DALI Security Research

Nikkei 225 Domain Security Index

A comprehensive 12-check security audit of 306 domains belonging to Japan's largest publicly traded companies — including .com, .co.jp, and major subsidiary brands — every major Nikkei 225 constituent.

March 3, 2026 · 306 domains · 12 security checks per domain · Automated with DALI Engine

Key Findings

Score Distribution

Domains are scored 0–100 across 12 checks: DNS security (DNSSEC, CAA, NS, SPF, DMARC), HTTP headers (HSTS, CSP, security.txt), email auth (MTA-STS, BIMI), and registrar hygiene (locks, enterprise registrar).

Security Score Distribution

Score Categories

Security Feature Adoption

How many Nikkei 225 domains deploy each security feature? The results reveal major gaps.

All 12 Security Checks

DMARC Policy Breakdown

HTTP Security & Email Auth

Beyond DNS: HSTS enforces HTTPS, CSP prevents injection, security.txt invites responsible disclosure, MTA-STS encrypts email transport, and BIMI authenticates brand identity in email.

Sector Breakdown

Average security score by industry sector. Finance leads; most sectors score below 30.

Average Score by Sector

DNS Provider Distribution

Nikkei 225 vs Fortune 500

How does Japan’s corporate security posture compare to the US? Side-by-side comparison using the same 12-check methodology.

Overall

Avg ScoreNikkei: 22.6 vs F500: 21.4
Domains Audited306 vs 5,000
Score 90+0 vs 0
Score <3076% vs 78%

Feature Adoption (%)

SPF90.5% vs 87.2%
DMARC79.4% vs 78.1%
DNSSEC17.6% vs 7.1%
HSTS27.8% vs 28.6%
CSP9.8% vs 18.0%
security.txt2.6% vs 4.1%
MTA-STS0.3% vs 0.6%
BIMI5.2% vs 3.2%
CAA2.0% vs 13.8%
Reg Locks27.8% vs 62.4%

Full Results

All 306 Nikkei 225 domains ranked by security score. Click column headers to sort.

Company Domain Sector Score Locks DNSSEC DMARC CAA HSTS CSP sec.txt MTA-STS BIMI

Methodology

Each domain is scored across 12 dimensions, totaling 100 points max.

Registrar Locks

EPP status flags: clientTransferProhibited, clientDeleteProhibited, clientUpdateProhibited, and server-side equivalents

15 points max

DNSSEC

Presence of DS/DNSKEY records indicating DNSSEC is active

10 points

CAA

Certificate Authority Authorization records restricting which CAs can issue certs

8 points

NS Redundancy

Number of nameservers (4+ = 7 pts, 2–3 = 4 pts)

7 points max

Enterprise Registrar

Using a corporate-grade registrar (CSC, MarkMonitor, Safenames, etc.)

5 points

DMARC

DMARC record presence and policy (reject=10, quarantine=7, none=3)

10 points max

SPF

Sender Policy Framework TXT record

5 points

HSTS

Strict-Transport-Security header enforcing HTTPS (1yr=10, 30d=7, any=4)

10 points max

CSP

Content-Security-Policy header preventing XSS and injection attacks

10 points

security.txt

RFC 9116 standard for vulnerability disclosure at /.well-known/security.txt

10 points

MTA-STS

Mail Transfer Agent Strict Transport Security — enforces encrypted email delivery

10 points

BIMI

Brand Indicators for Message Identification — authenticated brand logo in email

5 points