.61%<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div id=\"attachment_1406\" style=\"width: 1130px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-1406\" class=\"wp-image-1406 size-full\" src=\"https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2017\/12\/Q3_Phishing_map.png\" alt=\"dmarc phishing\" width=\"1120\" height=\"876\" srcset=\"https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2017\/12\/Q3_Phishing_map.png 1120w, https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2017\/12\/Q3_Phishing_map-300x235.png 300w, https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2017\/12\/Q3_Phishing_map-768x601.png 768w, https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2017\/12\/Q3_Phishing_map-1024x801.png 1024w, https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2017\/12\/Q3_Phishing_map-900x704.png 900w\" sizes=\"auto, (max-width: 1120px) 100vw, 1120px\" \/><p id=\"caption-attachment-1406\" class=\"wp-caption-text\">Atacuri de tip phishing \u00een Q3 2017<\/p><\/div>\n<p>DMARC abordeaz\u0103 aceste probleme, ajut\u00e2nd expeditorii \u0219i destinatarii s\u0103 colaboreze pentru a proteja mai eficient emailurile, protej\u00e2nd utilizatorii de abuzuri dureroase \u0219i costisitoare.<\/p>\n<h2 style=\"text-align: center;\"><strong>3.1. Pe scurt \u0219i \u00een termeni non-tehnici, cum func\u021bioneaz\u0103?<\/strong><\/h2>\n<p>DMARC permite expeditorului s\u0103 precizeze c\u0103 mesajele sunt protejate de SPF si DKIM \u0219i ii spune destinatarului cum s\u0103 gestioneze aceste mesaje \u00een cazul \u00een care una din verific\u0103ri e\u0219ueaz\u0103.<br \/>\nDe asemenea, DMARC ofer\u0103 o metod\u0103 de a primi raporturi referitoare la mesajele care nu sunt validate de serverul destinatie.<\/p>\n<h2 style=\"text-align: center;\"><strong>4. Cum po\u021bi activa DMARC pentru contul t\u0103u de g\u0103zduire?<\/strong><\/h2>\n<p>Primul pas ar fi s\u0103 te autentifici \u00een cPanel.<br \/>\nAccesezi Advanced Zone Editor.<br \/>\nSelectezi domeniul t\u0103u.<br \/>\nSelectezi &#8222;Add a record&#8221; \u0219i completezi c\u00e2mpurile urm\u0103toare:<br \/>\nName: <em>_dmarc<\/em><br \/>\nTTL: <em>14400<\/em><br \/>\nType: <em>TXT<\/em><\/p>\n<p>Datele din acest c\u00e2mp trebuiesc configurate dup\u0103 cum dore\u0219ti ca serverele destina\u021bie s\u0103 gestioneze emailurile care nu reu\u0219e\u0219c validarea SPF \/ DKIM. Mai jos g\u0103se\u0219ti posibilele op\u021biuni:<\/p>\n<p><strong>None:<\/strong> <em>v=DMARC1; p=none; sp=none; rf=afrf; pct=100; ri=86400<\/em><br \/>\n<strong>Reject:<\/strong><em> v=DMARC1; p=reject; sp=none; rf=afrf; pct=100; ri=86400<\/em><br \/>\n<strong>Quarantine:<\/strong> <em>v=DMARC1; p=quarantine; sp=none; rf=afrf; pct=100; ri=86400<\/em><\/p>\n<p>\u00cen plus, se poate ad\u0103uga o op\u021biune prin care \u021bi se trimite \u0219i un raport \u00een cazul \u00een care un email nu reu\u0219e\u0219te validarea SPF \u0219i DKIM:<\/p>\n<p><strong>None:<\/strong> <em>v=DMARC1; p=none; sp=none; ruf=mailto:user@example.com; rf=afrf; pct=100; ri=86400<\/em><\/p>\n<p><strong>Reject:<\/strong> <em>v=DMARC1; p=reject; sp=none; rf=afrf; pct=100; ruf=mailto:user@example.com; ri=86400<\/em><\/p>\n<p><strong>Quarantine:<\/strong><em> v=DMARC1; p=quarantine; sp=none; ruf=mailto:user@example.com; rf=afrf; pct=100; ri=86400<\/em><\/p>\n<p>*user@example.com este adresa unde se vor trimite raporturile<\/p>\n<h2 style=\"text-align: center;\"><strong>5. Cum po\u021bi verifica dac\u0103 ai setat corect DMARC?