Why DMARC and BIMI are a business priority

Email threats aren’t slowing down, and neither should your authentication strategy. In our recent joint webinar with Marigold, “From DMARC to BIMI: Navigating the New Email Authorization Landscape,” we broke down what today’s evolving standards mean for both security and marketing teams—and how to take action now with our free Red Sift Investigate tool.

If you missed the live session or want the highlights, here’s your quick-fire recap.

Email authentication is rapidly changing

The session kicked off with Red Sift’s Brian Westnedge alongside Marigold’s Casey Stopperan and Ken Pfeiffer broke down the new bulk sender rules from Gmail and Yahoo (and now Microsoft). As of early 2024, both providers are enforcing stricter DMARC requirements for bulk senders—raising the bar for deliverability and domain protection, with Microsoft joining the party in 2025.

In fact, since the announcement in November 2023, domains with DMARC reporting enabled have increased from 6 million to 10 million. If you haven’t yet caught up, these updates are no longer optional. Brands must prove they’re legitimate senders, or risk getting filtered out completely for bulk senders.

DMARC: Your best line of defense

Domain-based Message Authentication, Reporting & Conformance (DMARC) isn’t new—but now it’s non-negotiable. Casey and Ken explained how DMARC helps prevent spoofing and phishing by letting domain owners tell inbox providers how to handle unauthorized email.

But as Brian emphasized, simply having a DMARC record isn’t enough. You need full alignment, proper enforcement, and real-time visibility across every platform and tool sending email on your behalf. Red Sift’s integrated monitoring, Red Sift OnDMARC, helps businesses uncover hidden senders and move from monitoring to enforcement with confidence.

BIMI: Boost security and your brand

Once DMARC is enforced, Brand Indicators for Message Identification (BIMI) is enabled. BIMI lets you display your verified logo next to emails in the inbox—making your brand instantly recognizable and more trustworthy. 

There’s a catch: BIMI requires a strict DMARC policy (p=quarantine or p=reject) and either a Common Mark Certificate (CMC) or a Verified Mark Certificate (VMC). Once DMARC is enforced, BIMI is enabled ready to boost your brand, letting your verified logo appear next to your emails in the inbox—creating instant recognition and trust.

Ken further highlighted how BIMI aligns perfectly with Marigold’s focus on deliverability and brand engagement. Meanwhile, Brian showed how Red Sift simplifies the process of getting BIMI-ready by managing everything from VMCs and CMCs to logo validation.

The bottom line? BIMI transforms authentication from a compliance task into a brand-building tool, excellent for security and marketing teams alike.

Get started with Red Sift OnDMARC

Red Sift OnDMARC is purpose-built to help businesses move from passive monitoring to active enforcement. With automated discovery, a dedicated customer success team, and integrated BIMI readiness, OnDMARC makes it easy to protect your domain from spoofing and phishing attacks, while providing enhanced email deliverability, and a needed boost to your brand’s visibility in every inbox. 

Whether you’re looking to comply with the latest Gmail, Yahoo and now Microsoft requirements or turn your authentication into a marketing advantage, OnDMARC gives you the tools, insights, and support to get there with confidence. Start your journey with a free domain check using Red Sift Investigate.

PUBLISHED BY

Jack Lilley

22 Apr. 2025

SHARE ARTICLE:

Recent Posts

VIEW ALL
Product Release

Red Sift’s Quarterly Product Release, Fall 2025

Francesca Rünger-Field

This Fall marks a major expansion of Red Sift Brand Trust with the launch of Social Media Monitoring, a new add-on that helps organizations detect and respond to fraudulent company and executive profiles across platforms such as Facebook, Instagram, LinkedIn, TikTok, and X. By extending protection beyond domains, Brand Trust now gives security teams…

Read more
AI

Red Sift’s AI Agent, Part III: Performance in action

Phong Nguyen

This is the third article in our AI Agent series. In Part 1, we introduced Red Sift’s AI Agent for lookalike classification – an intelligent solution for handling the ambiguous cases that rule-based automation can’t confidently resolve, offering analyst-grade triage autonomously. In Part 2, we took readers behind the scenes to explore the engineering…

Read more
Finance

41% of top Fintech companies are vulnerable to email phishing

Jack Lilley

Only 26% of leading Fintechs enforce DMARC at p=reject, the strongest protection against spoofing by bad actors. Phishing remains a top driver of breaches and fraud. Financial services are a prime target because email moves money, resets passwords, and confirms identity. Verizon’s 2025 Data Breach Investigations Report again lists social engineering and phishing among…

Read more
Certificates

New in Certificates Lite: Active certificate scanning and smarter expiry alerts

Francesca Rünger-Field

A quick recap Earlier this year, we launched Red Sift Certificates Lite, the free TLS certificate expiration monitoring service recommended by Let’s Encrypt. Since launch, thousands of organizations have adopted it to track their certificates and avoid expiry-related outages. What we heard from customers At launch, we had adopted Let’s Encrypt’s approach for consistency…

Read more