ð DNS解説_ã€ã³ã¿ãŒãããã®äœæé²ãåžãä»çµã¿
ð ã¯ããã«
ç§ãã¡ãæ¥åžžçã«ã€ã³ã¿ãŒãããã䜿ãæããgoogle.comãããyoutube.comããªã©ã®ããããããååãå ¥åããããšã§ãŠã§ããµã€ãã«ã¢ã¯ã»ã¹ã§ããŸããããããã³ã³ãã¥ãŒã¿ã®äžçã§ã¯ããããã®ãŠã§ããµã€ãã¯å®éã«ã¯ã172.217.175.110ãã®ãããªæ°åã®çŸ åïŒIPã¢ãã¬ã¹ïŒã§ç®¡çãããŠããŸãããã®ãååããšãäœæããçµã³ã€ããä»çµã¿ããDNSïŒDomain Name SystemïŒãã§ãããã®èšäºã§ã¯ãDNSã®åºæ¬ããä»çµã¿ãæŽ»çšæ¹æ³ãŸã§ãååŠè åãã«ãããããã解説ããŸãã
ð€ DNSãšã¯ïŒ
DNSïŒDomain Name SystemïŒã¯ã人éãèŠãããããã¡ã€ã³åïŒäŸïŒexample.comïŒãã³ã³ãã¥ãŒã¿ãçè§£ã§ããIPã¢ãã¬ã¹ïŒäŸïŒ93.184.216.34ïŒã«å€æããã·ã¹ãã ã§ãã
ð« ããšãã§çè§£ããã
DNSã¯ãé»è©±åž³ãããäœæé²ãã®ãããªãã®ã§ããåéã«é»è©±ãããããšããç§ãã¡ã¯11æ¡ã®é»è©±çªå·ãå šéšèŠããã®ã§ã¯ãªãããç°äžããããšããååããé»è©±åž³ã§çªå·ã調ã¹ãŸããåæ§ã«ãã³ã³ãã¥ãŒã¿ãDNSã䜿ã£ãŠãgoogle.comããšããååãã察å¿ããIPã¢ãã¬ã¹ã調ã¹ãã®ã§ãã
!
ð¯ DNSã®åœ¹å²ãšéèŠæ§
â DNSã®äž»ãªåœ¹å²
- ð€âð¢ åå解決: ãã¡ã€ã³åãIPã¢ãã¬ã¹ã«å€æãã
- ð è² è·åæ£: åããã¡ã€ã³åã«è€æ°ã®IPã¢ãã¬ã¹ãé¢é£ä»ããããšã§ãã©ãã£ãã¯ã忣
- ð§ ã¡ãŒã«é é: ã¡ãŒã«ãµãŒããŒã®å Žæãç¹å®ããããã®MXã¬ã³ãŒããæäŸ
- ð ãµãŒãã¹æ€åº: ç¹å®ã®ãµãŒãã¹ãæäŸãããµãŒããŒã®æ å ±ãæäŸ
ð DNSã®éèŠæ§
DNSããªããã°ãã€ã³ã¿ãŒãããã¯ä»æ¥ã®ããã«äœ¿ãããããã®ã«ã¯ãªããŸããã§ããã以äžã®ãããªéèŠãªåœ¹å²ãæãããŠããŸãïŒ
- ð§ èšæ¶ã®è£å©: è€éãªIPã¢ãã¬ã¹ã®ä»£ããã«èŠããããååã䜿çšå¯èœã«
- ð æè»æ§: ãµãŒããŒã®IPã¢ãã¬ã¹ãå€ãã£ãŠããåããã¡ã€ã³åã§ã¢ã¯ã»ã¹å¯èœ
- ð å¹çæ§: ãã£ãã·ã¥æ©èœã«ããé«éãªã¢ã¯ã»ã¹ãå®çŸ
- ð ã°ããŒãã«å: 忣åã®ã·ã¹ãã ã«ããäžçäžã©ãããã§ãåå解決ãå¯èœ
!
