mirror of
https://github.com/domainaware/parsedmarc.git
synced 2026-02-17 07:03:58 +00:00
370 lines
40 KiB
HTML
370 lines
40 KiB
HTML
|
||
|
||
<!DOCTYPE html>
|
||
<html class="writer-html5" lang="en" data-content_root="./">
|
||
<head>
|
||
<meta charset="utf-8" /><meta name="viewport" content="width=device-width, initial-scale=1" />
|
||
|
||
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
||
<title>Sample outputs — parsedmarc 9.0.10 documentation</title>
|
||
<link rel="stylesheet" type="text/css" href="_static/pygments.css?v=b86133f3" />
|
||
<link rel="stylesheet" type="text/css" href="_static/css/theme.css?v=9edc463e" />
|
||
|
||
|
||
<script src="_static/jquery.js?v=5d32c60e"></script>
|
||
<script src="_static/_sphinx_javascript_frameworks_compat.js?v=2cd50e6c"></script>
|
||
<script src="_static/documentation_options.js?v=164cc7e6"></script>
|
||
<script src="_static/doctools.js?v=fd6eb6e6"></script>
|
||
<script src="_static/sphinx_highlight.js?v=6ffebe34"></script>
|
||
<script src="_static/js/theme.js"></script>
|
||
<link rel="index" title="Index" href="genindex.html" />
|
||
<link rel="search" title="Search" href="search.html" />
|
||
<link rel="next" title="Elasticsearch and Kibana" href="elasticsearch.html" />
|
||
<link rel="prev" title="Using parsedmarc" href="usage.html" />
|
||
</head>
|
||
|
||
<body class="wy-body-for-nav">
|
||
<div class="wy-grid-for-nav">
|
||
<nav data-toggle="wy-nav-shift" class="wy-nav-side">
|
||
<div class="wy-side-scroll">
|
||
<div class="wy-side-nav-search" >
|
||
|
||
|
||
|
||
<a href="index.html" class="icon icon-home">
|
||
parsedmarc
|
||
</a>
|
||
<div role="search">
|
||
<form id="rtd-search-form" class="wy-form" action="search.html" method="get">
|
||
<input type="text" name="q" placeholder="Search docs" aria-label="Search docs" />
|
||
<input type="hidden" name="check_keywords" value="yes" />
|
||
<input type="hidden" name="area" value="default" />
|
||
</form>
|
||
</div>
|
||
</div><div class="wy-menu wy-menu-vertical" data-spy="affix" role="navigation" aria-label="Navigation menu">
|
||
<p class="caption" role="heading"><span class="caption-text">Contents</span></p>
|
||
<ul class="current">
|
||
<li class="toctree-l1"><a class="reference internal" href="installation.html">Installation</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="usage.html">Using parsedmarc</a></li>
|
||
<li class="toctree-l1 current"><a class="current reference internal" href="#">Sample outputs</a><ul>
|
||
<li class="toctree-l2"><a class="reference internal" href="#sample-aggregate-report-output">Sample aggregate report output</a><ul>
|
||
<li class="toctree-l3"><a class="reference internal" href="#json-aggregate-report">JSON aggregate report</a></li>
|
||
<li class="toctree-l3"><a class="reference internal" href="#csv-aggregate-report">CSV aggregate report</a></li>
|
||
</ul>
|
||
</li>
|
||
<li class="toctree-l2"><a class="reference internal" href="#sample-forensic-report-output">Sample forensic report output</a><ul>
|
||
<li class="toctree-l3"><a class="reference internal" href="#json-forensic-report">JSON forensic report</a></li>
|
||
<li class="toctree-l3"><a class="reference internal" href="#csv-forensic-report">CSV forensic report</a></li>
|
||
<li class="toctree-l3"><a class="reference internal" href="#json-smtp-tls-report">JSON SMTP TLS report</a></li>
|
||
</ul>
|
||
</li>
|
||
</ul>
|
||
</li>
|
||
<li class="toctree-l1"><a class="reference internal" href="elasticsearch.html">Elasticsearch and Kibana</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="opensearch.html">OpenSearch and Grafana</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="kibana.html">Using the Kibana dashboards</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="splunk.html">Splunk</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="davmail.html">Accessing an inbox using OWA/EWS</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="dmarc.html">Understanding DMARC</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="contributing.html">Contributing to parsedmarc</a></li>
|
||
<li class="toctree-l1"><a class="reference internal" href="api.html">API reference</a></li>
|
||
</ul>
|
||
|
||
</div>
|
||
</div>
|
||
</nav>
|
||
|
||
<section data-toggle="wy-nav-shift" class="wy-nav-content-wrap"><nav class="wy-nav-top" aria-label="Mobile navigation menu" >
|
||
