MediumPolicy · usually medium
BIMI record published without DMARC enforcement
BIMI requires a DMARC policy of quarantine or reject. The record will be ignored.
Check your own domain
What causes this
BIMI is only honoured for domains at DMARC enforcement, because the logo is a trust signal and it would be actively harmful to display it for a domain anyone can forge. With p=none the BIMI record is published but no provider will act on it.
What it breaks
The logo is not displayed. The BIMI record has no effect until the DMARC policy is raised.
How to fix it
Raise the DMARC policy to quarantine or reject.
- Work through DMARC aggregate reports until every legitimate sender authenticates with alignment.
- Raise p= to quarantine, then reject.
- BIMI then takes effect with no further change to the BIMI record.
Specification: BIMI Group — specification
Related problems
- External reporting address is not authorisedReports are directed to another domain that has not published the required authorisation record.
- DMARC record requests no aggregate reportsThere is no rua address, so you receive no data about who sends as your domain.
- DMARC policy is set to noneThe policy monitors but does not act — failing mail is still delivered.
- Subdomain policy is weaker than the domain policysp= is set to a laxer value than p=, leaving subdomains less protected.
- Non-sending domain is not protected against forgeryThis domain appears not to send mail, but publishes no policy preventing others from doing so.