West Japan Railway Company

West Japan Railway Company

  • BIMI

JR-West Takes On Email Security to Protect 13 Million Customers
―Behind the Scenes of Adopting DMARC and Logo-Enabled Email (BIMI)―

West Japan Railway Company

In recent years, the damage caused by spoofed email and phishing scams that impersonate corporate brands has grown increasingly serious. One company that has responded with robust countermeasures is West Japan Railway Company (hereinafter “JR-West”).

”WESTER ID,” which serves as the hub for the member payment services and the various reservation systems that JR-West provides, has approximately 13 million users. We spoke with the company about how it came to tighten its DMARC policy and adopt logo-enabled email (BIMI) in order to protect this vast customer base from spoofed email, and about the results it has seen.

Background: Countering the Phishing Threat Aimed at 13 Million Customers

──JR-West offers a wide range of services, including a MaaS app and payment services. We understand that “WESTER ID” is the platform underpinning them all, and that its user count has now reached approximately 13 million.

We send various notification emails to this large user base every day, but at the same time we were detecting a great many “phishing sites and phishing emails impersonating JR-West.” Up to that point we had been posting warnings on each of our service websites and pursuing takedowns (driving malicious sites to shut down), but with new ones appearing one after another it became a game of cat and mouse, and we decided to take on the challenge of solving the problem through fundamental technical countermeasures.

Phishing damage had in fact been confirmed even before the COVID-19 pandemic. In addition to the warnings on our websites, we began serious consideration around 2024 of “technical measures that are easy for customers to understand, so that they can use our services with peace of mind.”

From DMARC to BIMI: A Phased Approach Spanning Roughly Two Years

──At a large enterprise such as JR-West, strengthening email security is not something that can be accomplished overnight, and we understand that you also operate a great many email delivery systems in house. Through what stages did you raise your DMARC policy and adopt logo-enabled email (BIMI)?

We proceeded in stages over roughly two years, following the steps below.

  1. Assessing the current state and organizing our email systems (from 2024)
    A prerequisite for introducing DMARC is that sender authentication such as SPF and DKIM be configured correctly on every email delivery system. We checked our internal systems one by one and spent about a year correcting the settings and putting them into effect.
  2. Tightening the DMARC policy (2025)
    In parallel with organizing the systems, we started out by receiving DMARC monitoring (none) reports, then gradually tightened the policy (from quarantine to reject). By the end of 2025, the tightening work was essentially complete for our principal domains.
  3. Displaying our brand logo with BIMI (May 2026)
    Once the shift to a DMARC reject policy was complete, we adopted logo-enabled email (BIMI) in May 2026 as the final step. This put in place a mechanism whereby the official JR-West logo is displayed automatically in supported mail clients (recipient-side environments).

    To give a sense of the scale of what we undertook: for the two main domains (excluding subdomains) where we introduced DMARC and logo-enabled email (BIMI) this time, monthly email volume alone comes to roughly 8 million messages. Including subdomains, tens of millions of messages per month fall within scope.

The Team and Costs Involved, and Buy-In from Management

──What kind of team and cost structure did you use to carry out the rollout?

This project was driven largely in house, mainly by members of JR-West’s internal IT department and the group’s IT subsidiary, JR WEST IT Solutions Company (J-WITS).

Because we handled the work in house, outlays to external parties were held to a limited scope: the introduction of a “visualization tool bundled with consulting services” to make sense of the enormous volume of DMARC reports, plus the cost of modifications on the individual email systems.

Other work we handled in house included (1) daily checks of DMARC verification status using the visualization tool, (2) validating the soundness of the judgments made by the consulting service, and (3) building a shared understanding with the owners of each email system where DMARC alignment was failing, and coordinating how to address it. We operate a large number of email systems, so seeing this through in house was a significant challenge, but through close communication with the email system owners we also strengthened trust with the members on each system’s side. Handling it in house was the right approach, and the results were substantial.

As for the various costs associated with adopting logo-enabled email (BIMI), such as issuing the Verified Mark Certificate (VMC) that attests to ownership of the corporate logo, we took advantage of an affordably priced plan from GMO Brand Security.

When we explained this organizational structure and these costs to management, it took several rounds of discussion, but because this was “a measure to protect our customers’ safety, security, and trust,” and because — thanks in part to handling the work in house — “the direct external costs were limited relative to the expected benefits,” we received very positive backing and approval came smoothly. After the rollout, interest inside the company ran high as well: even our executives took note, remarking that “the logo has appeared.”

The Dramatic Results Achieved

──Since the rollout, have you observed any concrete results?

The most conspicuous change is that raising the DMARC policy to the strictest level (reject and the like) produced a dramatic shift in how spoofed email was being delivered.

According to the reports from the DMARC visualization tool we have deployed, the volume of spoofed email being sent in our name fell dramatically the instant we tightened the policy. We surmise that the attackers themselves sensed that “this domain has a strict policy, so spoofed messages will be rejected on the receiving side and will not get through,” and gave up.

As a secondary effect, we have also been hearing a response to our forward-looking efforts as an infrastructure operator: inquiries from other companies (those considering DMARC adoption) asking about our know-how, such as “how did you manage to get all the way to adopting logo-enabled email (BIMI)?”

Challenges do remain in directly defending against, and fully covering, spoofing that relies on “look-alike domains” (for example, domains that differ by a single character). Even so, we keep track of the registration of fraudulent domains through means such as attack surface monitoring (a service that monitors from the outside whether suspicious look-alike domains have been registered anywhere in the world). Through this initiative we have created a situation in which “email that arrives from the genuine domain carries the official logo (BIMI),” and that allows us to provide customers with further information for judging whether an email is authentic.

BIMI/VMC