<i data-toggle="wy-nav-top" class="fa fa-bars"></i>
|
||
<a href="index.html">parsedmarc</a>
|
||
</nav>
|
||
|
||
<div class="wy-nav-content">
|
||
<div class="rst-content">
|
||
<div role="navigation" aria-label="Page navigation">
|
||
<ul class="wy-breadcrumbs">
|
||
<li><a href="index.html" class="icon icon-home" aria-label="Home"></a></li>
|
||
<li class="breadcrumb-item active">Sample outputs</li>
|
||
<li class="wy-breadcrumbs-aside">
|
||
<a href="_sources/output.md.txt" rel="nofollow"> View page source</a>
|
||
</li>
|
||
</ul>
|
||
<hr/>
|
||
</div>
|
||
<div role="main" class="document" itemscope="itemscope" itemtype="http://schema.org/Article">
|
||
<div itemprop="articleBody">
|
||
|
||
<section class="tex2jax_ignore mathjax_ignore" id="sample-outputs">
|
||
<h1>Sample outputs<a class="headerlink" href="#sample-outputs" title="Link to this heading"></a></h1>
|
||
<section id="sample-aggregate-report-output">
|
||
<h2>Sample aggregate report output<a class="headerlink" href="#sample-aggregate-report-output" title="Link to this heading"></a></h2>
|
||
<p>Here are the results from parsing the <a class="reference external" href="https://dmarc.org/wiki/FAQ#I_need_to_implement_aggregate_reports.2C_what_do_they_look_like.3F">example</a>
|
||
report from the <a class="reference external" href="http://dmarc.org">dmarc.org</a> wiki. It’s actually an older draft of
|
||
the 1.0 report schema standardized in
|
||
<a class="reference external" href="https://tools.ietf.org/html/rfc7489#appendix-C">RFC 7480 Appendix C</a>.
|
||
This draft schema is still in wide use.</p>
|
||
<p><code class="docutils literal notranslate"><span class="pre">parsedmarc</span></code> produces consistent, normalized output, regardless
|
||
of the report schema.</p>
|
||
<section id="json-aggregate-report">
|
||
<h3>JSON aggregate report<a class="headerlink" href="#json-aggregate-report" title="Link to this heading"></a></h3>
|
||
<div class="highlight-json notranslate"><div class="highlight"><pre><span></span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"xml_schema"</span><span class="p">:</span><span class="w"> </span><span class="s2">"draft"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"report_metadata"</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"org_name"</span><span class="p">:</span><span class="w"> </span><span class="s2">"acme.com"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"org_email"</span><span class="p">:</span><span class="w"> </span><span class="s2">"noreply-dmarc-support@acme.com"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"org_extra_contact_info"</span><span class="p">:</span><span class="w"> </span><span class="s2">"http://acme.com/dmarc/support"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"report_id"</span><span class="p">:</span><span class="w"> </span><span class="s2">"9391651994964116463"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"begin_date"</span><span class="p">:</span><span class="w"> </span><span class="s2">"2012-04-27 20:00:00"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"end_date"</span><span class="p">:</span><span class="w"> </span><span class="s2">"2012-04-28 19:59:59"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"timespan_requires_normalization"</span><span class="p">:</span><span class="w"> </span><span class="kc">false</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"original_timespan_seconds"</span><span class="p">:</span><span class="w"> </span><span class="mi">86399</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"errors"</span><span class="p">:</span><span class="w"> </span><span class="p">[]</span>
|
||
<span class="w"> </span><span class="p">},</span>
|
||
<span class="w"> </span><span class="nt">"policy_published"</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"domain"</span><span class="p">:</span><span class="w"> </span><span class="s2">"example.com"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"adkim"</span><span class="p">:</span><span class="w"> </span><span class="s2">"r"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"aspf"</span><span class="p">:</span><span class="w"> </span><span class="s2">"r"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"p"</span><span class="p">:</span><span class="w"> </span><span class="s2">"none"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"sp"</span><span class="p">:</span><span class="w"> </span><span class="s2">"none"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"pct"</span><span class="p">:</span><span class="w"> </span><span class="s2">"100"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"fo"</span><span class="p">:</span><span class="w"> </span><span class="s2">"0"</span>
