Build Trust at a Glance: Visual Protection Against Phishing
BIMI (Brand Indicators for Message Identification) is a standard for displaying brand logos in company emails. By seeing the logo, recipients can instantly confirm that the email is from a legitimate company. This reduces the risk of threats like phishing and spoofing and helps enhance brand trust. Displaying the logo requires a Verified Mark Certificate (VMC) issued by a Certificate Authority.
Please check your DMARC (anti-spoofing email) configuration.
We assess the risk of impersonation. Please enter the domain name managed by your company.
Please wait a moment for the result to be displayed
Do not reload the page until the result is displayed
Diagnosis Result
Potential impacts in case of impersonation
If a website is impersonated due to phishing scams or domain spoofing, there are risks such as customers and fans falling victim to fraud, the circulation of counterfeit products, and the spread of false information. As a result, there are direct business risks such as a decline in brand image, sluggish product sales, and potential reputational damage caused by the spread of misinformation.
VMC Usage
Yes
No
VMC (Verified Mark Certificate) is a digital certificate that certifies that the BIMI logo is genuine. Without a VMC, you may not be able to use the BIMI logo or your email may not be as effective at preventing spoofing. Obtaining a VMC further increases the credibility of your email.
BIMI (Brand Indicators for Message Identification) is a system that displays the official logo of the email sender. Without this setting, it becomes difficult to determine whether an email is official, and fake emails are more likely to be trusted. Setting up BIMI makes it easier to spot spoofed emails.
An SPF record specifies which mail servers are allowed to send emails from your domain. This allows the recipient to verify the authenticity of the sender. Without an SPF record, third parties can send emails using your domain, increasing the risk of spoofing. By setting up an SPF record, you can block emails from unauthorized senders and maintain a reliable email environment.
DMARC Record Setting
YesNo
DMARC (Domain-based Message Authentication, Reporting, and Conformance) is a protocol designed to specify how to handle email messages that fail authentication checks based on SPF and DKIM results. By implementing DMARC, organizations can strengthen their defenses against spoofed emails. There are three types of DMARC policies. none (monitor only): Messages that fail authentication are still delivered to the inbox. quarantine: Messages that fail authentication are delivered to the spam or junk folder. reject: Messages that fail authentication are rejected entirely and not delivered to the recipient. DMARC also includes a reporting feature that provides visibility into unauthorized email activity. This enables organizations to implement more effective email security measures.
Brand TLD Usage
Yes
No
A brand TLD (e.g., .gmo) is a system that allows companies and organizations to use their brand name as a top-level domain, creating a unique domain space. It offers high security and greater control over brand management, helping to strengthen online strategies.
Number of similar domains
Similar domains(Display only 10 items)
This shows how many domains are similar to your company's domain (e.g. example.com). For example, if there are domains like examp1e.com (with the number 1) or example.co (.co domain), it is easier for fraudulent websites to be created. The higher the risk of spoofing, the more caution you need to take.
To improve the rank, it is important to strengthen impersonation countermeasures. Specifically, let's implement the following measures.
Obtain a VMC (Enhance the Trustworthiness of Your BIMI Logo)
Obtain a VMC (Verified Mark Certificate) to officially certify the BIMI logo and enhance email credibility.
By configuring the SPF record in the DNS and specifying the mail servers authorized as legitimate senders, you can prevent third parties from unauthorized use of your domain.
Prevent emails from being marked as spam
If SPF is not configured, even legitimate emails may be recognized as "suspicious" by the recipient's system and placed in the spam folder. By setting up SPF, you ensure that legitimate emails are delivered properly.
Use in combination with DMARC
Since SPF alone cannot prevent all cases, combining it with DMARC allows for more precise control over spoofed email policies, ensuring a more effective elimination of fraudulent emails.
Set Up DMARC
Block spoofed emails
By setting DMARC to "p=reject", emails that fail authentication will not be sent, preventing the reception of fraudulent emails.
Reduce the risk of phishing scams
By filtering emails that fail SPF or DKIM authentication into the spam folder, the risk of recipients accidentally opening fraudulent emails can be reduced.
Use the reporting feature to monitor attack activity
By utilizing DMARC's reporting feature, you can identify which emails fail authentication and monitor the presence and trends of spoofing attacks.
Utilize a Brand TLD (Fundamentally Prevent Spoofing)
Acquisition of a dedicated domain
For example, acquiring a dedicated domain like ".gmo" prevents others from registering similar domains, significantly enhancing security.
