2017-02-23 219 views
0

我们为我们的域配置了SPF,DKIM和DMARC记录,并且它们工作正常。我们的Gmail,Hotmail,Yahoo的DMARC报告也证实了这一点。Gmail上的DMARC行为

但是,就在上周,我们的一位(Gmail)用户将我们的域名上伪造的电子邮件地址发送的欺诈电子邮件发送给我们。

在查看电子邮件标题后,我们意识到Gmail并未发起任何DMARC检查,并且电子邮件登录在用户的收件箱中。 Gmail只执行了一次SPF检查,因为检查是在信封FROM标头域上执行的。

电子邮件标头(带有识别删节细节)看起来像以下:

Delivered-To: [email protected] 
Received: by 10.28.167.23 with SMTP id q23csp326872wme; 
     Mon, 20 Feb 2017 23:53:04 -0800 (PST) 
X-Received: by 10.36.147.1 with SMTP id y1mr22192213itd.34.1487663583976; 
     Mon, 20 Feb 2017 23:53:03 -0800 (PST) 
Return-Path: <[email protected]> 
Received: from server2.fraudulentdomain.net (server2.fraudulentdomain.net. [144.X.Y.Z]) 
     by mx.google.com with ESMTP id i196si19658513ioi.78.2017.02.20.23.53.03 
     for <[email protected]>; 
     Mon, 20 Feb 2017 23:53:03 -0800 (PST) 
Received-SPF: pass (google.com: domain of [email protected] designates 144.X.Y.Z as permitted sender) client-ip=144.X.Y.Z; 
Authentication-Results: mx.google.com; 
     spf=pass (google.com: domain of [email protected] designates 144.X.Y.Z as permitted sender) [email protected] 
Received: by server2.fraudulentdomain.net (Postfix, from userid 330) 
    id 385716C165; Tue, 21 Feb 2017 08:53:03 +0100 (CET) 
To: [email protected] 
Subject: Some Subject 
From: My Service <[email protected]>, 
    "MIME-Version:1.0"@server2.fraudulentdomain.net 
Content-type: text/html; charset=iso-8859-1 
Message-Id: <[email protected]> 
Date: Tue, 21 Feb 2017 08:53:03 +0100 (CET) 

为什么Gmail不启动DMARC检查,只是执行SPF检查?是否需要使用具有2个值的Display FROM标题做些事情?

回答

0

这是一个错误,我向Google报告,他们现在修复了它。