|
||
<span class="w"> </span><span class="p">},</span>
|
||
<span class="w"> </span><span class="nt">"records"</span><span class="p">:</span><span class="w"> </span><span class="p">[</span>
|
||
<span class="w"> </span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"source"</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"ip_address"</span><span class="p">:</span><span class="w"> </span><span class="s2">"72.150.241.94"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"country"</span><span class="p">:</span><span class="w"> </span><span class="s2">"US"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"reverse_dns"</span><span class="p">:</span><span class="w"> </span><span class="kc">null</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"base_domain"</span><span class="p">:</span><span class="w"> </span><span class="kc">null</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"name"</span><span class="p">:</span><span class="w"> </span><span class="kc">null</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"type"</span><span class="p">:</span><span class="w"> </span><span class="kc">null</span>
|
||
<span class="w"> </span><span class="p">},</span>
|
||
<span class="w"> </span><span class="nt">"count"</span><span class="p">:</span><span class="w"> </span><span class="mi">2</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"alignment"</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"spf"</span><span class="p">:</span><span class="w"> </span><span class="kc">true</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"dkim"</span><span class="p">:</span><span class="w"> </span><span class="kc">false</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"dmarc"</span><span class="p">:</span><span class="w"> </span><span class="kc">true</span>
|
||
<span class="w"> </span><span class="p">},</span>
|
||
<span class="w"> </span><span class="nt">"policy_evaluated"</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"disposition"</span><span class="p">:</span><span class="w"> </span><span class="s2">"none"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"dkim"</span><span class="p">:</span><span class="w"> </span><span class="s2">"fail"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"spf"</span><span class="p">:</span><span class="w"> </span><span class="s2">"pass"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"policy_override_reasons"</span><span class="p">:</span><span class="w"> </span><span class="p">[]</span>
|
||
<span class="w"> </span><span class="p">},</span>
|
||
<span class="w"> </span><span class="nt">"identifiers"</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"header_from"</span><span class="p">:</span><span class="w"> </span><span class="s2">"example.com"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"envelope_from"</span><span class="p">:</span><span class="w"> </span><span class="s2">"example.com"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"envelope_to"</span><span class="p">:</span><span class="w"> </span><span class="kc">null</span>
|
||
<span class="w"> </span><span class="p">},</span>
|
||
<span class="w"> </span><span class="nt">"auth_results"</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"dkim"</span><span class="p">:</span><span class="w"> </span><span class="p">[</span>
|
||
<span class="w"> </span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"domain"</span><span class="p">:</span><span class="w"> </span><span class="s2">"example.com"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"selector"</span><span class="p">:</span><span class="w"> </span><span class="s2">"none"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"result"</span><span class="p">:</span><span class="w"> </span><span class="s2">"fail"</span>
|
||
<span class="w"> </span><span class="p">}</span>
|
||
<span class="w"> </span><span class="p">],</span>
|
||
<span class="w"> </span><span class="nt">"spf"</span><span class="p">:</span><span class="w"> </span><span class="p">[</span>
|
||