ðïž DNSã®éå±€æ§é
DNSã¯éå±€çãªæ§é ã«ãªã£ãŠãããããã¡ã€ã³å空éããšåŒã°ããæšæ§é ã圢æããŠããŸãããã®æ§é ã®ãããã§ãå¹ççãªåå解決ãå¯èœã«ãªã£ãŠããŸãã
ð³ ãã¡ã€ã³åã®éå±€
- ð ã«ãŒãïŒ.ïŒ: æäžäœå±€ïŒéåžžã¯è¡šèšãããªãïŒ
- ð ãããã¬ãã«ãã¡ã€ã³ïŒTLDïŒ: .com, .org, .net, .jp ãªã©ã®æäžäœã®åé¡
- ð¢ ã»ã«ã³ãã¬ãã«ãã¡ã€ã³ïŒSLDïŒ: example.com ã®ãexampleãéšå
- ð ãµããã¡ã€ã³: blog.example.com ã®ãblogãéšå
!
ð¡ ååŠè åããã€ã³ã
ãã¡ã€ã³åã¯å³ããå·Šãžãšéå±€ãæ·±ããªããŸããexample.comã§ã¯ãã.comããTLDããexampleããSLDã§ããããã¯äœæã®ãåœâçâåžâçºâçªå°ãã®ãããªéå±€æ§é ã«äŒŒãŠããŸãã
ðïž DNSãµãŒããŒã®çš®é¡
DNSã·ã¹ãã ã¯ãæ§ã ãªçš®é¡ã®ãµãŒããŒã«ãã£ãŠæ¯ããããŠããŸãïŒ
- ð ã«ãŒãDNSãµãŒããŒ: ã€ã³ã¿ãŒãããã®æäžäœã«äœçœ®ããäžçã«13çµååš
- ð TLDããŒã ãµãŒããŒ: .com, .org ãªã©ã®ãããã¬ãã«ãã¡ã€ã³ã管ç
- ð¢ æš©åšDNSãµãŒããŒ: ç¹å®ã®ãã¡ã€ã³ïŒexample.com ãªã©ïŒã®å ¬åŒãªæ å ±ã管ç
- ð ååž°çDNSãµãŒããŒ: ãŠãŒã¶ãŒããã®åãåãããåããä»ã®DNSãµãŒããŒã«åãåãããŠåçãè¿ãïŒISPãGoogle Public DNSïŒ8.8.8.8ïŒãªã©ïŒ
ð DNS解決ã®ä»çµã¿ïŒ8ã¹ããã
ãã©ãŠã¶ã§ãwww.example.comããšå ¥åããŠããWebããŒãžã衚瀺ããããŸã§ãDNSã®åå解決ã¯è€æ°ã®ã¹ããããçµãŠè¡ãããŸãã
!
ð ãªãã»ã©ïŒãã€ã³ã
ãã®äžé£ã®æµãã¯ãååž°çãªæ€çŽ¢ããšåŒã°ããŸãã峿žé€šã§æ¬ãæ¢ããšãããŸãç·åæ¡å æã§æ£ã®å ŽæãèãïŒã«ãŒããµãŒããŒïŒããã®æ£ã®ããéšå±ã«è¡ãïŒTLDãµãŒããŒïŒãããã«è©³ããæ£ã®äœçœ®ã確èªãïŒæš©åšãµãŒããŒïŒãæçµçã«ç®çã®æ¬ãèŠã€ããæµãã«äŒŒãŠããŸãã
ð DNSã¬ã³ãŒãã®çš®é¡
DNSãµãŒããŒã«ã¯ãæ§ã ãªçš®é¡ã®æ å ±ïŒDNSã¬ã³ãŒãïŒãä¿åãããŠããŸããäž»ãªã¬ã³ãŒãã®çš®é¡ã¯ä»¥äžã®éãã§ãïŒ
äž»èŠãªDNSã¬ã³ãŒã
ð·ïž ã¬ã³ãŒãã¿ã€ã | ð 説æ | ð çšéäŸ |
---|---|---|
A | ãã¡ã€ã³åãIPv4ã¢ãã¬ã¹ã«é¢é£ä»ãã | ãŠã§ããµã€ãã®ãµãŒããŒIPãæå® |
AAAA | ãã¡ã€ã³åãIPv6ã¢ãã¬ã¹ã«é¢é£ä»ãã | IPv6察å¿ãµãŒããŒã®IPãæå® |
CNAME | ããååãå¥ã®ååã«é¢é£ä»ããïŒãšã€ãªã¢ã¹ïŒ | www.example.com â example.com |
MX | ã¡ãŒã«é éå ã®ãµãŒããŒãæå® | example.comã®ã¡ãŒã«ãmail.example.comã§åä¿¡ |
TXT | ããã¹ãæ å ±ãä¿å | SPF, DKIMïŒã¡ãŒã«èªèšŒïŒã®èšå® |
NS | ãã¡ã€ã³ã®ããŒã ãµãŒããŒãæå® | example.comã®æš©åšãµãŒããŒãæå® |
SOA | ãã¡ã€ã³ã®ç®¡çæ å ±ïŒéå§æš©éïŒ | ãŸãŒã³æ å ±ãæŽæ°ééã管çè ã¡ãŒã«ã¢ãã¬ã¹ãªã© |
PTR | IPã¢ãã¬ã¹ãããã¡ã€ã³åãéåŒã | éåŒãDNSæ€çŽ¢çš |
!
