GMO Brand Security Research: Only 26.7% of Japan’s Banks and Shinkin Banks Are Equipped to Block Spoofed Emails

—Survey of 386 financial institutions nationwide reveals only 26.7% have effective "SPF/DMARC" configuration to block spoofed emails; just 51 institutions (13.2%) have adopted BIMI—

  • Press Release
  • Share
    • X
    • Facebook
    • LinkedIn

GMO Brand Security Inc. (President and COO: Mitsuaki Nakagawa; hereinafter “GMO Brand Security”), a member of the GMO Internet Group, has conducted a survey on the implementation and operational status of SPF ∗1∗1, DMARC ∗2∗2, and BIMI ∗3∗3—key technologies used to prevent email spoofing—across domains owned by 386 financial institutions in Japan, consisting of 131 banks and 255 shinkin banks.

The survey found that while adoption of anti-spoofing measures has progressed to a certain extent, only 26.7% (103 institutions) are operating DMARC with an enforcement policy of "p=quarantine" or "p=reject", meaning they are in a position to actually block spoofed emails. This result highlights a clear gap between the formal introduction of email authentication measures and their real-world effectiveness in protecting users.

Among the 386 institutions surveyed, 309 (80.1%) had implemented SPF and 233 (60.4%) had implemented DMARC. However, only 103 institutions (26.7%) had advanced their DMARC policy to an effective enforcement level capable of blocking impersonation emails. In other words, although many institutions have introduced the relevant technologies, far fewer have reached the stage where those measures can function as meaningful protection against phishing and spoofing attacks.

The survey also revealed significant differences by institution type. All four city banks surveyed (100%) had raised their DMARC policy to p=reject, while among shinkin banks, only 30 out of 255 institutions (11.8%) had done so.

In addition, BIMI—a technology that visually verifies the legitimacy of an email by displaying the sender’s brand logo—had been adopted by 51 institutions (13.2%). All four city banks had implemented BIMI, while among shinkin banks, adoption was limited to just 7 institutions (2.7%). These findings indicate that although email authentication initiatives are moving forward in the financial sector, the number of institutions that are truly operating at a level capable of protecting users remains limited.

With phishing scams often increasing during the Obon holiday period, GMO Brand Security is publishing this report to help raise awareness of the current state of email security across Japan’s financial institutions and the need for more effective anti-spoofing measures.

 【銀行・信金386行を調査】
なりすましメールを遮断できる金融機関は26.7%に留まる
~GMOブランドセキュリティ、お盆のフィッシング急増期前に実態レポートを公開~

For further details, please refer to the link below (Japanese): https://brandsecurity.gmo/news/post/post-20260807/

Go to news list

GMO Spoofing ZERO