このチュートリアルでは、Email security を MX レコードとして Microsoft 365 に設定する方法を説明します。
このチュートリアルでの変更をすぐに反映するには、対象ドメインの既存 MX レコードの TTL(Time to Live)を 5 分に更新します。デプロイするすべてのドメインで行います。
TTL を変更すると、DNS サーバーは責任ネームサーバーに更新を問い合わせるまで、この値をどれだけキャッシュするかを指示されます。MX レコードを Email security に切り替える前に、TTL を変更してください。これにより、変更がすぐに反映され、必要ならすぐに元に戻せます。DNS マネージャーで TTL を 5 分に設定できない場合は、設定できる最短の値にしてください。
現在の TTL を確認するには、ターミナルを開き、ドメインに対して次のコマンドを実行します。
dig mx <YOUR_DOMAIN>; <<>> DiG 9.10.6 <<>> mx <YOUR_DOMAIN>
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 39938
;; flags: qr rd ra; QUERY: 1, ANSWER: 5, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;<YOUR_DOMAIN>. IN MX
;; ANSWER SECTION:
<YOUR_DOMAIN>. 300 IN MX 10 mxa.global.inbound.cf-emailsecurity.net.
<YOUR_DOMAIN>. 300 IN MX 10 mxb.global.inbound.cf-emailsecurity.net.上の例では、TTL は秒単位で 300(5 分)と表示されています。
DNS に Cloudflare を使っている場合は、TTL 設定を Auto のまま にできます。
よく使われるサービスで MX レコードを編集する手順は、次のとおりです。
- Cloudflare: メールレコードを設定する
- GoDaddy: MX レコードを編集する ↗
- AWS: Amazon Route 53 コンソールでレコードを作成する ↗
- Azure: Web アプリのカスタムドメインに DNS レコードを作成する ↗
- Anti-spam policies ページ ↗ を開き、Edit connection filter policy を選択します。
- Always allow messages from the following IP addresses or address range に、Egress IPs ページに記載の IP アドレスと CIDR ブロックを追加します。
- Save を選択します。
- メールソリューションを前面に置く場合、Microsoft は SPF Hard fail を無効にすることを推奨しています。
- Anti-spam ↗ に戻ります。
- Default anti-spam policy を選択します。
- Edit spam threshold and properties ↗ > Mark as spam > SPF record: hard fail を開き、Off になっていることを確認します。
- Save を選択します。
- コネクタをセットアップ ↗ します。
- Connection from で Partner organization を選択します。
- コネクタ名を入力します。
- Name:
Email security Inbound Connector - Description:
Inbound connector for Enhanced Filtering
- Name:
- コネクタ名を入力します。
- Authenticating sent email で、By verifying that the IP address of the sending server matches one of the following IP addresses, which belongs to your partner organization. を選択します。
- Egress IPs ページに記載のエグレス IP をすべて入力します。
- Security restrictions では、デフォルトの Reject email messages if they aren't sent over TLS をそのまま使います。
受信コネクタの設定が完了したら、そのコネクタの Enhanced Filtering を有効にします。
- Security admin console ↗ を開き、Enhanced Filtering を有効にします ↗。
- Automatically detect and skip the last IP address と Apply to entire organization を選択します。
- Save を選択します。
スパム対策ポリシーを設定するには:
- Microsoft 365 Defender コンソール ↗ を開きます。
- Email & collaboration > Policies & rules を開きます。
- Threat policies を選択します。
- Policies で Anti-spam を選択します。
- Anti-spam inbound policy (Default) のテキストを選択します(チェックボックスは選びません)。
- Actions で下にスクロールし、Edit actions を選択します。
- 次の条件とアクションを設定します(表示位置に応じて上下にスクロールします)。
- Spam: Move messages to Junk Email folder.
- High confidence spam: Quarantine message.
- Select quarantine policy: AdminOnlyAccessPolicy.
- Phishing: Quarantine message.
- Select quarantine policy: AdminOnlyAccessPolicy.
- High confidence phishing: Quarantine message.
- Select quarantine policy: AdminOnlyAccessPolicy.
- Retain spam in quarantine for this many days: デフォルトは 15 日です。Email security では 15〜30 日を推奨します。
- 上記の手順でスパム時のアクションを選択します。
- Save を選択します。
特定の disposition のメールを Email security に送るトランスポートルールを作成するには:
-
新しい Exchange admin center ↗ を開きます。
-
Mail flow > Rules を開きます。
-
Add a Rule > Create a new rule を選択します。
-
次のルール条件を設定します。
- Name: Email Security Deliver to Junk Email folder.
- Apply this rule if: The message headers > includes any of these words.
- Enter text:
X-CFEmailSecurity-Disposition> Save. - Enter words:
BULK> Add > Save.
- Enter text:
- Apply this rule if: + を選択して 2 つ目の条件を追加します。
- And: The sender > IP address is in any of these ranges or exactly matches > Egress IPs に記載のエグレス IP を入力します。
- Do the following - Modify the message properties > Set the Spam Confidence Level (SCL) > 5.
-
Next を選択します。
-
この画面はデフォルト値のままで構いません。Next を選択します。
-
設定を確認し、Finish > Done を選択します。
-
作成したルール Email security Deliver to Junk Email folder を選択し、Enable を選びます。
-
Add a Rule > Create a new rule を選択します。
-
次のルール条件を設定します。
- Name:
Email security Deliver to Junk Email folder. - Apply this rule if: The message headers > includes any of these words.
- Enter text:
X-CFEmailSecurity-Disposition> Save. - Enter words:
MALICIOUS,UCE,SPOOF> Add > Save.
- Enter text:
- Apply this rule if: + を選択して 2 つ目の条件を追加します。
- And: The sender > IP address is in any of these ranges or exactly matches > Egress IPs に記載のエグレス IP を入力します。
- Do the following: Redirect the message to > hosted quarantine.
- Name:
-
Next を選択します。
-
この画面はデフォルト値のままで構いません。Next を選択します。
-
設定を確認し、Finish > Done を選択します。
-
作成したルールを選択し、Enable を選びます。
前提条件の手順が完了したら、Cloudflare ダッシュボードで MX/Inline を設定します。次の手順は MX/Inline デプロイを設定する を参照してください。
DNS 攻撃の手法のひとつは、古い MX レコードを探し、メールサーバーへ直接 フィッシング メールを送ることです。メールフローを保護するには、受信メッセージを Email security 経由のときだけ Microsoft 365 が受け付けるようにします。そのためには、TLS 暗号化付きで Email security からのメールだけを許可するコネクタを追加します。この手順は任意ですが、推奨します。
-
新しい Exchange admin center ↗ を開きます。
-
Mail flow > Connectors を開きます。
-
Add a connector を選択します。
-
Connection from > Partner organization を開きます。
-
Next を選択します。
-
次のオプションを設定します。
- Name -
Secure M365 Inbound - Description -
Only accept inbound email from Email security
- Name -
-
Next を選択します。
-
By Verifying that the sender domain matches one of the following domains が選ばれていることを確認します。
-
テキストフィールドに
*を入力し、+ を選択します。 -
Next を選択します。
-
Reject email messages if they aren't sent over TLS が選ばれていることを確認します。
-
同じ画面で Reject email messages if they aren't sent from within this IP address range を選択し、Egress IPs ページに記載のエグレス IP をすべて入力します。
-
Next を選択します。
-
設定を確認し、Create connector を選択します。