mirror of
https://github.com/domainaware/parsedmarc.git
synced 2026-10-10 22:27:13 +00:00
Add dashboard guide
This commit is contained in:
1 parent
4a0cf63f25
commit
60ba8c11c3
13 files changed
+209
-30
No files matched your search
@@ -0,0 +1 @@
|
||||
*.dat
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
# Sphinx build info version 1
|
||||
# This file hashes the configuration used when building these files. When it is not found, a full rebuild will be done.
|
||||
config: a59d5383374d9259b707ed9bddbb58c9
|
||||
config: b572f0b0b984c71eb4deee02cb5f1b4f
|
||||
tags: 645f666f9bcd5a90fca523b33c5a78b7
|
||||
@@ -8,7 +8,7 @@
|
||||
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
|
||||
<title>Overview: module code — parsedmarc 3.5.0 documentation</title>
|
||||
<title>Overview: module code — parsedmarc 3.6.0 documentation</title>
|
||||
|
||||
|
||||
|
||||
@@ -56,7 +56,7 @@
|
||||
|
||||
|
||||
<div class="version">
|
||||
3.5.0
|
||||
3.6.0
|
||||
</div>
|
||||
|
||||
|
||||
@@ -177,7 +177,7 @@
|
||||
<script type="text/javascript">
|
||||
var DOCUMENTATION_OPTIONS = {
|
||||
URL_ROOT:'../',
|
||||
VERSION:'3.5.0',
|
||||
VERSION:'3.6.0',
|
||||
LANGUAGE:'None',
|
||||
COLLAPSE_INDEX:false,
|
||||
FILE_SUFFIX:'.html',
|
||||
|
||||
@@ -8,7 +8,7 @@
|
||||
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
|
||||
<title>parsedmarc — parsedmarc 3.5.0 documentation</title>
|
||||
<title>parsedmarc — parsedmarc 3.6.0 documentation</title>
|
||||
|
||||
|
||||
|
||||
@@ -56,7 +56,7 @@
|
||||
|
||||
|
||||
<div class="version">
|
||||
3.5.0
|
||||
3.6.0
|
||||
</div>
|
||||
|
||||
|
||||
@@ -149,6 +149,7 @@
|
||||
|
||||
<span class="kn">import</span> <span class="nn">logging</span>
|
||||
<span class="kn">import</span> <span class="nn">os</span>
|
||||
<span class="kn">import</span> <span class="nn">xml.parsers.expat</span> <span class="k">as</span> <span class="nn">expat</span>
|
||||
<span class="kn">import</span> <span class="nn">json</span>
|
||||
<span class="kn">from</span> <span class="nn">datetime</span> <span class="k">import</span> <span class="n">datetime</span>
|
||||
<span class="kn">from</span> <span class="nn">collections</span> <span class="k">import</span> <span class="n">OrderedDict</span>
|
||||
@@ -187,7 +188,7 @@
|
||||
<span class="kn">import</span> <span class="nn">dateparser</span>
|
||||
<span class="kn">import</span> <span class="nn">mailparser</span>
|
||||
|
||||
<span class="n">__version__</span> <span class="o">=</span> <span class="s2">"3.5.0"</span>
|
||||
<span class="n">__version__</span> <span class="o">=</span> <span class="s2">"3.6.0"</span>
|
||||
|
||||
<span class="n">logger</span> <span class="o">=</span> <span class="n">logging</span><span class="o">.</span><span class="n">getLogger</span><span class="p">(</span><span class="vm">__name__</span><span class="p">)</span>
|
||||
<span class="n">logger</span><span class="o">.</span><span class="n">setLevel</span><span class="p">(</span><span class="n">logging</span><span class="o">.</span><span class="n">INFO</span><span class="p">)</span>
|
||||
@@ -496,7 +497,10 @@
|
||||
<span class="n">new_record</span><span class="p">[</span><span class="s2">"policy_evaluated"</span><span class="p">]</span> <span class="o">=</span> <span class="n">new_policy_evaluated</span>
|
||||
<span class="n">new_record</span><span class="p">[</span><span class="s2">"identifiers"</span><span class="p">]</span> <span class="o">=</span> <span class="n">record</span><span class="p">[</span><span class="s2">"identifiers"</span><span class="p">]</span><span class="o">.</span><span class="n">copy</span><span class="p">()</span>
|
||||
<span class="n">new_record</span><span class="p">[</span><span class="s2">"auth_results"</span><span class="p">]</span> <span class="o">=</span> <span class="n">OrderedDict</span><span class="p">([(</span><span class="s2">"dkim"</span><span class="p">,</span> <span class="p">[]),</span> <span class="p">(</span><span class="s2">"spf"</span><span class="p">,</span> <span class="p">[])])</span>
|
||||
<span class="n">auth_results</span> <span class="o">=</span> <span class="n">record</span><span class="p">[</span><span class="s2">"auth_results"</span><span class="p">]</span><span class="o">.</span><span class="n">copy</span><span class="p">()</span>
|
||||
<span class="k">if</span> <span class="n">record</span><span class="p">[</span><span class="s2">"auth_results"</span><span class="p">]</span> <span class="ow">is</span> <span class="ow">not</span> <span class="kc">None</span><span class="p">:</span>
|
||||
<span class="n">auth_results</span> <span class="o">=</span> <span class="n">record</span><span class="p">[</span><span class="s2">"auth_results"</span><span class="p">]</span><span class="o">.</span><span class="n">copy</span><span class="p">()</span>
|
||||
<span class="k">else</span><span class="p">:</span>
|
||||
<span class="n">auth_results</span> <span class="o">=</span> <span class="n">new_record</span><span class="p">[</span><span class="s2">"auth_results"</span><span class="p">]</span><span class="o">.</span><span class="n">copy</span><span class="p">()</span>
|
||||
<span class="k">if</span> <span class="s2">"dkim"</span> <span class="ow">in</span> <span class="n">auth_results</span><span class="p">:</span>
