> ## Documentation Index
> Fetch the complete documentation index at: https://docs.textyess.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Email deliverability: DMARC and BIMI

> Understand DMARC policies, when to move to enforcement, and what BIMI needs.

## What is DMARC?

DMARC is a rule in the DNS of your domain. It tells inbox providers, such as Gmail and Yahoo, what to do with email that fails authentication. Authentication is the SPF and DKIM check. DMARC protects your domain against spoofing, where a bad actor sends email that pretends to come from you.

Google and Yahoo require a DMARC record for bulk senders. TextYess adds one for you when you set up a sending domain.

## The three DMARC policies

A DMARC record has a policy value, written as `p=`. There are three policies:

* `p=none` — Monitor only. The inbox provider takes no action on email that fails authentication. It still delivers the email. This policy meets the Google and Yahoo rule, but it does not stop spoofing.
* `p=quarantine` — The inbox provider sends failed email to the spam folder.
* `p=reject` — The inbox provider blocks failed email. The recipient never sees it.

`none` gives the least protection. `reject` gives the most.

## What TextYess sets up

TextYess creates your DMARC record with `p=none`. This is the safe default. It meets the bulk-sender rule, and it never blocks your legitimate email.

TextYess is designed to send your email from a dedicated subdomain, for example `updates.yourbrand.com`. We recommend that only TextYess sends from this subdomain.

## When to move to enforcement

Move to `p=quarantine` or `p=reject` when you want to stop spoofing of your domain.

<Warning>
  Enforcement filters or blocks every email from the domain that fails SPF or DKIM. Move to enforcement only after you make sure that all legitimate email from the domain passes authentication.
</Warning>

If only TextYess sends from the subdomain, enforcement is safe. TextYess email passes authentication, so enforcement does not filter it. You can then move the subdomain to enforcement with low risk.

Do not change the DMARC policy on your root domain (for example `yourbrand.com`) until you check every service that sends email from it. A missed service loses its email at enforcement.

## How to move to enforcement

<Steps>
  <Step title="Open your DNS provider">
    Sign in to the DNS provider for your domain.
  </Step>

  <Step title="Find the DMARC record">
    Find the TXT record named `_dmarc.<your-sending-subdomain>`. Its value starts with `v=DMARC1; p=none`.
  </Step>

  <Step title="Change the policy">
    Change `p=none` to `p=quarantine`. Save the record.
  </Step>

  <Step title="Watch delivery, then move to reject">
    Watch your email delivery for two to four weeks. If your legitimate email arrives as normal, change `p=quarantine` to `p=reject` for full protection.
  </Step>
</Steps>

## BIMI: your brand logo in the inbox

BIMI (Brand Indicators for Message Identification) shows your brand logo next to your sender name in Gmail and Apple Mail. BIMI needs three things:

1. A DMARC policy of `p=quarantine` or `p=reject`. BIMI does not work with `p=none`. Move to enforcement first.
2. Your logo as an SVG file, in the SVG Tiny PS profile, on a square canvas.
3. A Verified Mark Certificate (VMC) for Gmail. A VMC proves that you own the trademark for the logo. You buy it from a certificate provider, and it has a yearly cost.

You then add a TXT record named `default._bimi.<your-domain>`. Its value points to the logo and the certificate:

```
v=BIMI1; l=https://yourbrand.com/logo.svg; a=https://yourbrand.com/vmc.pem
```

<Note>
  TextYess does not manage BIMI for you today. This page explains what BIMI needs, so you can decide if it is worth the cost. Contact support if you want help.
</Note>
