StrategyCore
Back to Resources
25/cybersecurity 8 min read

Finding Shadow IT and Its Owner: The Hardest Part of DMARC Enforcement in Japan

Discovering an unauthorized sender is the easy half. Naming the person inside the organization who owns it is where enforcement stalls, and where recipient side analysis wins.

For most of the past decade, the fight against email impersonation was concentrated in the United States and Europe. It has now moved to Japan: a 2025 Valimail study found that roughly 84 percent of newly observed fraudulent email campaigns were aimed at Japanese targets, and the guidance has caught up. METI, the FSA, NISC, and the securities industry association have each set DMARC enforcement as a requirement or strong recommendation on a 2025 to 2026 timeline, while Gmail and Yahoo have rejected unauthenticated bulk mail since February 2024 and Microsoft since May 2025. Reaching enforcement sounds like a policy change, but the hard work sits in the middle: finding every legitimate service that sends as your domain, then finding the person inside the company who owns each one. Owner discovery is the real bottleneck, and reading the recipient side of email is how you clear it.

Shadow IT · to governance

SC-FL-05 · REV A · 2026.07

01Discover senders

rua · shadow IT

02Attribute owner

ruf+ · recipients

03Authorize service

SPF · DKIM

04Enforce policy

p=reject

05Govern ongoing

monitor · new senders

Owner discovery drops from 18 to 24 months per domain to roughly 45 to 90 days.

Flow diagram showing the enforcement path: discover every service sending as the domain, attribute each to its internal owner through recipient-side analysis, authorize it with aligned authentication, enforce the policy, and govern new senders continuously.
01

Why the impersonation fight moved to Japan

Japanese business email is unusually vulnerable to impersonation. Communication is formal, hierarchical, and title driven, so a forged message from a senior figure carries weight that bypasses ordinary caution. Attackers have noticed. Alongside the shift in attacker attention, the rules have tightened. The securities industry association now expects a reject policy from member firms, the Ministry of Internal Affairs and Communications expects quarantine or reject from telecom operators, the FSA expects DMARC from financial institutions, and NISC expects authentication from government entities. Gmail, Yahoo, and Microsoft now filter or reject unauthenticated bulk mail outright. Monitoring mode no longer satisfies either the regulators or the mailbox providers.

02

Two problems, and the second is harder

Reaching a reject policy safely means one thing above all: every legitimate sender must be known and authenticated first, or its mail gets blocked the moment enforcement turns on. That splits into two jobs. The first is discovery, finding every cloud service, marketing platform, and internal system that sends as your domain. The second is attribution, finding the employee or team who signed up for each service and can confirm it is legitimate. Discovery is difficult. Attribution is the part that stalls projects, because a sending IP address does not tell you which department inside a large enterprise is responsible for it. Company wide surveys are the usual fallback, and they miss the shadow IT that no one remembers signing up for.

03

Why aggregate reports show you the wrong half

Standard DMARC monitoring reads aggregate reports, which list the servers that sent mail as your domain. Those reports show senders, not recipients, and they stop short of naming an internal owner. The detailed failure reports that might help are largely unavailable, because the major mailbox providers do not send them for privacy reasons. So a monitoring only tool can tell you that an unknown service failed authentication, without giving you a path to the person who introduced it. You are left staring at IP addresses and guessing which business unit they belong to.

04

Reading the recipient side names the owner

Valimail approaches the problem from the other direction with RUF+, a patented method (US 11,991,139) that reads the internal recipients of a failing service's mail rather than only the sending IP. If a marketing platform sends to a specific team, the people receiving that mail point directly to the group that adopted the service, and from there to its owner. The data comes through the Mailbox Connector, an administrator granted read of inbound message metadata in Microsoft 365 or Google Workspace. It reads headers and metadata only, never message content, and it runs on a deterministic, policy based model rather than AI. Access is scoped to the domains you connect and can be revoked at any time. Valimail holds SOC 2 Type 2 and is the only FedRAMP authorized DMARC vendor, and its authentication engine holds zero personal data, which matters under the APPI.

05

From eighteen months to ninety days

The combination compresses a task that used to take one to two years per domain into roughly forty five to ninety days. Precision Sender Intelligence recognizes more than 5,500 services by name, so an unknown IP resolves to Salesforce Marketing Cloud or Zendesk rather than a number to chase, and a single sample is often enough to identify a service. Once a service is confirmed, one click authorizes it. Discovery, attribution, and authorization move from a manual survey that never quite finishes to a repeatable process that does, which is what finally makes a reject policy safe to switch on.

// Key Takeaways

What to remember

  • Reaching p=reject safely requires knowing every legitimate sender first; the blocker is rarely discovery, it is finding who owns each one
  • Aggregate DMARC reports show sending IPs, not internal owners, and the major mailbox providers withhold the detailed failure reports for privacy
  • Valimail RUF+ (patent US 11,991,139) reads the internal recipients of failing mail, pointing straight to the team that adopted a service
  • The Mailbox Connector reads Microsoft 365 or Google Workspace metadata only, never message content, and is revocable and APPI friendly
  • Owner discovery drops from 18 to 24 months per domain to roughly 45 to 90 days, which is what makes enforcement safe to switch on

// FAQ

Frequently asked questions

Q1

What is Shadow IT in the context of DMARC?

Shadow IT is any cloud service or application that sends email as your domain without the security team's knowledge, such as a marketing tool a department signed up for directly. It matters for DMARC because every one of these senders must be found and authenticated before a domain can move to p=reject, or its mail will be blocked.

Q2

Why is finding the owner of a sending service so hard?

A DMARC aggregate report shows the IP address that sent mail, not the person or team responsible for it. In a large Japanese enterprise with thousands of employees, an unfamiliar IP gives no clue which business unit adopted the service. Manual, company wide surveys are slow and routinely miss services no one remembers approving.

Q3

How does Valimail identify the owner of a Shadow IT sender?

Valimail RUF+ (patent US 11,991,139) reads the internal recipients of a failing service's mail rather than only the sending IP. The employees receiving that mail point to the team that adopted the service. The data comes from the Mailbox Connector, which reads Microsoft 365 or Google Workspace metadata only, never message content.

Q4

Does owner discovery read the contents of our email?

No. The Mailbox Connector reads message headers and metadata only, never bodies, attachments, or links, and runs on a deterministic model rather than AI. Access is scoped to the domains you connect and revocable at any time. Valimail holds SOC 2 Type 2, is the only FedRAMP authorized DMARC vendor, and keeps its authentication engine free of personal data.

Q5

How long does service owner identification take?

By hand it has taken 18 to 24 months per domain in large organizations. With RUF+ and Precision Sender Intelligence, which recognizes more than 5,500 services by name, the same work compresses to roughly 45 to 90 days, and it is repeatable across every domain in a group.

Last updated:

Scoping Japan entry in this category?

If your company is weighing Japan entry in the work above, StrategyCore is the operating layer that carries it from first assessment to live deployments, run locally and in Japanese.