|
||||
<span class="k">if</span> <span class="nb">type</span><span class="p">(</span><span class="n">auth_results</span><span class="p">[</span><span class="s2">"dkim"</span><span class="p">])</span> <span class="o">!=</span> <span class="nb">list</span><span class="p">:</span>
|
||||
<span class="n">auth_results</span><span class="p">[</span><span class="s2">"dkim"</span><span class="p">]</span> <span class="o">=</span> <span class="p">[</span><span class="n">auth_results</span><span class="p">[</span><span class="s2">"dkim"</span><span class="p">]]</span>
|
||||
@@ -634,8 +638,18 @@
|
||||
|
||||
<span class="k">return</span> <span class="n">new_report</span>
|
||||
|
||||
<span class="k">except</span> <span class="n">expat</span><span class="o">.</span><span class="n">ExpatError</span> <span class="k">as</span> <span class="n">error</span><span class="p">:</span>
|
||||
<span class="k">raise</span> <span class="n">InvalidAggregateReport</span><span class="p">(</span><span class="s2">"Invalid XML: "</span>
|
||||
<span class="s2">"</span><span class="si">{0}</span><span class="s2">"</span><span class="o">.</span><span class="n">format</span><span class="p">(</span><span class="n">error</span><span class="o">.</span><span class="fm">__str__</span><span class="p">()))</span>
|
||||
|
||||
<span class="k">except</span> <span class="ne">KeyError</span> <span class="k">as</span> <span class="n">error</span><span class="p">:</span>
|
||||
<span class="k">raise</span> <span class="n">InvalidAggregateReport</span><span class="p">(</span><span class="s2">"Missing field: "</span>
|
||||
<span class="s2">"</span><span class="si">{0}</span><span class="s2">"</span><span class="o">.</span><span class="n">format</span><span class="p">(</span><span class="n">error</span><span class="o">.</span><span class="fm">__str__</span><span class="p">()))</span>
|
||||
<span class="k">except</span> <span class="ne">AttributeError</span><span class="p">:</span>
|
||||
<span class="k">raise</span> <span class="n">InvalidAggregateReport</span><span class="p">(</span><span class="s2">"Report missing required section"</span><span class="p">)</span>
|
||||
|
||||
<span class="k">except</span> <span class="ne">Exception</span> <span class="k">as</span> <span class="n">error</span><span class="p">:</span>
|
||||
<span class="k">raise</span> <span class="n">InvalidAggregateReport</span><span class="p">(</span><span class="s2">"Unexpected error: "</span>
|
||||
<span class="s2">"</span><span class="si">{0}</span><span class="s2">"</span><span class="o">.</span><span class="n">format</span><span class="p">(</span><span class="n">error</span><span class="o">.</span><span class="fm">__str__</span><span class="p">()))</span></div>
|
||||
|
||||
|
||||
@@ -676,6 +690,9 @@
|
||||
<span class="k">except</span> <span class="ne">UnicodeDecodeError</span><span class="p">:</span>
|
||||
<span class="k">raise</span> <span class="n">InvalidAggregateReport</span><span class="p">(</span><span class="s2">"File objects must be opened in binary "</span>
|
||||
<span class="s2">"(rb) mode"</span><span class="p">)</span>
|
||||
<span class="k">except</span> <span class="ne">Exception</span> <span class="k">as</span> <span class="n">error</span><span class="p">:</span>
|
||||
<span class="k">raise</span> <span class="n">InvalidAggregateReport</span><span class="p">(</span><span class="s2">"Invalid archive file: "</span>
|
||||
<span class="s2">"</span><span class="si">{0}</span><span class="s2">"</span><span class="o">.</span><span class="n">format</span><span class="p">(</span><span class="n">error</span><span class="o">.</span><span class="fm">__str__</span><span class="p">()))</span>
|
||||
|
||||
<span class="k">return</span> <span class="n">xml</span></div>
|
||||
|
||||
@@ -955,7 +972,11 @@
|
||||
|
||||
<span class="k">except</span> <span class="ne">KeyError</span> <span class="k">as</span> <span class="n">error</span><span class="p">:</span>
|
||||
<span class="k">raise</span> <span class="n">InvalidForensicReport</span><span class="p">(</span><span class="s2">"Missing value: </span><span class="si">{0}</span><span class="s2">"</span><span class="o">.</span><span class="n">format</span><span class="p">(</span>
|
||||
<span class="n">error</span><span class="o">.</span><span class="fm">__str__</span><span class="p">()))</span></div>
|
||||
<span class="n">error</span><span class="o">.</span><span class="fm">__str__</span><span class="p">()))</span>
|
||||
|
||||
<span class="k">except</span> <span class="ne">Exception</span> <span class="k">as</span> <span class="n">error</span><span class="p">:</span>
|
||||
<span class="k">raise</span> <span class="n">InvalidForensicReport</span><span class="p">(</span><span class="s2">"Unexpected error: "</span>
|
||||
<span class="s2">"</span><span class="si">{0}</span><span class="s2">"</span><span class="o">.</span><span class="n">format</span><span class="p">(</span><span class="n">error</span><span class="o">.</span><span class="fm">__str__</span><span class="p">()))</span></div>
|
||||
|
||||
|
||||