Reduction of risk rank
Having a brand TLD tends to result in a lower risk rank in search results.
Promote awareness of the official domain
It is important to standardize the official website URL under the brand TLD and inform users that any domain other than this is not official.
Similar Domain Protection (Preventing Phishing Websites)
Register similar domains
If your domain is "example.com", registering similar domains such as "example.net" or "examp1e.com" (with the number 1 instead of 'l') can enhance security and prevent misuse.
Regularly check for similar domains
Use a domain monitoring service to check for newly created similar domains.
Delete immediately upon discovery
If a phishing site is detected, submit a deletion request (domain suspension procedure) immediately.
By implementing these measures, It is possible to improve the risk rank from D (high risk) to A (low risk). Taking early action is the key to preventing impersonation attacks.
Receive a more detailed impersonation risk diagnosis and countermeasures
We have implemented BIMI to ensure our customers can view our important emails with peace of mind.
FOLIO Co., Ltd.
Guided by directives from Japan's Financial Services Agency (FSA) and the securities industry, FOLIO Co., Ltd. took a proactive approach to implementing BIMI (Brand Indicators for Message Identification), ensuring their customers can open and review important emails with complete peace of mind.
'Email Spoofing is Not Someone Else's Problem.' Achieving Brand Visibility and Security Enhancement Through BIMI.
JINUSHI Financial Advisors Inc.
Recognizing email spoofing as a direct concern for their organization, JINUSHI Financial Advisors Inc. implemented BIMI (Brand Indicators for Message Identification) to simultaneously enhance security measures and make their brand identity visible to customers.
Implementing BIMI as Part of Security Enhancement Efforts as a Financial Institution.
The Yamagata Bank, Ltd.
The Yamagata Bank, Ltd., as a financial institution, has been implementing various initiatives to protect its customers from spoofed emails and phishing scams. As part of these security measures, the bank has implemented BIMI, displaying their corporate logo in emails.
Implemented BIMI primarily for marketing and branding purposes.
GeoTechnologies, Inc.
GeoTechnologies, Inc. offers a wide range of services, including development and technical support using map databases, as well as marketing support through mobility data analysis. The company implemented BIMI for "Torima," a loyalty app service that allows users to earn points simply by traveling.
The Kita-Nippon Bank, Ltd. implements a wide range of security measures through a specialized department. As part of these comprehensive efforts, they introduced BIMI. With a deep understanding of the BIMI framework, the bank acted quickly for the benefit of its customers.
Decided to use corporate emails with a logo (BIMI) to improve safety for online stores and customers.
BASE, Inc.
BASE, an online store creation service operated by BASE, Inc., is working to improve the reliability of emails, aiming to create an environment where customers can receive emails and information with peace of mind. They have introduced emails with corporate logos (BIMI).
Losing Business Opportunities to Undelivered Emails? Visualize Trust with BIMI
Talk Eye Co., Ltd.
Email deliverability is the lifeline of a business. We spoke with Talk Eye Co., Ltd. to learn what motivated them to consider implementing BIMI (Brand Indicators for Message Identification), and what the deciding factors were in choosing GMO Brand Security for the implementation.
Reports of phishing incidents have increased dramatically since 2019. The number of cases skyrocketed from approximately 20,000 in 2018 to nearly 1.2 million in 2023—a staggering 60-fold increase in just six years.
One key factor behind this surge is the COVID-19 pandemic. As economic activities and daily communication moved online, criminal activities like spoofing and phishing also proliferated in the digital world.
The pandemic also brought new demographics online, such as seniors and young students, who previously had limited internet experience. Due to lower digital literacy, these groups have become particularly vulnerable, leading to a sharp rise in the number of victims.
Growth in Reported Phishing Cases
Phishing reports to the Anti‑Phishing Council are rapidly increasing!
Source: Anti‑Phishing Council monthly reports; compiled by GMO Brand Security
Financial Losses from Phishing
A sharp increase in fraudulent transfers via internet banking (approx. 8.7 billion JPY in 2023).
Source: Compiled by GMO Brand Security from the Deputy Chief Cabinet Secretary’s Office — “Comprehensive Measures to Protect Citizens from Fraud (Draft)”.
Key Benefits of Implementing BIMI & VMC
In today's complex world of cybersecurity, BIMI and VMC offer a refreshingly simple advantage: security you can see. Displaying a trusted logo directly in the inbox gives users instant confidence that a message is legitimate.