<span class="w"> </span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"domain"</span><span class="p">:</span><span class="w"> </span><span class="s2">"example.com"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"scope"</span><span class="p">:</span><span class="w"> </span><span class="s2">"mfrom"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"result"</span><span class="p">:</span><span class="w"> </span><span class="s2">"pass"</span>
|
||
<span class="w"> </span><span class="p">}</span>
|
||
<span class="w"> </span><span class="p">]</span>
|
||
<span class="w"> </span><span class="p">},</span>
|
||
<span class="w"> </span><span class="nt">"normalized_timespan"</span><span class="p">:</span><span class="w"> </span><span class="kc">false</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"interval_begin"</span><span class="p">:</span><span class="w"> </span><span class="s2">"2012-04-28 00:00:00"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"interval_end"</span><span class="p">:</span><span class="w"> </span><span class="s2">"2012-04-28 23:59:59"</span>
|
||
<span class="w"> </span><span class="p">}</span>
|
||
<span class="w"> </span><span class="p">]</span>
|
||
<span class="p">}</span>
|
||
</pre></div>
|
||
</div>
|
||
</section>
|
||
<section id="csv-aggregate-report">
|
||
<h3>CSV aggregate report<a class="headerlink" href="#csv-aggregate-report" title="Link to this heading"></a></h3>
|
||
<div class="highlight-text notranslate"><div class="highlight"><pre><span></span>xml_schema,org_name,org_email,org_extra_contact_info,report_id,begin_date,end_date,normalized_timespan,errors,domain,adkim,aspf,p,sp,pct,fo,source_ip_address,source_country,source_reverse_dns,source_base_domain,source_name,source_type,count,spf_aligned,dkim_aligned,dmarc_aligned,disposition,policy_override_reasons,policy_override_comments,envelope_from,header_from,envelope_to,dkim_domains,dkim_selectors,dkim_results,spf_domains,spf_scopes,spf_results
|
||
draft,acme.com,noreply-dmarc-support@acme.com,http://acme.com/dmarc/support,9391651994964116463,2012-04-28 00:00:00,2012-04-28 23:59:59,False,,example.com,r,r,none,none,100,0,72.150.241.94,US,,,,,2,True,False,True,none,,,example.com,example.com,,example.com,none,fail,example.com,mfrom,pass
|
||
draft,acme.com,noreply-dmarc-support@acme.com,http://acme.com/dmarc/support,9391651994964116463,2012-04-28 00:00:00,2012-04-28 23:59:59,False,,example.com,r,r,none,none,100,0,72.150.241.94,US,,,,,2,True,False,True,none,,,example.com,example.com,,example.com,none,fail,example.com,mfrom,pass
|
||
</pre></div>
|
||
</div>
|
||
</section>
|
||
</section>
|
||
<section id="sample-forensic-report-output">
|
||
<h2>Sample forensic report output<a class="headerlink" href="#sample-forensic-report-output" title="Link to this heading"></a></h2>
|
||
<p>Thanks to GitHub user <a class="reference external" href="https://github.com/xennn">xennn</a> for the anonymized
|
||
<a class="reference external" href="https://github.com/domainaware/parsedmarc/raw/master/samples/forensic/DMARC%20Failure%20Report%20for%20domain.de%20(mail-from%3Dsharepoint%40domain.de%2C%20ip%3D10.10.10.10).eml">forensic report email sample</a>.</p>
|
||
<section id="json-forensic-report">
|
||
<h3>JSON forensic report<a class="headerlink" href="#json-forensic-report" title="Link to this heading"></a></h3>
|
||
<div class="highlight-json notranslate"><div class="highlight"><pre><span></span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"feedback_type"</span><span class="p">:</span><span class="w"> </span><span class="s2">"auth-failure"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"user_agent"</span><span class="p">:</span><span class="w"> </span><span class="s2">"Lua/1.0"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"version"</span><span class="p">:</span><span class="w"> </span><span class="s2">"1.0"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"original_mail_from"</span><span class="p">:</span><span class="w"> </span><span class="s2">"sharepoint@domain.de"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"original_rcpt_to"</span><span class="p">:</span><span class="w"> </span><span class="s2">"peter.pan@domain.de"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"arrival_date"</span><span class="p">:</span><span class="w"> </span><span class="s2">"Mon, 01 Oct 2018 11:20:27 +0200"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"message_id"</span><span class="p">:</span><span class="w"> </span><span class="s2">"<38.E7.30937.BD6E1BB5@ mailrelay.de>"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"authentication_results"</span><span class="p">:</span><span class="w"> </span><span class="s2">"dmarc=fail (p=none, dis=none) header.from=domain.de"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"delivery_result"</span><span class="p">:</span><span class="w"> </span><span class="s2">"policy"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"auth_failure"</span><span class="p">:</span><span class="w"> </span><span class="p">[</span>