<div class="viewcode-block" id="parsed_forensic_reports_to_csv"><a class="viewcode-back" href="../index.html#parsedmarc.parsed_forensic_reports_to_csv">[docs]</a><span class="k">def</span> <span class="nf">parsed_forensic_reports_to_csv</span><span class="p">(</span><span class="n">reports</span><span class="p">):</span>
|
||||
@@ -1597,7 +1618,7 @@
|
||||
<script type="text/javascript">
|
||||
var DOCUMENTATION_OPTIONS = {
|
||||
URL_ROOT:'../',
|
||||
VERSION:'3.5.0',
|
||||
VERSION:'3.6.0',
|
||||
LANGUAGE:'None',
|
||||
COLLAPSE_INDEX:false,
|
||||
FILE_SUFFIX:'.html',
|
||||
|
||||
@@ -8,7 +8,7 @@
|
||||
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
|
||||
<title>parsedmarc.elastic — parsedmarc 3.5.0 documentation</title>
|
||||
<title>parsedmarc.elastic — parsedmarc 3.6.0 documentation</title>
|
||||
|
||||
|
||||
|
||||
@@ -56,7 +56,7 @@
|
||||
|
||||
|
||||
<div class="version">
|
||||
3.5.0
|
||||
3.6.0
|
||||
</div>
|
||||
|
||||
|
||||
@@ -545,7 +545,7 @@
|
||||
<script type="text/javascript">
|
||||
var DOCUMENTATION_OPTIONS = {
|
||||
URL_ROOT:'../../',
|
||||
VERSION:'3.5.0',
|
||||
VERSION:'3.6.0',
|
||||
LANGUAGE:'None',
|
||||
COLLAPSE_INDEX:false,
|
||||
FILE_SUFFIX:'.html',
|
||||
|
||||
@@ -27,7 +27,15 @@ Features
|
||||
* Consistent data structures
|
||||
* Simple JSON and/or CSV output
|
||||
* Optionally email the results
|
||||
* Optionally send the results to Elasticsearch, for use with premade Kibana dashboards
|
||||
* Optionally send the results to Elasticsearch, for use with premade Kibana
|
||||
dashboards
|
||||
|
||||
Resources
|
||||
=========
|
||||
|
||||
* `Demystifying DMARC`_
|
||||
|
||||
|
||||
|
||||
CLI help
|
||||
========
|
||||
@@ -518,6 +526,78 @@ Then, enable the service
|
||||
You must also run the above commands whenever you edit
|
||||
``parsedmarc.service``.
|
||||
|
||||
|
||||
Using the Kibana dashboards
|
||||
===========================
|
||||
|
||||
The Kibana DMARC dashboards are a human-friendly way to understand the results
|
||||
from incoming DMARC reports.
|
||||
|
||||
DMARC Summary
|
||||
-------------
|
||||
|
||||
Start by using the DMARC summary dashboard. As the name suggests, this
|
||||
dashboard is the best place to start reviewing your aggregate DMARC data.
|
||||
|
||||
Across the top of the dashboard, three pie charts display the percentage of
|
||||
alignment pass/fail for SPF, DKIM, and DMARC. Clicking on any chart segment
|
||||
will filter for that value.
|
||||
|
||||
.. note::
|
||||
|
||||
Messages failing DMARC should not be considered malicious just because they
|
||||
failed to pass DMARC; especially if you have just started collecting data.
|
||||
In may be a service that needs SPF and DKIM configured correctly.
|
||||
|
||||
Start by filtering the results to only show failed DKIM alignment. While DMARC
|
||||
passes if a message passes SPF or DKIM alignment, only DKIM alignment remains
|
||||
valid when a message is forwarded without changing the from address, which is
|
||||
often caused by a mailbox forwarding rule. This is because DKIM signatures are
|
||||
part of the message headers, whereas SPF relies on SMTP session headers.
|
||||
|
||||
Underneath the pie charts. you can see graphs of DMARC passage and message
|
||||
disposition over time.
|
||||
|
||||
Under the graphs you will find the most useful data tables on the dashboard. On
|
||||
the left, there is a list of organizations that are sending you DMARC reports.
|
||||
In the center, there is a list of sending servers grouped by the base domain
|
||||
in their reverse DNS. On the right, there is a list of email from domains,
|
||||
sorted by message volume.
|
||||
|
||||
By hovering your mouse over a data table value and using the magnifying glass
|
||||
icons, you can filter on our filter out different values. Start by looking at
|
||||
the Message Sources by Reverse DNS table. Find a sender that you recognize,
|
||||
such as an email marketing service, hover over it, and click on the plus (+)
|
||||
magnifying glass icon, to add a filter that only shows results for that sender.
|
||||
Now, look at the Message From Header table to the right. That shows you the
|
||||
domains that a sender is sending as, which might tell you which brand/business
|
||||
is using a particular service, you can contact them and have them set up DKIM.
|
||||
|
||||
Any other filters work the same way. Further down the dashboard, you can filter
|
||||
by source country or source IP address. You can also add your own custom
|
||||
temporary filters
|
||||
|
||||
DMARC Failures
|
||||
--------------
|
||||
|
||||
The DMARC Failures dashboard contains data tables showing the details of
|
||||
misaligned SPF and DKIM results, which may be useful for identifying the
|
||||
specific application or service that is generating failing email messages.
|
||||
|
||||
DMARC Forensic Samples
|
||||
----------------------
|
||||
|
||||
The DMARC Forensic Samples dashboard contains information on DMARC forensic
|
||||
reports (also known as failure reports or ruf reports). These reports contain
|
||||
samples of emails that have failed to pass DMARC.
|
||||
|
||||
.. note::
|
||||
|
||||
Most recipients do not send forensic/failure/ruf reports at all to avoid
|
||||
privacy leaks. Some recipients (notably Chinese webmail services) will only
|
||||
supply the headers of sample emails. Very few provide the entire email.
