3 Steps to Bring Your Email Authentication Up to Scratch?
There have been real changes to email delivery rules over the past couple of years. Here’s how to check your own setup — and a live tool below that does it for you in seconds.
Whenever your business sends an email, a series of automated checks run in the background to confirm it’s genuinely you. Providers like Gmail and Microsoft score every message before it lands in an inbox, trying to separate legitimate mail from spam and phishing — the fake messages that look like they’re from someone trustworthy but are designed to steal login details. Email authentication is how you pass that test.
Three things make up that check:
SPF (Sender Policy Framework)
Think of SPF as a list of approved senders for your domain. When an email goes out, the receiving server checks that list. If the sending server’s on it, the message gets through. If it’s not, the receiving server assumes someone might be impersonating you — and the email can get rejected or marked as spam.
DKIM (DomainKeys Identified Mail)
DKIM is like a tamper-proof seal on the email. It proves the message genuinely came from your domain and wasn’t altered on the way.
DMARC (Domain-based Message Authentication, Reporting, and Conformance)
DMARC is the rulebook that tells receiving servers what to do when SPF or DKIM fails — ignore it, quarantine it, or reject it outright — and it’s also what lets you see who’s sending email as your domain, authorised or not.
Since 2024, Gmail and Yahoo have required SPF, DKIM and DMARC to all be properly configured, or they’ll simply refuse to deliver your mail. A surprising number of businesses still don’t have this set up correctly, and don’t find out until customers stop receiving their emails.
We can check your setup in seconds, with nothing more than your domain name — no access to your systems needed. If anything needs fixing, we’ll walk you through exactly what and why.

Check your domain NOW!
Enter your domain below (e.g. yourbusiness.co.uk) and we’ll scan SPF, DKIM, DMARC, and your mail server records live, right now. You’ll get an overall grade plus a plain-English breakdown of exactly what’s working, what isn’t, and what to fix first — no jargon, no guesswork.
Got a good grade? What about BIMI?
BIMI — Brand Indicators for Message Identification — is the next step once your core authentication is solid. It’s what lets your company logo show up next to your emails in supporting inboxes, making your messages instantly recognisable and harder to spoof.
BIMI only works once DMARC is properly enforced, and — this is the bit most guides skip — getting your logo to actually display depends on which inbox you’re looking at:
– **Gmail and Apple Mail** require a certificate before they’ll show your logo at all — either a Verified Mark Certificate (VMC, needs a registered trademark) or a Common Mark Certificate (CMC, no trademark needed, just 12+ months of using the logo publicly).
– **Yahoo, Fastmail and AOL** will display your logo from the DNS record alone, no certificate required.
Our scanner checks for BIMI too — switch on “Advanced checks” after scanning — and tells you exactly which of these applies to your setup.
To get BIMI working, you’ll need to:
1. **Have SPF, DKIM and DMARC properly configured** — check this with the scanner above first; everything else depends on it.
2. **Prepare your logo** to BIMI’s technical spec (SVG format, specific sizing).
3. **Add a BIMI DNS record** pointing to your logo.
4. **Get a certificate** if you want it showing in Gmail or Apple Mail (VMC or CMC, see above).
5. **Keep it maintained** — logo location, certificate renewal, and your underlying DMARC enforcement all need to stay in place.
Run the scan above, and if you’d like a hand getting the rest sorted, book a call and we’ll take it from there.