|
||
<span class="w"> </span><span class="s2">"dmarc"</span>
|
||
<span class="w"> </span><span class="p">],</span>
|
||
<span class="w"> </span><span class="nt">"reported_domain"</span><span class="p">:</span><span class="w"> </span><span class="s2">"domain.de"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"arrival_date_utc"</span><span class="p">:</span><span class="w"> </span><span class="s2">"2018-10-01 09:20:27"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"source"</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"ip_address"</span><span class="p">:</span><span class="w"> </span><span class="s2">"10.10.10.10"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"country"</span><span class="p">:</span><span class="w"> </span><span class="kc">null</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"reverse_dns"</span><span class="p">:</span><span class="w"> </span><span class="kc">null</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"base_domain"</span><span class="p">:</span><span class="w"> </span><span class="kc">null</span>
|
||
<span class="w"> </span><span class="p">},</span>
|
||
<span class="w"> </span><span class="nt">"authentication_mechanisms"</span><span class="p">:</span><span class="w"> </span><span class="p">[],</span>
|
||
<span class="w"> </span><span class="nt">"original_envelope_id"</span><span class="p">:</span><span class="w"> </span><span class="kc">null</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"dkim_domain"</span><span class="p">:</span><span class="w"> </span><span class="kc">null</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"sample_headers_only"</span><span class="p">:</span><span class="w"> </span><span class="kc">false</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"sample"</span><span class="p">:</span><span class="w"> </span><span class="s2">"Received: from Servernameone.domain.local (Servernameone.domain.local [10.10.10.10])\n\tby mailrelay.de (mail.DOMAIN.de) with SMTP id 38.E7.30937.BD6E1BB5; Mon, 1 Oct 2018 11:20:27 +0200 (CEST)\nDate: 01 Oct 2018 11:20:27 +0200\nMessage-ID: <38.E7.30937.BD6E1BB5@ mailrelay.de>\nTo: <peter.pan@domain.de>\nfrom: \"=?utf-8?B?SW50ZXJha3RpdmUgV2V0dGJld2VyYmVyLcOcYmVyc2ljaHQ=?=\" <sharepoint@domain.de>\nSubject: Subject\nMIME-Version: 1.0\nX-Mailer: Microsoft SharePoint Foundation 2010\nContent-Type: text/html; charset=utf-8\nContent-Transfer-Encoding: quoted-printable\n\n<html><head><base href=3D'\nwettbewerb' /></head><body><!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 3.2//EN\"=\n><HTML><HEAD><META NAME=3D\"Generator\" CONTENT=3D\"MS Exchange Server version=\n 08.01.0240.003\"></html>\n"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"parsed_sample"</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"from"</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"display_name"</span><span class="p">:</span><span class="w"> </span><span class="s2">"Interaktive Wettbewerber-Übersicht"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"address"</span><span class="p">:</span><span class="w"> </span><span class="s2">"sharepoint@domain.de"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"local"</span><span class="p">:</span><span class="w"> </span><span class="s2">"sharepoint"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"domain"</span><span class="p">:</span><span class="w"> </span><span class="s2">"domain.de"</span>
|
||
<span class="w"> </span><span class="p">},</span>
|
||
<span class="w"> </span><span class="nt">"to_domains"</span><span class="p">:</span><span class="w"> </span><span class="p">[</span>
|
||
<span class="w"> </span><span class="s2">"domain.de"</span>
|
||
<span class="w"> </span><span class="p">],</span>
|
||
