Email DNS Monitor
Each month, the publicly available DNS records of listed companies in Japan are observed for email authentication (SPF, DKIM, DMARC) and the protocols around it. This site measures conformance to published standards and is not an overall security assessment.
Summary
Rates are calculated only over domains that could be observed. Putting domains that returned SERVFAIL, or nothing at all, into the denominator would count "could not be observed" as "not configured".
Observed
This is a checklist of standards met. No overall position and no A-to-F style summary mark is attached. Whether each individual standard is met is meant to be readable on its own.
Bar length is good for seeing a trend, but it does not answer "how many domains publish SPF". Counts and shares are given together. The denominator for every share is the number of domains observed.
Counted by company
Counted by domain alone, companies holding many domains carry more weight. A company does not necessarily hold exactly one domain, so both are published.
Stated versus effective
That a record says p=reject, and that the policy actually takes effect, are
two different facts. A pct below 100 applies the policy to only part of the
mail, t=y means test mode, and without rua the operator cannot see what is
being rejected.
Over time
Maturity stages
MTA-STS, BIMI and DANE all presuppose DMARC, so simply adding them up would count the lower items twice. They are shown as an ordered set of stages.
Domains that do not send
Most of the domains expanded in the candidate set are not used for sending. A domain with no sending history and nobody watching it can become a starting point for spoofing. So domains explicitly locked down are shown separately from domains with nothing configured.
Limits of this measurement
Details are on the Methodology page.