ð¡ ååŠè åããã€ã³ã
CNAMEã¬ã³ãŒãã¯ãå¥åãã®ãããªãã®ã§ããäŸãã°ããå±±ç°å€ªéãããã®ããã¯ããŒã ããã€ãã¡ãããã®å Žåããã€ãã¡ããããšåŒãã§ããå±±ç°å€ªéãããã®ãšããã«é£çµ¡ãè¡ããããªã€ã¡ãŒãžã§ãã
ð DNSã¬ã³ãŒãã®å®äŸ
å®éã®DNSã¬ã³ãŒãã®äŸãèŠãŠã¿ãŸãããïŒ
# Aã¬ã³ãŒãã®äŸ
example.com. 86400 IN A 93.184.216.34
# MXã¬ã³ãŒãã®äŸ
example.com. 86400 IN MX 10 mail-server-1.example.com.
example.com. 86400 IN MX 20 mail-server-2.example.com.
# CNAMEã¬ã³ãŒãã®äŸ
www.example.com. 86400 IN CNAME example.com.
ð DNSãã£ãã·ã¥ãšå¹çå
DNSã·ã¹ãã ã§ã¯ãããã©ãŒãã³ã¹ãåäžãããããã«ããã£ãã·ã¥ãæ©èœãéèŠãªåœ¹å²ãæãããŠããŸãã
ðŠ DNSãã£ãã·ã¥ã®ä»çµã¿
- ð¥ïž ãã©ãŠã¶ãã£ãã·ã¥: ãã©ãŠã¶ãäžå®æéãåå解決ã®çµæãä¿å
- ð» OSãã£ãã·ã¥: ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¬ãã«ã§ã®ä¿å
- ð DNSãªãŸã«ããã£ãã·ã¥: ååž°çDNSãµãŒããŒã§ã®ä¿å
- â° TTLïŒTime To LiveïŒ: åDNSã¬ã³ãŒããæã€æå¹æéïŒç§åäœïŒ
!
ð ãªãã»ã©ïŒãã€ã³ã
DNSãã£ãã·ã¥ã¯ãèŠããŠããããšãã«äŒŒãŠããŸããäžåºŠèª¿ã¹ãé»è©±çªå·ãã¡ã¢ããŠããã°ã次åã¯é»è©±åž³ãåŒããªããŠãé»è©±ãã§ããŸããããåæ§ã«ãäžåºŠè§£æ±ºãããã¡ã€ã³åã®IPã¢ãã¬ã¹ããã£ãã·ã¥ããŠããããšã§ã次åããã®åå解決ãé«éåãããŸãã
âïž TTLã®éèŠæ§
TTLïŒTime To LiveïŒã¯ãDNSã¬ã³ãŒãããã£ãã·ã¥ã«ä¿åãããæéãç§åäœã§æå®ããŸãïŒ
ð é·ãTTLïŒäŸïŒ86400ç§=1æ¥ïŒ:
- ã¡ãªãã: DNSãµãŒããŒã®è² è·è»œæžãé«éãªåå解決
- ãã¡ãªãã: èšå®å€æŽãåæ ããããŸã§æéãããã
ð çãTTLïŒäŸïŒ300ç§=5åïŒ:
- ã¡ãªãã: èšå®å€æŽãããã«åæ ããã
- ãã¡ãªãã: DNSãµãŒããŒãžã®åãåãããå¢å
!
