Research

Japan External Attack Surface

Using information anyone can see from the internet, we observe the external attack surface of Japanese companies every month. We do not publish individual company names or domains; we show trends for Japan as a whole and by industry and company size.

Observed
August 2026
Companies observed
43,987
Last updated
2026-08-28
  • Email spoofing protection

    Base: Companies with resolvable DNS and a mail server (MX) 40,141

    • DMARC set to quarantine or reject8.7%
    • DMARC set (no quarantine or reject)41.1%
    • SPF only45.8%
    • Neither SPF nor DMARC found4.3%
  • Website CMS

    Base: Companies whose top page could be retrieved 37,573

    • CMS not identified70.5%
    • Another CMS or site builder identified5.3%
    • WordPress (version not readable)7.6%
    • WordPress version readable from outside13.5%
    • Running a version WordPress marks as insecure3.2%
  • Website certificates

    Base: Companies with a certificate retrievable on port 443 40,920

    • Valid94.5%
    • Expired0.3%
    • Name mismatch (listed URL is https)0.2%
    • Name mismatch (listed URL is http etc.)5.0%

Why look at the external attack surface?

Attackers use information that can be checked from the internet to look for attack targets and methods. Basic conditions such as email authentication, website software and certificates can also serve as material for those decisions.

In supply chain security, it matters to cover business partners as well as your own company. Regardless of company size, understanding how your external attack surface appears from outside is a first step in cybersecurity.

Selection

All of JapanCompanies in this selection: 43,987

Email spoofing protection

Emails pretending to come from a business partner or from the company itself are a common entry point for fraud, fraudulent payments and malware. SPF declares which servers may send a company’s mail, and DMARC decides what happens to mail judged to be spoofed; set to quarantine or reject, it makes fake mail using the company’s domain less likely to reach recipients. This breakdown shows how far companies have gone with these settings.

Base: Companies with resolvable DNS and a mail server (MX)

  • DMARC set to quarantine or reject
  • DMARC set (no quarantine or reject)
  • SPF only
  • Neither SPF nor DMARC found
Figure 1Monthly trend

Only one month so far. The trend will appear as more months are observed.

Figure 2This month, compared

By industry (top row: all of Japan)

Underlying numbers

All of JapanBase: 40,141

GroupShareCompaniesvs last month
DMARC set to quarantine or reject8.7%3,491
DMARC set (no quarantine or reject)41.1%16,512
SPF only45.8%18,403
Neither SPF nor DMARC found4.3%1,735
  • Both DMARC groups include companies that have no SPF record.

Website CMS

A website CMS left on an old version with known weaknesses can be defaced or taken over using publicly known techniques. When the CMS and its version can be read from outside, sites running a vulnerable version are easier to pick out. This breakdown shows whether the top page reveals which CMS is used, whether a WordPress version can be read, and whether it is a version WordPress itself marks as insecure.

Base: Companies whose top page could be retrieved

  • CMS not identified
  • Another CMS or site builder identified
  • WordPress (version not readable)
  • WordPress version readable from outside
  • Running a version WordPress marks as insecure
Figure 3Monthly trend

Only one month so far. The trend will appear as more months are observed.

Figure 4This month, compared

By industry (top row: all of Japan)

Underlying numbers

All of JapanBase: 37,573

GroupShareCompaniesvs last month
CMS not identified70.5%26,473
Another CMS or site builder identified5.3%1,979
WordPress (version not readable)7.6%2,845
WordPress version readable from outside13.5%5,091
Running a version WordPress marks as insecure3.2%1,185
  • “CMS not identified” includes sites that do not name a CMS, hand-built sites, and WordPress sites that hide it from outside.
  • “Another CMS or site builder identified” covers pages whose generator tag names a CMS or site builder.

Website certificates

A website certificate (the TLS certificate used for HTTPS) lets visitors confirm they are connected to the real site over an encrypted connection. When it has expired or does not match the site’s name, browsers show a warning, and visitors who get used to clicking through warnings are less likely to notice a fake site or an intercepted connection. This breakdown shows whether each certificate is valid, expired, or issued for a different name.

Base: Companies with a certificate retrievable on port 443

  • Valid
  • Expired
  • Name mismatch (listed URL is https)
  • Name mismatch (listed URL is http etc.)
Figure 5Monthly trend

Only one month so far. The trend will appear as more months are observed.

Figure 6This month, compared

By industry (top row: all of Japan)

Underlying numbers

All of JapanBase: 40,920

GroupShareCompaniesvs last month
Valid94.5%38,650
Expired0.3%138
Name mismatch (listed URL is https)0.2%101
Name mismatch (listed URL is http etc.)5.0%2,031
  • “Name mismatch (listed URL is http etc.)” covers companies that appear not to have set up HTTPS.

Methodology

The companies in scope are those listed on Shokubalabo, the workplace information site run by Japan’s Ministry of Health, Labour and Welfare. The companies and their industry, employee size and prefecture were derived by processing data from that site.

Observation is limited to what anyone can see from the internet. We check DNS records, each company’s top page and the website certificate, and perform no intrusive or load-generating tests.

Email spoofing protection, website CMS and website certificates are each counted against the companies for which that item could be checked. The detailed group definitions are given for each item.

Comparisons with ISMS-certified companies use only companies matched by name and prefecture against the ISMS certification registry. Companies that could not be matched are not treated as “not ISMS certified”.

Source: Shokubalabo

Citing and reusing this research