Suped

What are the DMARC requirements for BIMI and how does pct affect the policies?

Summary

The Brand Indicators for Message Identification (BIMI) standard relies heavily on DMARC to ensure brand logos are displayed only for authenticated emails. A crucial aspect of meeting BIMI requirements involves understanding how DMARC policies, particularly the pct (percentage) tag, apply to both organizational and subdomain policies. While the general rule is to have an enforcing DMARC policy (quarantine or reject), the specific pct requirements can vary, especially when transitioning to stronger policies or dealing with complex domain structures.

Suped DMARC monitor
Free forever, no credit card required
Get started for free
Trusted by teams securing millions of inboxes
Company logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logo

What email marketers say

Email marketers often approach BIMI implementation with practical questions about DMARC pct policies, particularly regarding the nuances between organizational and subdomain requirements. Their primary concern is often how to achieve BIMI compliance without disrupting legitimate email flows, balancing strict authentication with operational flexibility. The general consensus among marketers is the importance of moving towards an enforcing DMARC policy, acknowledging the benefits of visual brand recognition in the inbox.

Marketer view

Email marketer from Email Geeks notes that BIMI mandates enforcing DMARC policies for both organizational and subdomain levels. However, they highlight a perceived inconsistency in the documentation regarding the pct=100 requirement specifically for subdomain quarantine policies, questioning if the same strictness applies to the organizational domain. This query underscores a common point of confusion among marketers navigating the technical details of BIMI and DMARC implementation. Clearer guidance on these specifics would greatly assist in successful adoption.

01 Feb 2023 - Email Geeks

Marketer view

An email marketer from Mailchimp emphasizes that BIMI's functionality is directly tied to a DMARC record that is either set to p=quarantine or p=reject. This strict requirement ensures that only authenticated emails can display a brand's logo, reinforcing trust and security. For marketers, this means moving beyond a p=none policy is a prerequisite for leveraging BIMI's visual benefits.

22 Jan 2023 - Mailchimp

What the experts say

Industry experts provide crucial insights into the technical nuances of DMARC pct policies within the context of BIMI, often referencing the underlying RFC specifications. They clarify how the pct tag functions, particularly its implications for DMARC policies set to quarantine versus reject. Experts also offer perspectives on the future of DMARC, including the evolution of standards like DMARCbis, and the timeline for their adoption.

Expert view

Expert from Email Geeks clarifies that when the DMARC pct tag is used with a policy and is not 100, the remaining percentage automatically applies to the next weaker policy. Specifically, if p=reject pct=70 is set, the remaining 30% are treated as quarantine. This configuration is considered sufficient for BIMI because it ensures that no percentage of emails falls under a p=none policy, thereby meeting the enforcement requirement for brand logo display.

01 Feb 2023 - Email Geeks

Expert view

Expert from Email Geeks highlights that BIMI implementation depends on a strong DMARC policy, specifically quarantine or reject, on both the organizational domain and the RFC5322.From domain. For quarantine policies, the pct tag must be set to 100, ensuring full enforcement for authenticated brand display.

01 Feb 2023 - Email Geeks

What the documentation says

Official documentation and specifications clarify the precise DMARC requirements for BIMI implementation. These authoritative sources emphasize the necessity of strong DMARC policies for both organizational and sending domains. They also detail the specific conditions under which the pct tag impacts BIMI compliance, particularly for quarantine policies. Understanding these foundational documents is paramount for accurate and successful BIMI deployment.

Technical article

Documentation from IETF Datatracker, in the BIMI draft specification, clearly states that to participate in BIMI, Domain Owners must have a strong DMARC policy (quarantine or reject) on both the Organizational Domain and the RFC5322.From Domain of the message. Furthermore, it specifies that quarantine policies must not have a pct less than pct=100, setting a definitive benchmark for compliance.

01 Feb 2023 - IETF Datatracker

Technical article

Documentation from BIMI Group's Implementation Guide outlines that the DMARC policy must be at enforcement on the organizational domain and subdomains. This means policies of either p=quarantine; sp=quarantine or p=reject; sp=reject are required for BIMI participation. This guide simplifies the DMARC policy choices for implementers aiming for BIMI compliance, emphasizing full policy application across the domain structure.

22 Jan 2023 - BIMI Group

15 resources

Start improving your email deliverability today

Get started