ð DNSã»ãã¥ãªãã£
DNSã¯éèŠãªã€ã³ã¿ãŒãããã€ã³ãã©ã§ãããã»ãã¥ãªãã£äžã®èª²é¡ããããŸãã
â ïž äž»ãªDNSã»ãã¥ãªãã£åé¡
- ð DNSã¹ããŒãã£ã³ã°: åœã®DNSå¿çãéä¿¡ããŠäžæ£ãªãµã€ãã«èªå°
- ð DNSãã£ãã·ã¥ãã€ãºãã³ã°: DNSãã£ãã·ã¥ã«äžæ£ãªæ å ±ãæ³šå ¥
- ð« DDoSæ»æ: DNSãµãŒããŒã«å€§éã®ã¯ãšãªãéããµãŒãã¹åæ¢ãåŒãèµ·ãã
- ðµïž ãã©ã€ãã·ãŒæžå¿µ: DNSã¯ãšãªã¯éåžžæå·åãããŠãããååå¯èœ
ð¡ïž DNSã»ãã¥ãªãã£å¯Ÿç
ð DNSSECïŒDNS Security ExtensionsïŒ:
- ããžã¿ã«çœ²åã䜿çšããŠDNSå¿çã®ä¿¡é Œæ§ã確ä¿
- DNSã¬ã³ãŒãã®æ¹ãããæ€åºå¯èœ
ð DNS over HTTPSïŒDoHïŒ/DNS over TLSïŒDoTïŒ:
- DNSã¯ãšãªãæå·åããŠãã©ã€ãã·ãŒãä¿è·
- ååãæ¹ããã鲿¢
ð§ DNSãã£ã«ã¿ãªã³ã°:
- æªæã®ãããã¡ã€ã³ãžã®ã¢ã¯ã»ã¹ããããã¯
- ãã£ãã·ã³ã°ãµã€ãããã«ãŠã§ã¢é åžãµã€ããžã®ã¢ã¯ã»ã¹ã鲿¢
!
ð¡ ååŠè åããã€ã³ã
DNSSECã¯ãå ¬å°ãã®ãããªãã®ã§ããå ¬ææžã«å ¬å°ãããã°æ¬ç©ãšç¢ºèªã§ããããã«ãDNSSECã®çœ²åãããã°ããã®DNSæ å ±ãæ¬ç©ã§ãããšç¢ºèªã§ããŸãã
ð ïž DNSã®ç®¡çãšæŽ»çš
ð ãã¡ã€ã³åã®ååŸãšç®¡ç
- ð ãã¡ã€ã³åã®ç»é²: ã¬ãžã¹ãã©ïŒGoDaddyããåå.comãªã©ïŒã§ãã¡ã€ã³åãè³Œå ¥
- âïž ããŒã ãµãŒããŒã®èšå®: ãã¡ã€ã³ã®DNS管çãè¡ããµãŒããŒãæå®
- ð DNSã¬ã³ãŒãã®èšå®: ãŠã§ããµã€ããã¡ãŒã«ããµããã¡ã€ã³ãªã©ã®èšå®
ð§ äžè¬çãªDNSèšå®ã·ããªãª
ð¥ïž ãŠã§ããµã€ãã®å ¬é:
example.com. IN A 203.0.113.10 www.example.com. IN CNAME example.com.
ð§ ã¡ãŒã«ãµãŒããŒã®èšå®:
example.com. IN MX 10 mail.example.com. mail.example.com. IN A 203.0.113.20
âïž ã¯ã©ãŠããµãŒãã¹ã®å©çš:
blog.example.com. IN CNAME example.myblogservice.com.
