Protect your domain: DMARC and BIMI
Anyone can send an email that claims to be from your domain. DMARC is one DNS record that tells Gmail, Outlook and Yahoo what to do with those fakes, and asks them to send you a daily report of who is sending mail as you. BIMI builds on it to show your brand logo next to your emails in the inbox.
What DMARC does
When you verify a domain with Resend, you add SPF and DKIM records. They prove that mail sent through Resend really comes from you. DMARC is the rule for everything else: what an inbox should do when a message says it’s from your domain but fails those checks.
| Setting in BlnkSpace | Record | What happens to fakes |
|---|---|---|
| Monitor | p=none | Nothing is blocked. You only get reports. Gmail and Yahoo expect at least this from anyone sending regularly, so a missing record already hurts delivery. |
| Send fakes to spam | p=quarantine | Mail that fails goes to the spam folder. |
| Block fakes | p=reject | Mail that fails is refused and never arrives. |
The safe way to set it up
Choose Monitor (recommended to start) and add a reports address. BlnkSpace won’t offer Block fakes until your domain has a working DMARC record, because jumping straight to it can silently block your own mail.
Inboxes send a daily summary (an XML file) of every server that sent mail as your domain. Free tools such as dmarcian, Postmark’s DMARC digests or EasyDMARC turn them into a readable list. Look for services you use that are failing: Google Workspace, Microsoft 365, a newsletter or helpdesk tool, your website’s contact form.
Each one needs its own SPF/DKIM set up for your domain (their help pages explain how). Mail sent through BlnkSpace already passes, because it goes through your verified Resend domain.
Come back to Protect your domain, choose the next level, and replace the record at your DNS host. Press Check again to confirm it’s live.
Adding the record at your DNS host
| Field | What to enter |
|---|---|
| Type | TXT |
| Name / Host | _dmarc. Some hosts want the full name, e.g. _dmarc.yourdomain.com. If yours adds the domain automatically, entering the full name creates _dmarc.yourdomain.com.yourdomain.com, which doesn’t work. |
| Value | The record BlnkSpace shows, e.g. v=DMARC1; p=none; rua=mailto:reports@yourdomain.com; |
_dmarc record; don’t add a second one. With two, inboxes ignore DMARC completely, and BlnkSpace shows this as a red warning.Reports address: use an address on the same domain (e.g. dmarc@yourdomain.com). Reports to an address on another domain are only delivered if that other domain publishes a small permission record. BlnkSpace tells you the exact record when this applies. Subdomains follow the main domain’s setting unless you choose otherwise under Advanced.
BIMI: your logo in the inbox
BIMI shows your brand logo as the sender’s profile picture next to your emails, instead of a plain initial, in Gmail, Yahoo and Apple Mail (Outlook doesn’t support it). It’s optional and mostly worth it for established brands, because it needs three things:
| You need | Details |
|---|---|
| DMARC that acts on fakes | Send fakes to spam or Block fakes, for all mail. Monitor isn’t enough. BlnkSpace’s Protect your domain section tells you when you’re there. |
| Your logo as an SVG | A square logo in the strict SVG Tiny Portable/Secure format, hosted at a public https:// address. Ordinary SVG exports are usually rejected; most designers and the certificate issuers can convert it. |
| A logo certificate | A VMC (Verified Mark Certificate, needs a registered trademark; works in Gmail, Yahoo and Apple Mail) or a CMC (Common Mark Certificate, needs the logo to have been in use for a year; Gmail and Yahoo only). Bought from DigiCert, GlobalSign or SSL.com. It costs money every year and takes a few weeks to issue. |
Once you have all three, add one more TXT record at your DNS host:
| Field | What to enter |
|---|---|
| Type | TXT |
| Name / Host | default._bimi |
| Value | v=BIMI1; l=https://yourdomain.com/logo.svg; a=https://yourdomain.com/certificate.pem; |
.pem file and usually checks the logo for you. After adding the record, open Protect your domain and press Check again: the BIMI line confirms the record is found. Inboxes can take a few days to start showing the logo.Troubleshooting
| What you see | What it means |
|---|---|
| Still "No DMARC record" after adding it | DNS changes can take up to an hour (occasionally longer) to show. Also check the Name: _dmarc, not _dmarc.yourdomain.com.yourdomain.com. |
| "There are two DMARC records" | Delete one at your DNS host so only the one you want is left. |
| "Block fakes" is greyed out | Your domain has no working DMARC record yet. Start with Monitor, read the reports, then move up. |
| "Protected ... for N% of mail only" | Your record has a pct= value below 100. Few inboxes honour it, and BIMI needs it at 100. Generating a new record from BlnkSpace removes it. |
| Your own emails started landing in spam after moving up | A service that sends as your domain is failing the checks. Go back one level, find it in your reports, and fix its SPF/DKIM before moving up again. |