|
||||
|
||||
|
||||
API
|
||||
===
|
||||
|
||||
@@ -545,6 +625,8 @@ Indices and tables
|
||||
.. |Build Status| image:: https://travis-ci.org/domainaware/parsedmarc.svg?branch=master
|
||||
:target: https://travis-ci.org/domainaware/parsedmarc
|
||||
|
||||
.. _Demystifying DMARC: https://seanthegeek.net/459/demystifying-dmarc/
|
||||
|
||||
.. _X-Pack: https://www.elastic.co/products/x-pack
|
||||
|
||||
.. _kibana_saved_objects.json: https://raw.githubusercontent.com/domainaware/parsedmarc/master/kibana/kibana_saved_objects.json
|
||||
@@ -1,6 +1,6 @@
|
||||
var DOCUMENTATION_OPTIONS = {
|
||||
URL_ROOT: document.getElementById("documentation_options").getAttribute('data-url_root'),
|
||||
VERSION: '3.5.0',
|
||||
VERSION: '3.6.0',
|
||||
LANGUAGE: 'None',
|
||||
COLLAPSE_INDEX: false,
|
||||
FILE_SUFFIX: '.html',
|
||||
|
||||
+3
-3
@@ -9,7 +9,7 @@
|
||||
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
|
||||
<title>Index — parsedmarc 3.5.0 documentation</title>
|
||||
<title>Index — parsedmarc 3.6.0 documentation</title>
|
||||
|
||||
|
||||
|
||||
@@ -57,7 +57,7 @@
|
||||
|
||||
|
||||
<div class="version">
|
||||
3.5.0
|
||||
3.6.0
|
||||
</div>
|
||||
|
||||
|
||||
@@ -310,7 +310,7 @@
|
||||
<script type="text/javascript">
|
||||
var DOCUMENTATION_OPTIONS = {
|
||||
URL_ROOT:'./',
|
||||
VERSION:'3.5.0',
|
||||
VERSION:'3.6.0',
|
||||
LANGUAGE:'None',
|
||||
COLLAPSE_INDEX:false,
|
||||
FILE_SUFFIX:'.html',
|
||||
|
||||
+79
-4
@@ -8,7 +8,7 @@
|
||||
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
|
||||
<title>Welcome to parsedmarc’s documentation! — parsedmarc 3.5.0 documentation</title>
|
||||
<title>Welcome to parsedmarc’s documentation! — parsedmarc 3.6.0 documentation</title>
|
||||
|
||||
|
||||
|
||||
@@ -56,7 +56,7 @@
|
||||
|
||||
|
||||
<div class="version">
|
||||
3.5.0
|
||||
3.6.0
|
||||
</div>
|
||||
|
||||
|
||||
@@ -84,6 +84,7 @@
|
||||
<div class="local-toc"><ul>
|
||||
<li><a class="reference internal" href="#">Welcome to parsedmarc’s documentation!</a><ul>
|
||||
<li><a class="reference internal" href="#features">Features</a></li>
|
||||
<li><a class="reference internal" href="#resources">Resources</a></li>
|
||||
<li><a class="reference internal" href="#cli-help">CLI help</a></li>
|
||||
<li><a class="reference internal" href="#spf-and-dmarc-record-validation">SPF and DMARC record validation</a></li>
|
||||
<li><a class="reference internal" href="#sample-aggregate-report-output">Sample aggregate report output</a><ul>
|
||||
@@ -99,6 +100,12 @@
|
||||
<li><a class="reference internal" href="#running-parsedmarc-as-a-systemd-service">Running parsedmarc as a systemd service</a></li>
|
||||
</ul>
|
||||
</li>
|
||||
<li><a class="reference internal" href="#using-the-kibana-dashboards">Using the Kibana dashboards</a><ul>
|
||||
<li><a class="reference internal" href="#dmarc-summary">DMARC Summary</a></li>
|
||||
<li><a class="reference internal" href="#dmarc-failures">DMARC Failures</a></li>
|
||||
<li><a class="reference internal" href="#dmarc-forensic-samples">DMARC Forensic Samples</a></li>
|
||||
</ul>
|
||||
</li>
|
||||
<li><a class="reference internal" href="#module-parsedmarc">API</a><ul>
|
||||
<li><a class="reference internal" href="#module-parsedmarc.elastic">parsedmarc.elastic</a></li>
|
||||
</ul>
|
||||
@@ -185,7 +192,14 @@
|
||||
<li>Consistent data structures</li>
|
||||
<li>Simple JSON and/or CSV output</li>
|
||||
<li>Optionally email the results</li>
|
||||
<li>Optionally send the results to Elasticsearch, for use with premade Kibana dashboards</li>
|
||||
<li>Optionally send the results to Elasticsearch, for use with premade Kibana
|
||||
dashboards</li>
|
||||
</ul>
|
||||
</div>
|
||||
<div class="section" id="resources">
|
||||
<h2>Resources<a class="headerlink" href="#resources" title="Permalink to this headline">¶</a></h2>
|
||||
<ul class="simple">
|
||||
<li><a class="reference external" href="https://seanthegeek.net/459/demystifying-dmarc/">Demystifying DMARC</a></li>
|
||||
</ul>
|
||||
</div>
|
||||
<div class="section" id="cli-help">
|
||||
@@ -576,6 +590,67 @@ sudo service parsedmarc restart
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
<div class="section" id="using-the-kibana-dashboards">
|
||||
<h2>Using the Kibana dashboards<a class="headerlink" href="#using-the-kibana-dashboards" title="Permalink to this headline">¶</a></h2>
|
||||
<p>The Kibana DMARC dashboards are a human-friendly way to understand the results
|
||||
from incoming DMARC reports.</p>
|
||||
<div class="section" id="dmarc-summary">
|
||||
<h3>DMARC Summary<a class="headerlink" href="#dmarc-summary" title="Permalink to this headline">¶</a></h3>
|
||||
<blockquote>
|
||||
<div>Start by using the DMARC summary dashboard. As the name suggests, this
|
||||
dashboard is the best place to start reviewing your aggregate DMARC data.</div></blockquote>
|
||||
<p>Across the top of the dashboard, three pie charts display the percentage of
|
||||
alignment pass/fail for SPF, DKIM, and DMARC. Clicking on any chart segment
|
||||
will filter for that value.</p>
|
||||
<div class="admonition note">
|
||||
<p class="first admonition-title">Note</p>
|
||||
<p class="last">Messages failing DMARC should not be considered malicious just because they
|
||||
failed to pass DMARC; especially if you have just started collecting data.