<span class="w"> </span><span class="nt">"to"</span><span class="p">:</span><span class="w"> </span><span class="p">[</span>
|
||
<span class="w"> </span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"display_name"</span><span class="p">:</span><span class="w"> </span><span class="kc">null</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"address"</span><span class="p">:</span><span class="w"> </span><span class="s2">"peter.pan@domain.de"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"local"</span><span class="p">:</span><span class="w"> </span><span class="s2">"peter.pan"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"domain"</span><span class="p">:</span><span class="w"> </span><span class="s2">"domain.de"</span>
|
||
<span class="w"> </span><span class="p">}</span>
|
||
<span class="w"> </span><span class="p">],</span>
|
||
<span class="w"> </span><span class="nt">"subject"</span><span class="p">:</span><span class="w"> </span><span class="s2">"Subject"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"timezone"</span><span class="p">:</span><span class="w"> </span><span class="s2">"+2"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"mime-version"</span><span class="p">:</span><span class="w"> </span><span class="s2">"1.0"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"date"</span><span class="p">:</span><span class="w"> </span><span class="s2">"2018-10-01 09:20:27"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"content-type"</span><span class="p">:</span><span class="w"> </span><span class="s2">"text/html; charset=utf-8"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"x-mailer"</span><span class="p">:</span><span class="w"> </span><span class="s2">"Microsoft SharePoint Foundation 2010"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"body"</span><span class="p">:</span><span class="w"> </span><span class="s2">"<html><head><base href='\nwettbewerb' /></head><body><!DOCTYPE HTML PUBLIC \"-//W3C//DTD HTML 3.2//EN\"><HTML><HEAD><META NAME=\"Generator\" CONTENT=\"MS Exchange Server version 08.01.0240.003\"></html>"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"received"</span><span class="p">:</span><span class="w"> </span><span class="p">[</span>
|
||
<span class="w"> </span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"from"</span><span class="p">:</span><span class="w"> </span><span class="s2">"Servernameone.domain.local Servernameone.domain.local 10.10.10.10"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"by"</span><span class="p">:</span><span class="w"> </span><span class="s2">"mailrelay.de mail.DOMAIN.de"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"with"</span><span class="p">:</span><span class="w"> </span><span class="s2">"SMTP id 38.E7.30937.BD6E1BB5"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"date"</span><span class="p">:</span><span class="w"> </span><span class="s2">"Mon, 1 Oct 2018 11:20:27 +0200 CEST"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"hop"</span><span class="p">:</span><span class="w"> </span><span class="mi">1</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"date_utc"</span><span class="p">:</span><span class="w"> </span><span class="s2">"2018-10-01 09:20:27"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"delay"</span><span class="p">:</span><span class="w"> </span><span class="mi">0</span>
|
||
<span class="w"> </span><span class="p">}</span>
|
||
<span class="w"> </span><span class="p">],</span>
|
||
<span class="w"> </span><span class="nt">"content-transfer-encoding"</span><span class="p">:</span><span class="w"> </span><span class="s2">"quoted-printable"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"message-id"</span><span class="p">:</span><span class="w"> </span><span class="s2">"<38.E7.30937.BD6E1BB5@ mailrelay.de>"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"has_defects"</span><span class="p">:</span><span class="w"> </span><span class="kc">false</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"headers"</span><span class="p">:</span><span class="w"> </span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"Received"</span><span class="p">:</span><span class="w"> </span><span class="s2">"from Servernameone.domain.local (Servernameone.domain.local [10.10.10.10])\n\tby mailrelay.de (mail.DOMAIN.de) with SMTP id 38.E7.30937.BD6E1BB5; Mon, 1 Oct 2018 11:20:27 +0200 (CEST)"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"Date"</span><span