Why DMARC and BIMI are a business priority

Email threats aren’t slowing down, and neither should your authentication strategy. In our recent joint webinar with Marigold, “From DMARC to BIMI: Navigating the New Email Authorization Landscape,” we broke down what today’s evolving standards mean for both security and marketing teams—and how to take action now with our free Red Sift Investigate tool.

If you missed the live session or want the highlights, here’s your quick-fire recap.

Email authentication is rapidly changing

The session kicked off with Red Sift’s Brian Westnedge alongside Marigold’s Casey Stopperan and Ken Pfeiffer breaking down the new bulk sender rules from Gmail and Yahoo (and now Microsoft). As of early 2024, both providers are enforcing stricter DMARC requirements for bulk senders—raising the bar for deliverability and domain protection, with Microsoft joining the party in 2025.

In fact, since the announcement in November 2023, domains with DMARC reporting enabled have increased from 6M+ to 10M+. If you haven’t yet caught up, these updates are no longer optional. Brands must prove they’re legitimate senders, or risk getting filtered out completely for bulk senders.

DMARC: Your best line of defense

Domain-based Message Authentication, Reporting & Conformance (DMARC) isn’t new—but now it’s non-negotiable. Casey and Ken explained how DMARC helps prevent spoofing and phishing by letting domain owners tell inbox providers how to handle unauthorized email.

But as Brian emphasized, simply having a DMARC record isn’t enough. You need full alignment, proper enforcement, and real-time visibility across every platform and tool sending email on your behalf. Red Sift’s integrated monitoring, Red Sift OnDMARC, helps businesses uncover hidden senders and move from monitoring to enforcement with confidence.

BIMI: Boost security and your brand

Once DMARC is in place and enforced, you can take the next step: BIMI (Brand Indicators for Message Identification). BIMI lets you display your verified logo next to emails in the inbox—making your brand instantly recognizable and more trustworthy. 

There’s a catch: BIMI requires a strict DMARC policy (p=quarantine or reject) and either a Common Mark Certificate (CMC) or a Verified Mark Certificate (VMC). Once DMARC is enforced, BIMI is enabled ready to boost your brand, letting your verified logo appear next to your emails in the inbox—creating instant recognition and trust.

Ken further highlighted how BIMI aligns perfectly with Marigold’s focus on deliverability and brand engagement. Meanwhile, Brian showed how Red Sift simplifies the process of getting BIMI-ready by managing everything from VMCs and CMCs to logo validation.

The bottom line? BIMI transforms authentication from a compliance task into a brand-building tool, excellent for security and marketing teams alike.

Get started with Red Sift OnDMARC

Red Sift OnDMARC is purpose-built to help businesses move from passive monitoring to active enforcement. With automated discovery, a dedicated customer success team, and integrated BIMI readiness, OnDMARC makes it easy to protect your domain from spoofing and phishing attacks, while providing enhanced email deliverability, and a needed boost to your brand’s visibility in every inbox. 

Whether you’re looking to comply with the latest Gmail, Yahoo and now Microsoft requirements or turn your authentication into a marketing advantage, OnDMARC gives you the tools, insights, and support to get there with confidence. Start your journey with a free domain check using Red Sift Investigate.

PUBLISHED BY

Jack Lilley

22 Apr. 2025

SHARE ARTICLE:

Recent Posts

VIEW ALL
BEC

DMARC: The best ROI for your organization

Jack Lilley

Executive summary: Implementing DMARC delivers one of the clearest, fastest returns on investment in email security. By authenticating outgoing mail and blocking spoofed messages, DMARC cuts the direct costs of phishing and Business Email Compromise, safeguards brand reputation, and boosts deliverability—ultimately driving revenue and trimming operational workload. Key takeaways: Email is a critical communication tool for…

Read more
DMARC

400,000 DMARC boost after Microsoft’s high-volume sender update

Jack Lilley

Microsoft’s decision to join Google and Yahoo in enforcing stricter rules for high-volume senders has triggered an immediate response across the internet. In the last 30 days alone, 406,042 new domains have deployed Domain‑based Message Authentication, Reporting & Conformance (DMARC), pushing the global total to 10.9 million. While not all domains will be exclusive Outlook users,…

Read more
DMARC

Red Sift partners with Gradian to strengthen email security through OnDMARC

Jack Lilley

Today Red Sift launches a new partnership with Gradian, a leading data protection provider, to offer its award-winning applications, including Red Sift OnDMARC, to new and existing customers. Established through Red Sift’s relationship with UK distributor E92plus, the two companies look to strengthen defences against phishing and Business Email Compromise (BEC) attacks. Allowing organisations…

Read more
Cybersecurity

DMARCbis: What are the changes and how to be ready

Jack Lilley

Executive Summary: DMARCbis, also known as DMARC 2.0, is the forthcoming update to the DMARC email authentication protocol, designed to address limitations and ambiguities in the original standard, with an expectation to be finalized and published in 2025. The update introduces clearer guidelines, a new method for determining organizational domains, and streamlined record management.…

Read more