This visual verification is a game-changer for businesses. It helps boost email open rates—a key marketing metric—and strengthens brand trust. In an era where email is the key to countless online services, allowing customers to identify your messages at a glance is a powerful advantage.
1
Protection Against Spoofing & Phishing
When combined with DMARC (an anti-spoofing email protocol), it helps prevent fraudulent emails and reduces the risk of phishing attacks.
2
Enhanced Brand Trust
When recipients see the official logo, they can instantly trust the sender and confidently open the message.
3
Increased Brand Recognition
With your logo visible in the inbox, recipients instantly recognize your brand. This consistent visibility reinforces brand identity with every email.
How BIMI Works
Major Companies Using BIMI & VMC
Japanese Companies
Rakuten
Yahoo!
DMM
Sumitomo Mitsui Banking Corporation (SMBC)
Matsui Securities
GMO Internet Group (50 companies)
etc
Global Companies
Amazon
NVIDIA
etc
BIMI/VMC Supported Email Clients
Gmail
Yahoo! Mail
Apple Mail
Fastmail
Logo Mark Certificate Lineup
Here is an overview of the logo mark certificates available for displaying your brand logo in company emails. The type of certificate you can obtain varies depending on factors such as the trademark registration status of your logo and the nature of your organization.
Display Your Organization's Logo with a Verified Mark
Boost Brand Trust with Trademark Logo Display
Verified Mark Certificate (VMC)
180,000JPY(excl. tax / per year)
Typical Organizations
Organizations that own a logo with an active trademark registration
This certificate can be issued as long as the trademark registration is valid. It verifies that the email sender is the legitimate owner of both the registered trademark logo and the domain.
For Government Agencies and Local Authorities
Government Mark Certificate (GMC)
180,000JPY(excl. tax / per year)
Typical Organizations
Government agencies, ministries, local governments, etc.
Can be issued for logos that are recognized as owned by, or that can be claimed by, government agencies or local authorities — even without trademark registration.
Available Even Without a Registered Trademark
Display a Logo in Use for Over One Year
Common Mark Certificate (CMC)
180,000JPY(excl. tax / per year)
Typical Organizations
Organizations that have been using an unregistered logo for over one year
Can be issued for logos that have not been trademarked by any third party, have been in use on the organization's website for over one year, and are currently still displayed there.
Ideal for Brand Renewal
Modified Registered Mark Certificate (MRMC)
180,000JPY(excl. tax / per year)
Typical Organizations
Organizations renewing a logo that has an active trademark registration
Can be issued for logos that are adapted versions of a trademark-registered logo within specified guidelines, where the adapted version itself is not yet registered as a trademark.
Logo Mark Certificate Lineup — Comparison Chart
VMC (Verified Mark Certificate)
GMC (Government Mark Certificate)
CMC (Common Mark Certificate)
MRMC (Modified Registered Mark Certificate)
Trademark Registration
Required
Not Required
Not Required
Not Required
Verified Mark
Displayed
Displayed
Hidden
Hidden
Supported Email Clients
Gmail, Fastmail, au Mail, etc.
Gmail, Fastmail, au Mail, etc.
Gmail only
Gmail only
※ Status as of April 2026.
DMARC Policy Upgrade Support
Our partner companies provide support to help upgrade your organization's DMARC policy. They offer multiple plans tailored to your situation.
With two decades of experience, GMO Brand Security possesses deep expertise in trademarks. You can confidently entrust us with the critical trademark verification required for VMC issuance, ensuring a seamless process.
2Seamless BIMI Operation with Our Group's Root CA
With our group company, GlobalSign—a trusted global Certificate Authority—serving as the Root CA, we deliver a seamless BIMI experience. This direct collaboration guarantees stable and consistent logo display across various email clients, providing you with peace of mind.
3Comprehensive Brand Protection Services
We also offer solutions to address brand infringement and cybersecurity risks. Our services include: Brand Abuse Monitoring Site Takedown Services Vulnerability Assessments
4Experienced team delivering tailored solutions
Our experienced staff design solutions tailored to each company’s challenges. We serve around 2,000 clients, primarily large enterprises, and excel at providing customized problem‑solving.
Related Links
FAQ: BIMI/VMC & GMO Anti-Spoofing Seal
Here are the answers to your questions about getting a VMC, from preparing your trademark and logo file to gathering the required documents (Japanese only).