
Oh-ami Inc.
- BIMI
Achieving Anti-Spoofing Protection and Brand Trust with BIMI/VMC
Reassurance that says “this email is from AmiAmi” at a glance ——
adopting BIMI/VMC to unite security and branding
Oh-ami Inc.
Oh-ami Inc. operates the “AmiAmi” (both its online shop and its brick-and-mortar stores), offering a wide range of figures, plastic models, and hobby-related products. Every day the company sends its customers a large volume of email — transactional messages such as order confirmations, shipping notifications, and membership-registration authentication emails, as well as newsletters and lottery-sale winning notices. Aiming to achieve both robust “countermeasures against increasingly sophisticated spoofing and phishing emails” and “branding” that lets recipients see at a glance that a message is “from AmiAmi,” the company progressively raised its DMARC policy and adopted BIMI (Brand Indicators for Message Identification) together with a VMC (Verified Mark Certificate). We asked about the background, the implementation process, and their plans for the future.
Email Clients and Sending Tools in Use
──Before adopting BIMI, what email clients and email-sending tools were you using?
Our needs range from general customer support to marketing-focused campaigns, and because each department has different objectives, we use a variety of tools to send email.
──What kinds of email do you mainly send?
For customers of the “AmiAmi Online Shop,” we mainly send transactional emails such as order confirmations, shipping notifications, and membership-registration authentication emails. We also send newsletters, replies to inquiries, and lottery-sale winning notices.
Working on DMARC: Efforts and Challenges
──What prompted you to start working on your DMARC configuration?
This BIMI project was the catalyst. With an eye on improving our domain’s trustworthiness as well, we began the work of raising our DMARC policy.
──What hurdles or concerns did you feel at first when configuring DMARC?
Because we send a high volume of email, an abrupt tightening of the DMARC policy would have had a large impact on our customers and business partners. We have therefore been strengthening the policy in stages while analyzing and monitoring DMARC reports. Identifying and accounting for every legitimate sending path required coordination with a wide range of people both inside and outside the company. In addition, passing DMARC authentication required us to address a variety of issues, and understanding their causes and the appropriate responses proved challenging. However, with the support and consulting services provided by our representative at GMO Brand Security, Inc., we were able to complete the work without any major problems.
Why the Company Considered Adopting BIMI/VMC
──What was the background and the catalyst for considering BIMI/VMC?
We believed it would help strengthen both security and branding, and we saw it as the next step in our email strategy, with the main goals of countering spoofing and phishing and improving open rates. We found great appeal in being able to make our security measures visible while also displaying a logo that lets recipients instantly recognize a message as “from AmiAmi,” thereby increasing the effectiveness of our campaigns. We also viewed it as an effective way to differentiate ourselves from competitors. On top of that, we had received comments from customers such as “Is this email really from AmiAmi?” and “Please display the AmiAmi logo clearly,” which became one of the major factors that pushed us toward adoption.
──Before adopting BIMI, what email-related challenges did you face?
With sophisticated spoofing and phishing emails rising sharply, there was a risk that customers might hesitate to receive or open even our legitimate email. We felt the need for measures that would make our trustworthiness visible.
The Deciding Factors and the Implementation Process
──Could you tell us about the schedule and the steps leading up to adoption?
Working with each department, we had to steadily resolve one issue after another before we could even reach the starting line for BIMI — filing a trademark application for our logo, obtaining the VMC certificate, and strengthening our DMARC policy in stages. From there, with the support of our representative at GMO Brand Security, Inc., we were able to introduce BIMI smoothly and without any major problems.
──Were there any difficulties or points you had to work around during implementation?
Beyond technical requirements such as email authentication and DNS configuration, there were many things to check and address before proceeding — verifying the quality of the logo to be displayed, handling it as a brand asset, and dividing roles among the relevant departments. We therefore worked with multiple departments, including Legal, Systems, Design, and Customer Support, drawing on advice from each of their perspectives. As a result, we feel we were able to carry out the project as an initiative that enhances brand trust and customer reassurance, while deepening internal understanding along the way. Also, when raising the DMARC policy in stages for domains with high email volumes, we increased the pct (percentage) in roughly three steps. Because we raised several domains in stages at the same time, there were some hectic periods coordinating schedules and tasks — including DNS record edits — with both internal teams and outside parties.
Results After Adopting BIMI/VMC
──What changes or effects have you experienced since adopting BIMI/VMC?
Now that our brand logo appears on received emails, we feel this has been an important turning point that not only improves the credibility of our email communications but also enhances the customer experience.
──What about the effects on security and peace of mind?
Inquiries asking us to “confirm whether an email is genuinely from AmiAmi” are trending downward, and we believe that displaying the brand logo is having a real effect on strengthening customers’ sense of trust. In addition, during the rollout period, a large number of DMARC-authentication-failure emails — apparently spoofed messages targeting the relevant domains — occurred at one point. Because we were using the consulting service and the DMARC report analysis service, we could grasp the situation immediately and bring our policy-strengthening schedule forward, which helped resolve the situation more quickly. It was a secondary benefit, but a very welcome one.
Advice for Companies Considering BIMI
──Do you have any advice for companies that are considering adopting BIMI?
BIMI is a highly effective mechanism precisely because it lets you improve security and branding at the same time. To ensure a safe rollout, thorough preparation and sufficient verification — carried out in coordination across departments — are essential, so we recommend allowing a comfortable, unhurried implementation timeline. We also feel that the BIMI implementation process is a good opportunity to take stock of and review your current technical settings, and that it is a worthwhile initiative that leads to a review of your entire email-authentication foundation.
──How do you plan to use and expand BIMI in the future?
Email is one of our most important channels for communicating with customers. Precisely because we have improved the visibility and trustworthiness of our sender identity and lowered the barrier to having our email noticed and opened, we now want to further expand our marketing initiatives going forward.