Skip to content
← MailMaid Academy
Authentication

BIMI, MTA-STS and TLS reporting: different layers

Short answer

A logo record, transport policy and delivery report solve different problems.

Keep branding separate from transport#

BIMI concerns supported sender-logo display and provider-specific eligibility. MTA-STS concerns a published transport policy. TLS reporting helps operators receive evidence about transport issues. Publishing one record does not activate every layer.

Use the complete setup process#

Follow the relevant specification and your provider’s requirements. Validate the supporting assets and policies, not only the DNS text. A BIMI record alone does not prove logo display, trademark registration or certificate eligibility.

Read diagnostics with their limits#

DomainGuard discovers related TXT records. It does not fetch and certify the hosted policy, issue a certificate or guarantee what a recipient sees. Treat the results as an inventory for a separate deployment and validation workflow.

Primary references

Consult the current specification or provider guidance when applying these checks.

BIMI Group resourcesMTA-STS specificationTLS reporting specification

Keep reading

Authentication

After a DNS change, verify what receivers can see

There is no single propagation timer for every sender and resolver.

2 min read
Authentication

Audit SPF without guessing at DNS

Build an inventory before editing the record.

2 min read
Authentication

DKIM simple and relaxed: diagnose message changes

Look for transformations between signing and receipt.

2 min read