|
||||
In may be a service that needs SPF and DKIM configured correctly.</p>
|
||||
</div>
|
||||
<p>Start by filtering the results to only show failed DKIM alignment. While DMARC
|
||||
passes if a message passes SPF or DKIM alignment, only DKIM alignment remains
|
||||
valid when a message is forwarded without changing the from address, which is
|
||||
often caused by a mailbox forwarding rule. This is because DKIM signatures are
|
||||
part of the message headers, whereas SPF relies on SMTP session headers.</p>
|
||||
<p>Underneath the pie charts. you can see graphs of DMARC passage and message
|
||||
disposition over time.</p>
|
||||
<p>Under the graphs you will find the most useful data tables on the dashboard. On
|
||||
the left, there is a list of organizations that are sending you DMARC reports.
|
||||
In the center, there is a list of sending servers grouped by the base domain
|
||||
in their reverse DNS. On the right, there is a list of email from domains,
|
||||
sorted by message volume.</p>
|
||||
<p>By hovering your mouse over a data table value and using the magnifying glass
|
||||
icons, you can filter on our filter out different values. Start by looking at
|
||||
the Message Sources by Reverse DNS table. Find a sender that you recognize,
|
||||
such as an email marketing service, hover over it, and click on the plus (+)
|
||||
magnifying glass icon, to add a filter that only shows results for that sender.
|
||||
Now, look at the Message From Header table to the right. That shows you the
|
||||
domains that a sender is sending as, which might tell you which brand/business
|
||||
is using a particular service, you can contact them and have them set up DKIM.</p>
|
||||
<p>Any other filters work the same way. Further down the dashboard, you can filter
|
||||
by source country or source IP address. You can also add your own custom
|
||||
temporary filters</p>
|
||||
</div>
|
||||
<div class="section" id="dmarc-failures">
|
||||
<h3>DMARC Failures<a class="headerlink" href="#dmarc-failures" title="Permalink to this headline">¶</a></h3>
|
||||
<p>The DMARC Failures dashboard contains data tables showing the details of
|
||||
misaligned SPF and DKIM results, which may be useful for identifying the
|
||||
specific application or service that is generating failing email messages.</p>
|
||||
</div>
|
||||
<div class="section" id="dmarc-forensic-samples">
|
||||
<h3>DMARC Forensic Samples<a class="headerlink" href="#dmarc-forensic-samples" title="Permalink to this headline">¶</a></h3>
|
||||
<p>The DMARC Forensic Samples dashboard contains information on DMARC forensic
|
||||
reports (also known as failure reports or ruf reports). These reports contain
|
||||
samples of emails that have failed to pass DMARC.</p>
|
||||
<div class="admonition note">
|
||||
<p class="first admonition-title">Note</p>
|
||||
<p class="last">Most recipients do not send forensic/failure/ruf reports at all to avoid
|
||||
privacy leaks. Some recipients (notably Chinese webmail services) will only
|
||||
supply the headers of sample emails. Very few provide the entire email.</p>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
<div class="section" id="module-parsedmarc">
|
||||
<span id="api"></span><h2>API<a class="headerlink" href="#module-parsedmarc" title="Permalink to this headline">¶</a></h2>