class="p">:</span><span class="w"> </span><span class="s2">"01 Oct 2018 11:20:27 +0200"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"Message-ID"</span><span class="p">:</span><span class="w"> </span><span class="s2">"<38.E7.30937.BD6E1BB5@ mailrelay.de>"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"To"</span><span class="p">:</span><span class="w"> </span><span class="s2">"<peter.pan@domain.de>"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"from"</span><span class="p">:</span><span class="w"> </span><span class="s2">"\"Interaktive Wettbewerber-Übersicht\" <sharepoint@domain.de>"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"Subject"</span><span class="p">:</span><span class="w"> </span><span class="s2">"Subject"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"MIME-Version"</span><span class="p">:</span><span class="w"> </span><span class="s2">"1.0"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"X-Mailer"</span><span class="p">:</span><span class="w"> </span><span class="s2">"Microsoft SharePoint Foundation 2010"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"Content-Type"</span><span class="p">:</span><span class="w"> </span><span class="s2">"text/html; charset=utf-8"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"Content-Transfer-Encoding"</span><span class="p">:</span><span class="w"> </span><span class="s2">"quoted-printable"</span>
|
||
<span class="w"> </span><span class="p">},</span>
|
||
<span class="w"> </span><span class="nt">"reply_to"</span><span class="p">:</span><span class="w"> </span><span class="p">[],</span>
|
||
<span class="w"> </span><span class="nt">"cc"</span><span class="p">:</span><span class="w"> </span><span class="p">[],</span>
|
||
<span class="w"> </span><span class="nt">"bcc"</span><span class="p">:</span><span class="w"> </span><span class="p">[],</span>
|
||
<span class="w"> </span><span class="nt">"attachments"</span><span class="p">:</span><span class="w"> </span><span class="p">[],</span>
|
||
<span class="w"> </span><span class="nt">"filename_safe_subject"</span><span class="p">:</span><span class="w"> </span><span class="s2">"Subject"</span>
|
||
<span class="w"> </span><span class="p">}</span>
|
||
<span class="w"> </span><span class="p">}</span>
|
||
</pre></div>
|
||
</div>
|
||
</section>
|
||
<section id="csv-forensic-report">
|
||
<h3>CSV forensic report<a class="headerlink" href="#csv-forensic-report" title="Link to this heading"></a></h3>
|
||
<div class="highlight-text notranslate"><div class="highlight"><pre><span></span>feedback_type,user_agent,version,original_envelope_id,original_mail_from,original_rcpt_to,arrival_date,arrival_date_utc,subject,message_id,authentication_results,dkim_domain,source_ip_address,source_country,source_reverse_dns,source_base_domain,delivery_result,auth_failure,reported_domain,authentication_mechanisms,sample_headers_only
|
||
auth-failure,Lua/1.0,1.0,,sharepoint@domain.de,peter.pan@domain.de,"Mon, 01 Oct 2018 11:20:27 +0200",2018-10-01 09:20:27,Subject,<38.E7.30937.BD6E1BB5@ mailrelay.de>,"dmarc=fail (p=none, dis=none) header.from=domain.de",,10.10.10.10,,,,policy,dmarc,domain.de,,False
|
||
</pre></div>
|
||
</div>
|
||
</section>
|
||
<section id="json-smtp-tls-report">
|
||
<h3>JSON SMTP TLS report<a class="headerlink" href="#json-smtp-tls-report" title="Link to this heading"></a></h3>
|
||
<div class="highlight-json notranslate"><div class="highlight"><pre><span></span><span class="p">[</span>
|
||
<span class="w"> </span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"organization_name"</span><span class="p">:</span><span class="w"> </span><span class="s2">"Example Inc."</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"begin_date"</span><span class="p">:</span><span class="w"> </span><span class="s2">"2024-01-09T00:00:00Z"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"end_date"</span><span class="p">:</span><span class="w"> </span><span class="s2">"2024-01-09T23:59:59Z"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"report_id"</span><span class="p">:</span><span class="w"> </span><span class="s2">"2024-01-09T00:00:00Z_example.com"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"policies"</span><span class="p">:</span><span class="w"> </span><span class="p">[</span>
|
||
