Research
Japan External Attack Surface
Using information anyone can see from the internet, we observe the external attack surface of Japanese companies every month. We do not publish individual company names or domains; we show trends for Japan as a whole and by industry and company size.
- Observed
- August 2026
- Companies observed
- 43,987
- Last updated
- 2026-08-28
- Email spoofing protection
Base: Companies with resolvable DNS and a mail server (MX) 40,141
- DMARC set to quarantine or reject8.7%
- DMARC set (no quarantine or reject)41.1%
- SPF only45.8%
- Neither SPF nor DMARC found4.3%
- Website CMS
Base: Companies whose top page could be retrieved 37,573
- CMS not identified70.5%
- Another CMS or site builder identified5.3%
- WordPress (version not readable)7.6%
- WordPress version readable from outside13.5%
- Running a version WordPress marks as insecure3.2%
- Website certificates
Base: Companies with a certificate retrievable on port 443 40,920
- Valid94.5%
- Expired0.3%
- Name mismatch (listed URL is https)0.2%
- Name mismatch (listed URL is http etc.)5.0%
Why look at the external attack surface?
Attackers use information that can be checked from the internet to look for attack targets and methods. Basic conditions such as email authentication, website software and certificates can also serve as material for those decisions.
In supply chain security, it matters to cover business partners as well as your own company. Regardless of company size, understanding how your external attack surface appears from outside is a first step in cybersecurity.
Selection
All of JapanCompanies in this selection: 43,987
Email spoofing protection
Emails pretending to come from a business partner or from the company itself are a common entry point for fraud, fraudulent payments and malware. SPF declares which servers may send a company’s mail, and DMARC decides what happens to mail judged to be spoofed; set to quarantine or reject, it makes fake mail using the company’s domain less likely to reach recipients. This breakdown shows how far companies have gone with these settings.
Base: Companies with resolvable DNS and a mail server (MX)
- DMARC set to quarantine or reject
- DMARC set (no quarantine or reject)
- SPF only
- Neither SPF nor DMARC found
Only one month so far. The trend will appear as more months are observed.
By industry (top row: all of Japan)
Underlying numbers
All of JapanBase: 40,141
| Group | Share | Companies | vs last month |
|---|---|---|---|
| DMARC set to quarantine or reject | 8.7% | 3,491 | — |
| DMARC set (no quarantine or reject) | 41.1% | 16,512 | — |
| SPF only | 45.8% | 18,403 | — |
| Neither SPF nor DMARC found | 4.3% | 1,735 | — |
- ※ Both DMARC groups include companies that have no SPF record.
Website CMS
A website CMS left on an old version with known weaknesses can be defaced or taken over using publicly known techniques. When the CMS and its version can be read from outside, sites running a vulnerable version are easier to pick out. This breakdown shows whether the top page reveals which CMS is used, whether a WordPress version can be read, and whether it is a version WordPress itself marks as insecure.
Base: Companies whose top page could be retrieved
- CMS not identified
- Another CMS or site builder identified
- WordPress (version not readable)
- WordPress version readable from outside
- Running a version WordPress marks as insecure
Only one month so far. The trend will appear as more months are observed.
By industry (top row: all of Japan)
Underlying numbers
All of JapanBase: 37,573
| Group | Share | Companies | vs last month |
|---|---|---|---|
| CMS not identified | 70.5% | 26,473 | — |
| Another CMS or site builder identified | 5.3% | 1,979 | — |
| WordPress (version not readable) | 7.6% | 2,845 | — |
| WordPress version readable from outside | 13.5% | 5,091 | — |
| Running a version WordPress marks as insecure | 3.2% | 1,185 | — |
- ※ “CMS not identified” includes sites that do not name a CMS, hand-built sites, and WordPress sites that hide it from outside.
- ※ “Another CMS or site builder identified” covers pages whose generator tag names a CMS or site builder.
Website certificates
A website certificate (the TLS certificate used for HTTPS) lets visitors confirm they are connected to the real site over an encrypted connection. When it has expired or does not match the site’s name, browsers show a warning, and visitors who get used to clicking through warnings are less likely to notice a fake site or an intercepted connection. This breakdown shows whether each certificate is valid, expired, or issued for a different name.
Base: Companies with a certificate retrievable on port 443
- Valid
- Expired
- Name mismatch (listed URL is https)
- Name mismatch (listed URL is http etc.)
Only one month so far. The trend will appear as more months are observed.
By industry (top row: all of Japan)
Underlying numbers
All of JapanBase: 40,920
| Group | Share | Companies | vs last month |
|---|---|---|---|
| Valid | 94.5% | 38,650 | — |
| Expired | 0.3% | 138 | — |
| Name mismatch (listed URL is https) | 0.2% | 101 | — |
| Name mismatch (listed URL is http etc.) | 5.0% | 2,031 | — |
- ※ “Name mismatch (listed URL is http etc.)” covers companies that appear not to have set up HTTPS.
Methodology
The companies in scope are those listed on Shokubalabo, the workplace information site run by Japan’s Ministry of Health, Labour and Welfare. The companies and their industry, employee size and prefecture were derived by processing data from that site.
Observation is limited to what anyone can see from the internet. We check DNS records, each company’s top page and the website certificate, and perform no intrusive or load-generating tests.
Email spoofing protection, website CMS and website certificates are each counted against the companies for which that item could be checked. The detailed group definitions are given for each item.
Comparisons with ISMS-certified companies use only companies matched by name and prefecture against the ISMS certification registry. Companies that could not be matched are not treated as “not ISMS certified”.
Source: Shokubalabo