|
||||
<p>A Python package for parsing DMARC reports</p>
|
||||
@@ -1059,7 +1134,7 @@ to a callback function</p>
|
||||
<script type="text/javascript">
|
||||
var DOCUMENTATION_OPTIONS = {
|
||||
URL_ROOT:'./',
|
||||
VERSION:'3.5.0',
|
||||
VERSION:'3.6.0',
|
||||
LANGUAGE:'None',
|
||||
COLLAPSE_INDEX:false,
|
||||
FILE_SUFFIX:'.html',
|
||||
|
||||
+1
-1
@@ -1,5 +1,5 @@
|
||||
# Sphinx inventory version 2
|
||||
# Project: parsedmarc
|
||||
# Version: 3.5.0
|
||||
# Version: 3.6.0
|
||||
# The remainder of this file is compressed using zlib.
|
||||
xÚ”KNÃ0†÷=…lSÑmw©‹HU‹ÄÒríibÉŽ-{RRV\ƒëqì$¥¥°ˆ;kòÿx±e΃ÐÌqb÷smD£€ÜYh§juÝDz’Mì—xº(òåƒsÆEZ¥©Éì”<GêSRäeé d+°Æa2_ä«»ÙGã ö’§âËxt‰õ®‹§Ô�beâ(hš+Lì×l"9å”�vBð‘ß65�û�•²Ãh©ëLÑÐAà!¨«Ël·ÃÔþÏ�VÆcB™šIòûF¥P-:Æ‘¶Z�fÊp·î4TëéÖæ²1m’ÉЬWiGcU£YMQjðÈ´��aš10Ú£;þÜ„TöHicoq¶9‰ô�¶›ýehzÕâGÙ>Ž�û]ªÏYíÉ6ݯg´Íø¾½0äÕ˜]-¡î"Ä£˜+¶E²9D;YÄãä(†Gщâ7a7Ñ�ã%>ÞÞ= ÚFC�,¦¿š„‡ó—tvŸ>ô~Eÿæö‰‡·åÑÇzñºÿ¾d%L>%;¤ë
|
||||
@@ -8,7 +8,7 @@
|
||||
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
|
||||
<title>Python Module Index — parsedmarc 3.5.0 documentation</title>
|
||||
<title>Python Module Index — parsedmarc 3.6.0 documentation</title>
|
||||
|
||||
|
||||
|
||||
@@ -59,7 +59,7 @@
|
||||
|
||||
|
||||
<div class="version">
|
||||
3.5.0
|
||||
3.6.0
|
||||
</div>
|
||||
|
||||
|
||||
@@ -200,7 +200,7 @@
|
||||
<script type="text/javascript">
|
||||
var DOCUMENTATION_OPTIONS = {
|
||||
URL_ROOT:'./',
|
||||
VERSION:'3.5.0',
|
||||
VERSION:'3.6.0',
|
||||
LANGUAGE:'None',
|
||||
COLLAPSE_INDEX:false,
|
||||
FILE_SUFFIX:'.html',
|
||||
|
||||
+3
-3
@@ -8,7 +8,7 @@
|
||||
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
||||
|
||||
<title>Search — parsedmarc 3.5.0 documentation</title>
|
||||
<title>Search — parsedmarc 3.6.0 documentation</title>
|
||||
|
||||
|
||||
|
||||
@@ -56,7 +56,7 @@
|
||||
|
||||
|
||||
<div class="version">
|
||||
3.5.0
|
||||
3.6.0
|
||||
</div>
|
||||
|
||||
|
||||
@@ -188,7 +188,7 @@
|
||||
<script type="text/javascript">
|
||||
var DOCUMENTATION_OPTIONS = {
|
||||
URL_ROOT:'./',
|
||||
VERSION:'3.5.0',
|
||||
VERSION:'3.6.0',
|
||||
LANGUAGE:'None',
|
||||
COLLAPSE_INDEX:false,
|
||||
FILE_SUFFIX:'.html',
|
||||
|
||||
+1
-1
@@ -1 +1 @@
|
||||
Search.setIndex({docnames:["index"],envversion:53,filenames:["index.rst"],objects:{"":{parsedmarc:[0,0,0,"-"]},"parsedmarc.elastic":{AlreadySaved:[0,1,1,""],create_indexes:[0,2,1,""],save_aggregate_report_to_elasticsearch:[0,2,1,""],save_forensic_report_to_elasticsearch:[0,2,1,""],set_hosts:[0,2,1,""]},parsedmarc:{IMAPError:[0,1,1,""],InvalidAggregateReport:[0,1,1,""],InvalidDMARCReport:[0,1,1,""],InvalidForensicReport:[0,1,1,""],ParserError:[0,1,1,""],SMTPError:[0,1,1,""],elastic:[0,0,0,"-"],email_results:[0,2,1,""],extract_xml:[0,2,1,""],get_dmarc_reports_from_inbox:[0,2,1,""],get_report_zip:[0,2,1,""],human_timestamp_to_datetime:[0,2,1,""],parse_aggregate_report_file:[0,2,1,""],parse_aggregate_report_xml:[0,2,1,""],parse_forensic_report:[0,2,1,""],parse_report_email:[0,2,1,""],parse_report_file:[0,2,1,""],parsed_aggregate_reports_to_csv:[0,2,1,""],parsed_forensic_reports_to_csv:[0,2,1,""],save_output:[0,2,1,""],watch_inbox:[0,2,1,""]}},objnames:{"0":["py","module","Python module"],"1":["py","exception","Python exception"],"2":["py","function","Python function"]},objtypes:{"0":"py:module","1":"py:exception","2":"py:function"},terms:{"50m":0,"break":0,"byte":0,"default":0,"float":0,"function":0,"import":0,"int":0,"null":0,"public":0,"return":0,"true":0,"while":0,DNS:0,For:0,OLE:0,The:0,Then:0,Use:0,_input:0,abl:0,abov:0,access:0,acm:0,actual:0,add:0,add_head:0,address:0,adkim:0,administr:0,adsl:0,aes256:0,after:0,age:0,aggregate_report:0,alreadysav:0,also:0,alwai:0,ani:0,answer:0,apache2:0,appear:0,appendix:0,apt:0,archiv:0,archive_fold:0,argument:0,arriv:0,arrival_d:0,artifact:0,ask:0,aspf:0,attach:0,attachment_filenam:0,auth_bas:0,auth_basic_user_fil:0,auth_result:0,authent:0,avail:0,base_domain:0,basic:0,becaus:0,been:0,begin_d:0,bellsouth:0,below:0,bin:0,bodi:0,bool:0,callback:0,can:0,cert:0,certif:0,chac:0,chacha20:0,check:0,checkdmarc:0,chmod:0,chown:0,click:0,cloudflar:0,com:0,command:0,commerci:0,common:0,compress:0,configur:0,connect:0,consist:0,contact:0,contain:0,content:0,context:0,control:0,convert:0,could:0,count:0,countri:0,creat:0,create_index:0,crt:0,csr:0,daemon:0,dai:0,daili:0,dashboard:0,data:0,date_rang:0,datetim:0,deb:0,debian:0,debug:0,delet:0,descript:0,develop:0,dhparam:0,directli:0,directori:0,disabl:0,disposit:0,dkim:0,dkim_align:0,dkim_domain:0,dkim_result:0,dkim_selector:0,dmarc_aggreg:0,dmarc_forens:0,dns_timeout:0,doe:0,domain:0,domainawar:0,don:0,download:0,draft:0,ecdh:0,ecdsa:0,echo:0,edit:0,elasticsearch_host:0,els:0,email:0,email_result:0,enabl:0,encount:0,end_dat:0,envelope_from:0,envelope_to:0,error:0,etc:0,even:0,exampl:0,exampleus:0,except:0,execstart:0,exist:0,exit:0,extract:0,extract_xml:0,fail:0,fals:0,feedback:0,feedback_report:0,fetch:0,few:0,field:0,file:0,file_path:0,filenam:0,fill:0,financ:0,first:0,flat:0,folder:0,foobar:0,forensic_report:0,format:0,forward:0,found:0,fqdn:0,frame:0,from:0,full:0,gcm:0,gener:0,get:0,get_dmarc_reports_from_inbox:0,get_report_zip:0,git:0,github:0,give:0,given:0,gpg:0,gzip:0,handl:0,has:0,have:0,header:0,header_from:0,healthcar:0,here:0,highli:0,host:0,hostnam:0,htpasswd:0,http2:0,http:0,httpasswd:0,human:0,human_timestamp:0,human_timestamp_to_datetim:0,identifi:0,idl:0,imap:0,imaperror:0,inbox:0,includ:0,includesubdomain:0,incom:0,index:0,industri:0,inform:0,input:0,input_:0,instanc:0,invalid:0,invalidaggregatereport:0,invaliddmarcreport:0,invalidforensicreport:0,ip_address:0,issu:0,its:0,jre:0,kei:0,keyout:0,kibana_saved_object:0,kind:0,later:0,latest:0,least:0,legitim:0,libemail:0,like:0,line:0,link:0,linux:0,list:0,listen:0,local:0,localhost:0,locat:0,log:0,login:0,look:0,maco:0,mai:0,mail:0,mail_from:0,mail_to:0,mailbox:0,main:0,manag:0,match:0,max:0,mechan:0,messag:0,mfrom:0,microsoft:0,mkdir:0,modul:0,more:0,most:0,move:0,msg:0,msgconvert:0,multi:0,must:0,name:0,nameserv:0,nano:0,need:0,net:0,newkei:0,newli:0,next:0,nginx:0,node:0,none:0,norepli:0,normal:0,nosniff:0,now:0,number:0,object:0,occur:0,off:0,office365:0,older:0,onc:0,one:0,onli:0,openjdk:0,openssl:0,ordereddict:0,org:0,org_email:0,org_extra_contact_info:0,org_nam:0,organis:0,origin:0,other:0,out:0,outgo:0,outgoing_attach:0,outgoing_from:0,outgoing_host:0,outgoing_messag:0,outgoing_password:0,outgoing_subject:0,outgoing_to:0,outgoing_us:0,outlook:0,output_directori:0,over:0,overrid:0,overwrit:0,own:0,pack:0,packag:0,page:0,paramet:0,pars:0,parse_aggregate_report_fil:0,parse_aggregate_report_xml:0,parse_forensic_report:0,parse_report_email:0,parse_report_fil:0,parsed_aggregate_reports_to_csv:0,parsed_forensic_reports_to_csv:0,parser:0,parsererror:0,particularli:0,pass:0,password:0,patch:0,path:0,pattern:0,pct:0,pem:0,perl:0,permiss:0,pip3:0,pip:0,place:0,plain:0,pleas:0,polici:0,policy_evalu:0,policy_override_com:0,policy_override_reason:0,policy_publish:0,poly1305:0,port:0,posit:0,possibl:0,preload:0,premad:0,print:0,privaci:0,process:0,produc:0,program:0,project:0,prompt:0,provid:0,proxi:0,proxy_add_x_forwarded_for:0,proxy_pass:0,proxy_set_head:0,publicli:0,pLine truncated
|
||||
Search.setIndex({docnames:["index"],envversion:53,filenames:["index.rst"],objects:{"":{parsedmarc:[0,0,0,"-"]},"parsedmarc.elastic":{AlreadySaved:[0,1,1,""],create_indexes:[0,2,1,""],save_aggregate_report_to_elasticsearch:[0,2,1,""],save_forensic_report_to_elasticsearch:[0,2,1,""],set_hosts:[0,2,1,""]},parsedmarc:{IMAPError:[0,1,1,""],InvalidAggregateReport:[0,1,1,""],InvalidDMARCReport:[0,1,1,""],InvalidForensicReport:[0,1,1,""],ParserError:[0,1,1,""],SMTPError:[0,1,1,""],elastic:[0,0,0,"-"],email_results:[0,2,1,""],extract_xml:[0,2,1,""],get_dmarc_reports_from_inbox:[0,2,1,""],get_report_zip:[0,2,1,""],human_timestamp_to_datetime:[0,2,1,""],parse_aggregate_report_file:[0,2,1,""],parse_aggregate_report_xml:[0,2,1,""],parse_forensic_report:[0,2,1,""],parse_report_email:[0,2,1,""],parse_report_file:[0,2,1,""],parsed_aggregate_reports_to_csv:[0,2,1,""],parsed_forensic_reports_to_csv:[0,2,1,""],save_output:[0,2,1,""],watch_inbox:[0,2,1,""]}},objnames:{"0":["py","module","Python