<span class="w"> </span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"policy_domain"</span><span class="p">:</span><span class="w"> </span><span class="s2">"example.com"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"policy_type"</span><span class="p">:</span><span class="w"> </span><span class="s2">"sts"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"policy_strings"</span><span class="p">:</span><span class="w"> </span><span class="p">[</span>
|
||
<span class="w"> </span><span class="s2">"version: STSv1"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="s2">"mode: testing"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="s2">"mx: example.com"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="s2">"max_age: 86400"</span>
|
||
<span class="w"> </span><span class="p">],</span>
|
||
<span class="w"> </span><span class="nt">"successful_session_count"</span><span class="p">:</span><span class="w"> </span><span class="mi">0</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"failed_session_count"</span><span class="p">:</span><span class="w"> </span><span class="mi">3</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"failure_details"</span><span class="p">:</span><span class="w"> </span><span class="p">[</span>
|
||
<span class="w"> </span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"result_type"</span><span class="p">:</span><span class="w"> </span><span class="s2">"validation-failure"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"failed_session_count"</span><span class="p">:</span><span class="w"> </span><span class="mi">2</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"sending_mta_ip"</span><span class="p">:</span><span class="w"> </span><span class="s2">"209.85.222.201"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"receiving_ip"</span><span class="p">:</span><span class="w"> </span><span class="s2">"173.212.201.41"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"receiving_mx_hostname"</span><span class="p">:</span><span class="w"> </span><span class="s2">"example.com"</span>
|
||
<span class="w"> </span><span class="p">},</span>
|
||
<span class="w"> </span><span class="p">{</span>
|
||
<span class="w"> </span><span class="nt">"result_type"</span><span class="p">:</span><span class="w"> </span><span class="s2">"validation-failure"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"failed_session_count"</span><span class="p">:</span><span class="w"> </span><span class="mi">1</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"sending_mta_ip"</span><span class="p">:</span><span class="w"> </span><span class="s2">"209.85.208.176"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"receiving_ip"</span><span class="p">:</span><span class="w"> </span><span class="s2">"173.212.201.41"</span><span class="p">,</span>
|
||
<span class="w"> </span><span class="nt">"receiving_mx_hostname"</span><span class="p">:</span><span class="w"> </span><span class="s2">"example.com"</span>
|
||
<span class="w"> </span><span class="p">}</span>
|
||
<span class="w"> </span><span class="p">]</span>
|
||
<span class="w"> </span><span class="p">}</span>
|
||
<span class="w"> </span><span class="p">]</span>
|
||
<span class="w"> </span><span class="p">}</span>
|
||
<span class="p">]</span>
|
||
</pre></div>
|
||
</div>
|
||
</section>
|
||
</section>
|
||
</section>
|
||
|
||
|
||
</div>
|
||
</div>
|
||
<footer><div class="rst-footer-buttons" role="navigation" aria-label="Footer">
|
||
<a href="usage.html" class="btn btn-neutral float-left" title="Using parsedmarc" accesskey="p" rel="prev"><span class="fa fa-arrow-circle-left" aria-hidden="true"></span> Previous</a>
|
||
<a href="elasticsearch.html" class="btn btn-neutral float-right" title="Elasticsearch and Kibana" accesskey="n" rel="next">Next <span class="fa fa-arrow-circle-right" aria-hidden="true"></span></a>
|
||
</div>
|
||
|
||
<hr/>
|
||
|
||
<div role="contentinfo">
|
||
<p>© Copyright 2018 - 2025, Sean Whalen and contributors.</p>
|
||
</div>
|
||
|
||
Built with <a href="https://www.sphinx-doc.org/">Sphinx</a> using a
|
||
<a href="https://github.com/readthedocs/sphinx_rtd_theme">theme</a>
|
||
provided by <a href="https://readthedocs.org">Read the Docs</a>.
|
||
|
||
|
||
</footer>
|
||
</div>
|
||
</div>
|
||
</section>
|
||
</div>
|
||
<script>
|
||
jQuery(function () {
|
||
SphinxRtdTheme.Navigation.enable(true);
|
||
});
|
||
</script>
|
||
|
||
</body>
|
||
</html> |