Making your domain hard to forge

Email was designed without any check on the sender. Anyone can write a message that shows your domain in the From line, and many phishing campaigns do exactly that. Three standards, published in the DNS of your domain, let receiving servers verify the sender and refuse the forgeries; a fourth puts your logo next to the messages that pass.

What SPF, DKIM, DMARC and BIMI do

  • SPF lists the servers allowed to send email for your domain.
  • DKIM signs each message, so that the receiver can check that it was not altered and that it comes from a domain that holds the key.
  • DMARC tells receivers what to do with a message that fails these checks (deliver it, put it in quarantine, or reject it) and sends you reports on who sends email in your name.
  • BIMI displays your logo in the mail clients that support it, for messages that pass DMARC under an enforced policy. Some mailbox providers also require a certificate tied to a registered trademark.

Why it matters

A domain without DMARC can be used to send phishing that seems to come from you, to your customers, your suppliers or your own staff. Large mailbox providers increasingly expect senders to authenticate their mail, so authentication also helps your genuine messages reach the inbox. The domains you hold but never use for email need protection too: a strict record tells receivers that no message should ever come from them.

How Domgate handles it

  • Inventory. We list the services that send email for you (your mail platform, newsletters, invoicing, support tools), domain by domain.
  • Records. We publish SPF, DKIM and DMARC in the DNS of your domains, starting with a monitoring policy that changes nothing for delivery.
  • Reports. We read the DMARC reports to find the genuine senders still missing and the sources that forge your domain.
  • Enforcement. Once every genuine sender passes, we move the policy to quarantine, then to reject, and add BIMI when you want your logo shown.

What you provide

Access to the DNS of the domains concerned, or their management by Domgate; the list of the tools that send email on your behalf; and, for BIMI, your logo and, where a mailbox provider requires it, the trademark registration that covers it.

Who it is for

Any organisation whose name is used in email, and especially brands targeted by phishing, companies with many domains, and groups whose subsidiaries send email from different platforms.

DMARC and BIMI: frequent questions

Will DMARC stop my own emails from being delivered?

Not when it is introduced step by step. We start with a policy that only collects reports, make sure every genuine sender passes, and only then ask receivers to quarantine or reject the rest.

Do domains that never send email need DMARC?

Yes. Those domains can still be forged. A record stating that no server sends email for them, with a reject policy, closes that door without affecting your mail.

What does BIMI require?

A DMARC policy set to quarantine or reject, a logo in the required format and, for some mailbox providers, a certificate for the logo, which may require a registered trademark. We tell you which conditions apply to the inboxes your customers use.

Contact Domgate

Explore your opportunities Let's get in touch!