Suped

Does BIMI require a reject policy on the top level domain if subdomains have it?

Summary

The question of whether BIMI requires a DMARC reject policy on the top-level domain, even when subdomains already have one, is a common point of confusion for email senders. This summary aims to clarify the requirements and implications for successful BIMI implementation.

Suped DMARC monitor
Free forever, no credit card required
Get started for free
Trusted by teams securing millions of inboxes
Company logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logo

What email marketers say

Email marketers often face challenges balancing brand visibility, email deliverability, and security protocols like DMARC and BIMI. Many are keen to implement BIMI for its branding benefits but are hesitant about enforcing a reject policy at the organizational domain level due to potential deliverability risks for legitimate mail. The discussion frequently revolves around whether subdomain-level DMARC enforcement is sufficient for BIMI display.

Marketer view

Email Marketer from Email Geeks indicates that they are looking into BIMI but currently lack a reject policy for their top-level domain. They are seeking clarification on whether BIMI will still function for emails sent from subdomains which do have a reject policy.

10 Nov 2022 - Email Geeks

Marketer view

Email Marketer from Email Geeks suggests that a DMARC quarantine policy is also acceptable for BIMI, not just reject. This provides a slightly less stringent option for those not ready for full rejection.

10 Nov 2022 - Email Geeks

What the experts say

Email deliverability experts consistently emphasize the importance of a strong DMARC policy at the organizational level for BIMI success. Their insights often focus on the cascading nature of DMARC and the technical requirements to ensure a brand's logo is reliably displayed in supporting inboxes.

Expert view

Expert from Email Geeks states that the top-level domain's DMARC policy must be at quarantine or reject for BIMI to work, regardless of subdomain policies. This ensures that the entire domain structure is secure.

15 Jan 2023 - Email Geeks

Expert view

Expert from Word to the Wise advises that while subdomains can have specific DMARC records, the foundational requirement for BIMI remains the organizational domain having a policy of quarantine or reject.

12 Mar 2024 - Word to the Wise

What the documentation says

Official documentation and technical specifications for BIMI and DMARC consistently underscore the requirement for a strong DMARC enforcement policy at the organizational domain level. These documents serve as the authoritative source for understanding the protocol's prerequisites and how subdomains interact with the overall policy.

Technical article

Documentation from BIMI Group states that senders must have a DMARC policy of at least quarantine or reject. This confirms the baseline requirement for any domain aiming to implement BIMI.

10 Aug 2020 - BIMI Group

Technical article

Mailgun documentation clarifies that senders must have a policy of quarantine or reject before a BIMI inbox logo is displayed, noting that a special policy of none for subdomains is insufficient for BIMI.

01 Oct 2023 - Mailgun

10 resources

Start improving your email deliverability today

Get started