ð DNSã®ããã©ãŒãã³ã¹ç£èŠ
- â±ïž å¿çæé: DNSã¯ãšãªãã©ãã ãéãå¿çããã
- ð å¯çšæ§: DNSãµãŒããŒãã©ãã ãå®å®ããŠçšŒåããŠããã
- ð æ£ç¢ºæ§: æ£ããIPã¢ãã¬ã¹ãè¿ãããŠããã
ð ïž DNSã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°
ããããåé¡ãšè§£æ±ºç
ð« ãŠã§ããµã€ãã«ã¢ã¯ã»ã¹ã§ããªã
- DNSãµãŒããŒãæ£ããèšå®ãããŠããã確èª
- ãã¡ã€ã³åã®æå¹æéãåããŠããªãã確èª
- DNSã®äŒæåŸ ã¡ïŒå€æŽãåæ ããããŸã§æéããããïŒ
ð§ ã¡ãŒã«ãéåä¿¡ã§ããªã
- MXã¬ã³ãŒããæ£ããèšå®ãããŠããã確èª
- ã¡ãŒã«ãµãŒããŒã®IPã¢ãã¬ã¹ãæ£ããã確èª
ð¢ ãŠã§ããµã€ãã®è¡šç€ºãé ã
- DNSãµãŒããŒã®å¿çæéãé ãå¯èœæ§
- ããé«éãªDNSãµãŒããŒã«å€æŽãæ€èš
ð» DNSã®ç¢ºèªã³ãã³ã
# Windows
nslookup example.com # åºæ¬çãªåå解決
nslookup -type=MX example.com # MXã¬ã³ãŒãã®ç¢ºèª
# macOS/Linux
dig example.com # 詳现ãªåå解決æ
å ±
dig MX example.com # MXã¬ã³ãŒãã®ç¢ºèª
host example.com # ã·ã³ãã«ãªåå解決
ð ãªã³ã©ã€ã³DNS確èªããŒã«
- ð DNS Checker: äžçåå°ããã®DNSäŒæç¶æ³ã確èª
- 𧪠MX Toolbox: ã¡ãŒã«é¢é£ã®DNSèšå®ã確èª
- ð Whois: ãã¡ã€ã³åã®ç»é²æ å ±ã確èª
ð ãŸãšã
DNSã¯ã人éãèŠãããããã¡ã€ã³åïŒexample.comïŒãšã³ã³ãã¥ãŒã¿ãçè§£ããIPã¢ãã¬ã¹ïŒ93.184.216.34ïŒãçµã³ã€ãããã€ã³ã¿ãŒãããã®ãé»è©±åž³ãã®ãããªéèŠãªä»çµã¿ã§ããéå±€çãªæ§é ãšåæ£åã®ã·ã¹ãã ã«ãããäžçäžã©ãããã§ãå¹ççã«åå解決ãè¡ããŸãã
æ§ã ãªçš®é¡ã®DNSã¬ã³ãŒãïŒAãMXãCNAMEãªã©ïŒã«ããããŠã§ããµã€ããã¡ãŒã«ããã®ä»ã®ã€ã³ã¿ãŒããããµãŒãã¹ãæ£ããæ©èœããããã®æ å ±ã管çãããŠããŸãããŸãããã£ãã·ã¥æ©èœã«ããDNSã®ããã©ãŒãã³ã¹ãåäžããDNSSECãDoH/DoTãªã©ã®ã»ãã¥ãªãã£æè¡ã«ããå®å šæ§ã確ä¿ãããŠããŸãã
ð¯ ãã®èšäºã®ãã€ã³ã
- ð DNSã¯ããã¡ã€ã³åâIPã¢ãã¬ã¹ãã®å€æãè¡ãã€ã³ã¿ãŒãããã®åºç€æè¡
- ð³ éå±€çãªæ§é ïŒã«ãŒããTLDãSLDãªã©ïŒã§å¹ççãªåå解決ãå®çŸ
- ð æ§ã ãªçš®é¡ã®DNSã¬ã³ãŒãïŒAãAAAAãMXãCNAMEãªã©ïŒãç°ãªã圹å²ãæ ã
- ð ãã£ãã·ã¥æ©èœãšTTLã«ããããã©ãŒãã³ã¹ãæé©åããã
- ð DNSSECãDoH/DoTãªã©ã®æè¡ã«ããã»ãã¥ãªãã£ã匷åããã
DNSã®ä»çµã¿ãçè§£ããããšã§ããŠã§ããµã€ããã¡ãŒã«ã®èšå®ããããã¯ãŒã¯ãã©ãã«ã®è§£æ±ºãå¹ççãªã€ã³ã¿ãŒãããå©çšã«åœ¹ç«ãŠãããšãã§ããŸãã