October 1, 2026
You can’t get your logo in the inbox without doing the unglamorous work first. That’s the message Mailgun and Red Sift brought to a recent joint webinar on getting to BIMI enforcement, hosted by Red Sift’s Natalie Hays alongside Mailgun’s JT Torres and Red Sift’s Iris Cox.
The session covered the full path: why SPF, DKIM, and DMARC exist, why so few senders actually enforce DMARC today, and what it takes to earn a Brand Indicators for Message Identification (BIMI) logo next to your emails. Along the way, the team demoed Red Sift’s new BIMI Maker tool and answered live questions from the audience. Here’s what you need to know.
Table of contents
Table of contents
What is email authentication, and why does it matter now?
Email authentication is how you prove the messages landing in your customers’ inboxes actually came from you, not someone pretending to be you. Setting up a server and hitting send stopped being enough long ago. Today, mailbox providers expect three layers working together: SPF, DKIM, and DMARC.
SPF: your published sender list
SPF (Sender Policy Framework) is the oldest of the three. As JT put it on the webinar, it works like a phone book listing: you publish the IP addresses allowed to send on your domain’s behalf, so mailbox providers can check whether a message really came from where it claims.
DKIM: the padlock on every message
DKIM often gets filed away as just another layer of email authentication, but it does more than that. It’s a digital signature that proves a message really came from you, not someone borrowing your name. That same signature also gives your email deliverability a boost. Our tip is to use a 2048-bit keyover the older 1024-bit standard where you can, and rotate it regularly to make it harder for an attacker to reuse.
I like to form it as a lock-and-key kind of thing. Your key is published publicly, and that’s the padlock you’re putting on your email. If anybody messes with it, that key should no longer work.
JT Torres Technical Account Manager, Sinch Mailgun
DMARC: the policy that ties it together
DMARC (Domain-based Message Authentication, Reporting, and Conformance)takes SPF and DKIM and turns them into a policy. Red Sift’s Iris Cox summed it up best:
SPF is the invitation list for the event. DKIM is the badge, the unique badge with the cool little shiny logo on it. DMARC is the bouncer at the front who decides: are you allowed in, or do I need to boot you out?
DMARC got its start in 2011, when a group of major email senders and receivers, including Gmail, Yahoo, Hotmail, PayPal, Bank of America, and LinkedIn, began working together to solve a shared problem: SPF and DKIM could verify a message, but there was no standard way to tell mailbox providers what to do when a message failed those checks. The first DMARC specification published in January 2012, giving domain owners a way to publish a policy and get visibility into who was sending mail on their behalf. Sounds good, right? But DMARC adoption didn’t take off like mailbox providers thought.
Pro tip: A DMARC policy has three settings: p=none (report only), p=quarantine (send failures to spam), and p=reject (block them outright). Learn the full five-step DMARC setup
Why is DMARC enforcement still relatively rare?
Here’s the uncomfortable number from the webinar: only about 7% of organizations have actually reached DMARC enforcement – quarantine or reject at 100%. The other 93% are sitting at p=none, collecting reports but doing nothing to stop the senders who shouldn’t be there.
This isn’t just a big-brand problem. Plenty of senders assume they’re too small to be a target, or that transactional mail doesn’t count. It does. JT shared a favorite example: an office printer-scanner still quietly sending email from a 2003 configuration, discovered only once a company started auditing its DMARC reports. Every domain accumulates senders like that over time, and each one is a gap an attacker can exploit.
How do you move from p=none to enforcement without breaking your mail flow?
Start by identifying every sender using your domain before you change anything. Let DMARC reports come in for a few weeks at p=none, then review who’s actually sending: your ESP, your CRM, that forgotten marketing tool, and yes, possibly a printer. Fix or remove the SPF and DKIM records for anything that shouldn’t be sending, then move to p=quarantine before you ever touch p=reject. Quarantine sends unauthenticated mail to spam instead of bouncing it, so it works as a safety net while you catch what you missed.
JT added one more piece: coordinate internally before you flip the switch, since recruiting and sales tools often send email from the company domain without IT or marketing knowing. The bigger the company, the more likely someone else is sending mail you don’t know about.
Pro tip: If you want a second set of eyes before you move to enforcement, Mailgun’s Deliverability Services team of authentication experts can review your setup with you.
What is BIMI, and what’s the payoff?
Once you hit p=quarantine or p=reject at 100%, you’ve unlocked BIMI (Brand Indicators for Message Identification).
I like to think of BIMI as a prize for reaching quarantine 100% or reject 100%. It’s a certificate that tells the internet: I am who I say I am.
Iris Cox Customer Success Engineer, Red Sift
BIMI puts your logo next to your emails in supporting inboxes, backed by a certificate proving you have the rights to use it: either a Common Mark Certificate (CMC), or, for trademarked logos, a Verified Mark Certificate (VMC). A CMC runs around $1,000 USD a year for the first domain, with additional domains on the same logo priced around $450 each.
The payoff is measurable. Red Sift’s own research found that a BIMI-verified logo drove a 44% increase in brand recall, a 39% increase in email open rates, and a 32% increase in purchase intent compared to no logo at all. JT noted Mailgun has seen similar upticks in its own research. See the technical setup for a BIMI DNS record →
Getting your logo in the inbox: Red Sift’s new BIMI Maker tool
Getting a CMC or VMC has historically meant a lot of do-it-yourself work: preparing an SVG file, verifying domain ownership, and navigating a certificate authority’s application. Red Sift built BIMI Maker to collapse that into one guided flow. Upload or search for your logo, and the tool converts it into a properly formatted SVG, previewed in light mode, dark mode, and the rounded-square and circle crops different inbox apps use. From there, you choose a CMC or VMC, verify your domain and logo ownership, and the tool runs a full readiness check before you apply. It’s free, live now, and open to anyone.
If your domain is already at DMARC enforcement, BIMI Maker is the fastest way to see what your logo will actually look like in the inbox before you commit to a certificate. And if you’re still working toward enforcement, a free Mailgun account or a free DMARC account with Red Sift is a reasonable place to start watching your own reports.
Want more deliverability deep-dives like this one? JT co-hosts Email’s Not Dead, Sinch Mailgun’s podcast on everything email.
Keep me posted! Get great resources in your inbox every week.









