What are the requirements for BIMI, and how do I troubleshoot authentication failures?
Summary
What email marketers say12Marketer opinions
Email marketer from Mailjet responds that you can use online BIMI checkers to verify if your BIMI record is properly configured and visible. This helps ensure that your logo will display correctly in supporting inboxes.
Email marketer from Gmass explains that your BIMI logo should be a square SVG file, optimized for display at various sizes. It's best to use a simple, recognizable version of your logo for maximum impact.
Email marketer from Valimail shares that BIMI necessitates DMARC enforcement. This means setting your DMARC policy to either 'quarantine' or 'reject' to instruct receiving mail servers on how to handle unauthenticated emails impersonating your domain.
Email marketer from Email Geeks shares that Google requires a VMC, which necessitates a trademarked logo, for BIMI. Also notes that low sending volume may prevent the logo from showing, but the specific cutoff is unknown.
Email marketer from EmailToolTester explains that common BIMI implementation errors include incorrect DNS record syntax, using an unvalidated VMC, or not having a DMARC policy strict enough (p=quarantine or p=reject).
Email marketer from ZeroBounce responds that implementing BIMI helps your brand stand out in crowded inboxes, increases brand awareness, and improves trust with recipients by proving you are a legitimate sender.
Email marketer from Reddit user u/email_pro explains that to troubleshoot SPF, check your DNS records to ensure your sending IPs are included. For DKIM, verify that your DKIM keys are properly configured in your DNS and that your email sending service is signing messages correctly.
Email marketer from Litmus responds that it is important to monitor your DMARC compliance regularly to ensure that your email authentication remains effective and that no unauthorized senders are using your domain. This involves setting up and reviewing DMARC reports.
Email marketer from Email Geeks shares that BIMI doesn't necessarily improve deliverability but gives you the deliverability you deserve based on your authentication setup. Studies suggest it can increase engagement.
Email marketer from Sendinblue shares to improve email authentication, ensure your SPF record includes all IPs that send email on your behalf, and generate and validate a DKIM record. Regularly check for DMARC compliance for each.
Email marketer from Email Geeks explains that one-off authentication failures are expected due to factors you can't control.
Email marketer from Email Marketing Forum shares that while BIMI does not directly impact deliverability, it can improve brand recognition and engagement in the inbox, indirectly boosting your sending reputation over time.
What the experts say6Expert opinions
Expert from Word to the Wise responds that a VMC is required if you want your BIMI logo to display in Gmail. It validates the trademarked status of your logo. You must obtain it from a recognized certification authority.
Expert from Email Geeks explains that if emails from Hubspot are failing SPF/DKIM, you should tweak your settings in Hubspot for those failed emails before moving to a quarantine.
Expert from Email Geeks responds that implementing DMARC with a 'quarantine' policy is only risky if both SPF and DKIM fail. Using DMARC tools should help assess the level of risk.
Expert from SpamResource explains that when troubleshooting authentication failures, it is crucial to thoroughly examine DMARC reports. These reports offer detailed information regarding SPF and DKIM alignment, which is essential for BIMI compliance. They further note identifying patterns of failure is also beneficial; for example, if a particular sending source consistently fails authentication, it suggests a misconfiguration that needs addressing.
Expert from Email Geeks explains that for Google, a VMC (Verified Mark Certificate) is required for BIMI implementation. Also DMARC needs to be at enforcement on p= and sp=.
Expert from Email Geeks explains that you should setup SPF/DKIM to fix authentication issues.
What the documentation says5Technical articles
Documentation from dmarcian explains that DMARC reports provide insights into authentication failures. Analyze these reports to identify the source of failures, whether it's misconfigured SPF/DKIM, or unauthorized senders using your domain.
Documentation from AuthSMTP notes that SPF records have a lookup limit of 10 DNS lookups. If your SPF record exceeds this limit, it can cause authentication failures. Try to flatten or consolidate your SPF record to stay within the limit.
Documentation from Entrust notes that a VMC verifies that you own the logo displayed with BIMI. This requires trademarking your logo and purchasing a VMC from an authorized provider.
Documentation from DigiCert shares that to obtain a VMC, you must first trademark your logo with an approved intellectual property office. Then, submit the trademark and other required information to a VMC issuing authority like DigiCert.
Documentation from BIMI Group explains that BIMI requires a DMARC policy set to 'quarantine' or 'reject', valid SPF and DKIM records, and a Verified Mark Certificate (VMC) for your logo (required by some mailbox providers like Google).