ドメインセキュリティ

DNSSEC、SSL/TLS、ドメインハイジャック対策、悪用防止について説明します。

DNSSEC

Cryptographic extensions that authenticate DNS responses to prevent tampering.

SSL/TLS証明書

Cryptographic certificate enabling encrypted HTTPS connections for a domain.

ドメインハイジャック

Unauthorized takeover of a domain through social engineering or security exploits.

ドメインセキュリティ

All measures protecting domain names from unauthorized access or modification.

HTTPS要件(HSTS)

TLD-level requirement for HTTPS, enforced via browser HSTS preload lists.

DNSスプーフィング(キャッシュポイズニング)

Attack that corrupts DNS cache data to redirect users to malicious sites.

タイポスクワッティング

Registering misspelled variants of popular domains to capture mistyped traffic.

サイバースクワッティング

Registering domains in bad faith that infringe on existing trademarks.

SPFレコード

DNS TXT record specifying authorized email-sending servers for a domain.

DMARC

Email authentication protocol that uses SPF and DKIM to prevent email spoofing.

DKIM

Email authentication adding digital signatures verified via DNS public keys.

ドメイン悪用

Malicious use of domains for phishing, malware, spam, or fraud.

ドメインシャドウイング

Attack creating malicious subdomains under a legitimate domain after compromising its registrar account.

DNS リバインディング

Attack that tricks browsers into accessing internal network resources by rapidly changing a domain's DNS resolution.

証明書の透明性 (CT)

Open standard requiring all TLS certificates to be recorded in public, auditable logs for transparency and abuse detection.

HSTS プリロード

Submission of a domain to browser preload lists ensuring HTTPS-only access from the very first connection.

DANE (DNS による名前付きエンティティ認証)

Protocol using DNSSEC-signed TLSA records to bind TLS certificates to domains, bypassing traditional CA trust.

RPZ(レスポンスポリシーゾーン)

DNS firewall mechanism allowing resolvers to block or redirect queries for domains on threat intelligence lists.

ドメインフロンティング

Technique hiding traffic's true destination by using a trusted domain's CDN infrastructure to route encrypted requests.

BIMI(メッセージ識別のためのブランドインジケーター)

Email standard enabling verified brand logos in inboxes, requiring DMARC enforcement and a Verified Mark Certificate.

MTA-STS(メール転送エージェント厳密トランスポートセキュリティ)

Standard requiring mail servers to use valid TLS when delivering email to a domain, preventing TLS downgrade attacks.

ドメインレピュテーション

Score assigned to a domain based on abuse history, email behavior, and content signals used by filters and security systems.