<\/strong><\/h2>\n<p style=\"text-align: left;\">Dupa ce ai terminat cu set\u0103rile din contul t\u0103u de g\u0103zduire web, trebuie s\u0103 \u0219i verifici dac\u0103 DMARC-ul func\u021bioneaz\u0103 corespunz\u0103tor.<\/p>\n<p style=\"text-align: left;\">Cea mai simpl\u0103 verificare se face acces\u00e2nd\u00a0<a href=\"https:\/\/mxtoolbox.com\/dmarc.aspx\">MXToolbox<\/a>.<\/p>\n<p style=\"text-align: left;\">Adi\u021bional, se poate face \u0219i o interogare a zonei DNS urm\u0103rind pa\u0219ii de mai jos:<br \/>\n<strong>Windows:<\/strong><br \/>\nDin cmd, se porne\u0219te nslookup:<br \/>\n<strong>nslookup<\/strong><br \/>\nSe seteaz\u0103 tipul recordului:<br \/>\n<strong>set type=TXT<\/strong><br \/>\nSe interogheaz\u0103 recordul dmarc:<br \/>\n<strong>_dmarc.domain.tld<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1350 size-full\" src=\"https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2017\/12\/dmarc_google.png\" alt=\"\" width=\"623\" height=\"189\" srcset=\"https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2017\/12\/dmarc_google.png 623w, https:\/\/hosterion.ro\/blog\/wp-content\/uploads\/2017\/12\/dmarc_google-300x91.png 300w\" sizes=\"auto, (max-width: 623px) 100vw, 623px\" \/><\/p>\n<p>Pentru linux se poate folosi direct comanda:<br \/>\n<strong>dig txt _dmarc.domain.tld +short<\/strong><br \/>\ndig txt _dmarc.google.ro +short<br \/>\n<em>&#8222;v=DMARC1\\; p=reject\\; rua=mailto:mailauth-reports@google.com&#8221;<\/em><\/p>\n<p>*unde domain.tld este domeniul t\u0103u<\/p>\n<p>\u00cen cazul \u00een care g\u0103se\u0219ti acest subiect interesant, nu ezita s\u0103 ne la\u0219i un comentariu cu opinia ta. Dac\u0103 ai \u00eentreb\u0103ri sau complet\u0103ri legate de DMARC,\u00a0 de asemenea te \u00eendemn\u0103m s\u0103 le \u00eemp\u0103rt\u0103\u0219e\u0219ti cu noi.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ai c\u00e2\u0219tigat o vacan\u021b\u0103 extravagant\u0103, chiar dac\u0103 tu nu te-ai \u00eenscris la extragere. Contul t\u0103u bancar a fost compromis \u0219i trebuie s\u0103 intri pe o pagin\u0103 indicat\u0103 \u00een email, ca s\u0103 \u00ee\u021bi po\u021bi securiza datele. Dac\u0103 folose\u0219ti servicii de mail, este imposibil s\u0103 nu fi primit cel pu\u021bin o dat\u0103 emailuri de tip phishing sau [&hellip;]<\/p>\n","protected":false},"author":10,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18,82,7],"tags":[202,105],"class_list":["post-1344","post","type-post","status-publish","format-standard","hentry","category-domenii","category-securitate","category-web-hosting","tag-dmarc","tag-domeniu-internet"],"_links":{"self":[{"href":"https:\/\/hosterion.ro\/blog\/wp-json\/wp\/v2\/posts\/1344","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hosterion.ro\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hosterion.ro\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hosterion.ro\/blog\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/hosterion.ro\/blog\/wp-json\/wp\/v2\/comments?post=1344"}],"version-history":[{"count":66,"href":"https:\/\/hosterion.ro\/blog\/wp-json\/wp\/v2\/posts\/1344\/revisions"}],"predecessor-version":[{"id":1459,"href":"https:\/\/hosterion.ro\/blog\/wp-json\/wp\/v2\/posts\/1344\/revisions\/1459"}],"wp:attachment":[{"href":"https:\/\/hosterion.ro\/blog\/wp-json\/wp\/v2\/media?parent=1344"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hosterion.ro\/blog\/wp-json\/wp\/v2\/categories?post=1344"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hosterion.ro\/blog\/wp-json\/wp\/v2\/tags?post=1344"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}