Saltar al contenido
05 · Arquitectura05 · Architecture

Seguridad del Correo (DMARC / SPF / DKIM)Email Security (DMARC / SPF / DKIM)

Autenticación del dominio de correo y bloqueo de suplantación.Mail domain authentication and blocking of impersonation attempts.

DMARC · SPF · DKIM · MTA-STSDMARC · SPF · DKIM · MTA-STS Diseño y despliegue de tecnología de seguridadDesign and deployment of security technology

¿Qué es este servicio?What is this service?

Es la autenticación del dominio de correo: publicar y mantener los registros SPF, DKIM y DMARC, leer los informes que devuelven los receptores y endurecer la política hasta que el correo falsificado se rechace. Incluye MTA-STS para forzar que el correo entrante viaje cifrado hacia los servidores de la organización.

Authentication of the corporate mail domain: publishing and maintaining SPF, DKIM and DMARC records, reading the reports receivers send back and hardening the policy until forged mail is rejected. It includes MTA-STS to force inbound mail to travel encrypted towards the servers of the organisation.

¿Para qué se usa?What is it used for?

Impide que un tercero envíe correo firmado con el dominio de la organización a sus clientes, a sus proveedores o a su propio personal. Conviene decir lo incómodo: DMARC solo protege cuando la política llega a rechazo. Quedarse en modo observación durante años, que es exactamente lo que hace la mayoría, no bloquea absolutamente nada: solo genera informes que nadie lee.

It stops a third party sending mail signed with the domain of the organisation to its clients, its suppliers or its own staff. The uncomfortable part deserves to be stated: DMARC only protects once the policy reaches reject. Sitting in monitoring mode for years, which is exactly what most organisations do, blocks nothing at all: it merely produces reports nobody reads.

Qué beneficios traeBenefits it delivers

  • Con la política en rechazo, la suplantación directa del dominio deja de funcionar. Es de los pocos controles que eliminan un vector entero.
  • Mejora la entregabilidad del correo legítimo: los grandes proveedores ya penalizan a los dominios sin autenticar.
  • Los informes DMARC revelan qué sistemas envían correo en nombre de la organización, y casi siempre aparecen dos o tres que nadie recordaba.
  • Cuesta poco: es configuración de DNS y disciplina, no una compra de licencias.
  • With the policy at reject, direct spoofing of the domain stops working. It is one of the few controls that removes an entire vector.
  • It improves deliverability of legitimate mail: major providers already penalise unauthenticated domains.
  • DMARC reports reveal which systems send mail on behalf of the organisation, and two or three nobody remembered always turn up.
  • It is cheap: DNS configuration and discipline, not a licence purchase.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • No hay obligación legal de implementar DMARC en Costa Rica.
  • El Acuerdo CONASSIF 5-24 espera de las entidades supervisadas controles sobre los canales de comunicación con clientes, y el correo suplantado es el origen habitual del fraude que después hay que reportar.
  • There is no legal obligation to implement DMARC in Costa Rica.
  • CONASSIF Agreement 5-24 expects supervised entities to control their client communication channels, and spoofed email is the usual origin of the fraud that later has to be reported.

InternacionalInternational

  • Ningún marco general lo exige por nombre, pero los grandes proveedores de correo ya lo imponen de hecho a quien envía volumen.
  • ISO 27001 exige proteger la información en tránsito y los servicios de mensajería.
  • Muchos programas de seguros y de gestión de proveedores lo piden hoy como requisito de entrada.
  • No general framework requires it by name, but the large mail providers already impose it in practice on bulk senders.
  • ISO 27001 requires protecting information in transit and messaging services.
  • Many insurance and vendor management programmes now ask for it as an entry requirement.

Requisitos mínimosMinimum requirements

  • Control sobre el DNS del dominio y de los subdominios que envían correo.
  • Un inventario honesto de todo lo que envía correo en nombre de la organización: la plataforma corporativa, el CRM, el ERP, la facturación, el proveedor de campañas.
  • Acceso a la consola del proveedor de correo para firmar con DKIM.
  • Voluntad de llegar a rechazo. Si la decisión es quedarse en observación, conviene no emprender el proyecto: no habrá protección real.
  • Control over the DNS of the domain and of any subdomains that send mail.
  • An honest inventory of everything sending mail on behalf of the organisation: the corporate platform, the CRM, the ERP, billing, the campaign provider.
  • Access to the mail provider console in order to sign with DKIM.
  • The will to reach reject. If the decision is to stay in monitoring, the project is not worth commissioning: no real protection will follow.

Plazo típico de entregaTypical delivery time

6 a 12 semanas 6 to 12 weeks rango habitual del mercado usual market range

El rango habitual va de seis a doce semanas hasta llegar a política de rechazo. La configuración inicial se hace en días; lo que consume el tiempo es la fase de observación, donde hay que descubrir y autenticar todos los emisores legítimos antes de endurecer, para no cortarle el correo a facturación. Cae en el extremo bajo si hay un solo emisor, y en el alto cuando aparecen sistemas heredados sin dueño.

The usual range runs from six to twelve weeks to reach a reject policy. Initial configuration takes days; what consumes time is the monitoring phase, where every legitimate sender must be found and authenticated before hardening, so that billing does not lose its mail. It lands at the low end with a single sender, and at the high end when ownerless legacy systems surface.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

SPFSPF
Registro en el DNS que lista qué servidores tienen permiso para enviar correo con el dominio de la organización. A DNS record listing which servers are allowed to send mail using the domain of the organisation.
DKIMDKIM
Firma criptográfica que se añade a cada mensaje y permite comprobar que no fue alterado ni falsificado. A cryptographic signature added to each message, proving it was neither altered nor forged.
DMARCDMARC
La política que le indica al receptor qué hacer cuando un correo no pasa SPF ni DKIM: nada, cuarentena o rechazo. The policy telling the receiver what to do when a message passes neither SPF nor DKIM: nothing, quarantine or reject.
p=none · p=rejectp=none · p=reject
Los extremos de la política DMARC. El primero solo observa e informa; el segundo es el único que bloquea. The extremes of the DMARC policy. The first only observes and reports; the second is the only one that blocks.
MTA-STSMTA-STS
Mecanismo que obliga a que el correo dirigido al dominio viaje cifrado, para que nadie lo intercepte en el camino. A mechanism forcing mail addressed to the domain to travel encrypted, so nobody intercepts it in transit.