module"],"1":["py","exception","Python exception"],"2":["py","function","Python function"]},objtypes:{"0":"py:module","1":"py:exception","2":"py:function"},terms:{"50m":0,"break":0,"byte":0,"default":0,"float":0,"function":0,"import":0,"int":0,"null":0,"public":0,"return":0,"true":0,"while":0,DNS:0,For:0,OLE:0,That:0,The:0,Then:0,These:0,Use:0,_input:0,abl:0,abov:0,access:0,acm:0,across:0,actual:0,add:0,add_head:0,address:0,adkim:0,administr:0,adsl:0,aes256:0,after:0,age:0,aggregate_report:0,align:0,all:0,alreadysav:0,also:0,alwai:0,ani:0,answer:0,apache2:0,appear:0,appendix:0,applic:0,apt:0,archiv:0,archive_fold:0,argument:0,arriv:0,arrival_d:0,artifact:0,ask:0,aspf:0,attach:0,attachment_filenam:0,auth_bas:0,auth_basic_user_fil:0,auth_result:0,authent:0,avail:0,avoid:0,base:0,base_domain:0,basic:0,becaus:0,been:0,begin_d:0,bellsouth:0,below:0,best:0,bin:0,bodi:0,bool:0,brand:0,busi:0,callback:0,can:0,caus:0,center:0,cert:0,certif:0,chac:0,chacha20:0,chang:0,chart:0,check:0,checkdmarc:0,chines:0,chmod:0,chown:0,click:0,cloudflar:0,collect:0,com:0,command:0,commerci:0,common:0,compress:0,configur:0,connect:0,consid:0,consist:0,contact:0,contain:0,content:0,context:0,control:0,convert:0,correctli:0,could:0,count:0,countri:0,creat:0,create_index:0,crt:0,csr:0,custom:0,daemon:0,dai:0,daili:0,dashboard:[],data:0,date_rang:0,datetim:0,deb:0,debian:0,debug:0,delet:0,demystifi:0,descript:0,detail:0,develop:0,dhparam:0,differ:0,directli:0,directori:0,disabl:0,displai:0,disposit:0,dkim:0,dkim_align:0,dkim_domain:0,dkim_result:0,dkim_selector:0,dmarc_:[],dmarc_aggreg:0,dmarc_forens:0,dns_timeout:0,doe:0,domain:0,domainawar:0,don:0,down:0,download:0,draft:0,ecdh:0,ecdsa:0,echo:0,edit:0,elasticsearch_host:0,els:0,email:0,email_result:0,enabl:0,encount:0,end_dat:0,entir:0,envelope_from:0,envelope_to:0,error:0,especi:0,etc:0,even:0,exampl:0,exampleus:0,except:0,execstart:0,exist:0,exit:0,extract:0,extract_xml:0,fail:0,fals:0,feedback:0,feedback_report:0,fetch:0,few:0,field:0,file:0,file_path:0,filenam:0,fill:0,filter:0,financ:0,find:0,first:0,flat:0,folder:0,foobar:0,forensic_report:0,format:0,forward:0,found:0,fqdn:0,frame:0,friendli:0,from:0,full:0,further:0,gcm:0,gener:0,get:0,get_dmarc_reports_from_inbox:0,get_report_zip:0,git:0,github:0,give:0,given:0,glass:0,gpg:0,graph:0,group:0,gzip:0,handl:0,has:0,have:0,header:0,header_from:0,healthcar:0,here:0,highli:0,host:0,hostnam:0,hover:0,htpasswd:0,http2:0,http:0,httpasswd:0,human:0,human_timestamp:0,human_timestamp_to_datetim:0,icon:0,identifi:0,idl:0,imap:0,imaperror:0,inbox:0,includ:0,includesubdomain:0,incom:0,index:0,industri:0,inform:0,input:0,input_:0,instanc:0,invalid:0,invalidaggregatereport:0,invaliddmarcreport:0,invalidforensicreport:0,ip_address:0,issu:0,its:0,jre:0,just:0,kei:0,keyout:0,kibana_saved_object:0,kind:0,known:0,later:0,latest:0,leak:0,least:0,left:0,legitim:0,libemail:0,like:0,line:0,link:0,linux:0,list:0,listen:0,local:0,localhost:0,locat:0,log:0,login:0,look:0,maco:0,magnifi:0,mai:0,mail:0,mail_from:0,mail_to:0,mailbox:0,main:0,malici:0,manag:0,market:0,match:0,max:0,mechan:0,messag:0,mfrom:0,microsoft:0,might:0,misalign:0,mkdir:0,modul:0,more:0,most:0,mous:0,move:0,msg:0,msgconvert:0,multi:0,must:0,name:0,nameserv:0,nano:0,need:0,net:0,newkei:0,newli:0,next:0,nginx:0,node:0,none:0,norepli:0,normal:0,nosniff:0,notabl:0,now:0,number:0,object:0,occur:0,off:0,office365:0,often:0,older:0,onc:0,one:0,onli:0,openjdk:0,openssl:0,ordereddict:0,org:0,org_email:0,org_extra_contact_info:0,org_nam:0,organ:0,organis:0,origin:0,other:0,our:0,out:0,outgo:0,outgoing_attach:0,outgoing_from:0,outgoing_host:0,outgoing_messag:0,outgoing_password:0,outgoing_subject:0,outgoing_to:0,outgoing_us:0,outlook:0,output_directori:0,over:0,overrid:0,overwrit:0,own:0,pack:0,packag:0,page:0,paramet:0,pars:0,parse_aggregate_report_fil:0,parse_aggregate_report_xml:0,parse_forensic_report:0,parse_report_email:0,parse_report_fil:0,parsed_aggregate_reports_to_csv:0,parsed_forensic_reports_to_csv:0,parser:0,parsLine truncated
|
||||
Reference in new issue
Block a user