[{"data":1,"prerenderedAt":50},["ShallowReactive",2],{"tool-guide:email-policy-records":3},{"overview":4,"whatIs":5,"useCases":6,"commonMistakes":12,"relatedStandards":18,"steps":28,"example":32,"limitations":36,"faq":40},"BIMI & TLS-RPT Toolkit constructs the correct DNS owner name, optionally retrieves the public TXT record through disclosed Cloudflare DNS over HTTPS, and analyzes or generates bounded record text locally.","BIMI and TLS-RPT are newer email standards that build on the foundation of SPF, DKIM, and DMARC to improve email trust and security reporting. BIMI (Brand Indicators for Message Identification) lets domain owners display their brand logo next to authenticated emails in supporting mail clients like Gmail, Apple Mail, and Yahoo Mail. It requires a DMARC enforcement policy (quarantine or reject), an SVG Tiny PS logo, and optionally a Verified Mark Certificate (VMC) from a certificate authority. TLS-RPT (SMTP TLS Reporting) is a DNS TXT record that tells other mail servers where to send reports about TLS connection failures when delivering email to your domain — similar to how DMARC reporting works for authentication, TLS-RPT reporting works for encryption. Both standards use DNS TXT records: BIMI at default._bimi.domain (or a custom selector) and TLS-RPT at _smtp._tls.domain. This toolkit helps you look up, analyze, and generate these records.",[7,8,9,10,11],"Setting up BIMI — generate the DNS TXT record pointing to your SVG logo and optional VMC certificate, and verify the syntax before publishing.","Verifying BIMI readiness — check that a domain has a valid BIMI record, DMARC enforcement policy, and the required prerequisites for logo display.","Configuring TLS-RPT — generate a TLS-RPT DNS record specifying where to receive TLS failure reports (mailto: or https: endpoint).","Monitoring email encryption — use TLS-RPT to receive reports when other servers fail to establish TLS connections to your mail servers, indicating potential downgrade attacks or misconfiguration.","Auditing existing records — look up and analyze current BIMI and TLS-RPT records for syntax errors, missing fields, or duplicate records that invalidate the policy.",[13,14,15,16,17],"BIMI without DMARC enforcement — BIMI requires a DMARC policy of p=quarantine or p=reject. A p=none policy means no logo display, regardless of the BIMI record.","Wrong SVG format for BIMI — BIMI requires SVG Tiny Portable\u002FSecure (SVG Tiny PS), not standard SVG. Regular SVG files with scripting, external references, or unsupported elements are rejected.","Multiple TLS-RPT records — publishing more than one TLS-RPT TXT record at _smtp._tls.domain invalidates the policy. Ensure only one record exists.","Report destination unreachable — TLS-RPT report destinations (mailto: or https:) must be reachable and authorized. An unmonitored mailbox or 404 endpoint means reports are lost.","BIMI selector mismatch — the default BIMI selector is \"default\" (default._bimi.domain). If your mail system uses a custom selector, the DNS record must match.",[19,22,25],{"title":20,"url":21},"RFC 9495 — BIMI","https:\u002F\u002Fdatatracker.ietf.org\u002Fdoc\u002Fhtml\u002Frfc9495",{"title":23,"url":24},"RFC 8460 — SMTP TLS Reporting","https:\u002F\u002Fdatatracker.ietf.org\u002Fdoc\u002Fhtml\u002Frfc8460",{"title":26,"url":27},"BIMI Group — Implementation Guide","https:\u002F\u002Fbimigroup.org\u002Fimplementation-guide\u002F",[29,30,31],"Choose BIMI or TLS-RPT, enter the policy domain and BIMI selector when applicable, then review the exact TXT query and provider disclosure.","Run the explicit lookup or paste an existing record to inspect version, locations, destinations, duplicates, and extension fields.","Generate reviewable TXT content locally, then validate referenced resources and operational requirements before publishing it in DNS.",{"label":33,"input":34,"output":35},"TLS-RPT reporting policy","v=TLSRPTv1; rua=mailto:tls-reports@example.com","Version and one mailto report destination pass local syntax checks",[37,38,39],"A lookup sends the queried name and TXT type in an HTTPS GET URL; Cloudflare also receives normal connection metadata.","BIMI analysis does not download or validate SVG or certificate files, check DMARC enforcement, or predict whether a mailbox provider will display a logo.","TLS-RPT analysis does not test report-destination ownership, availability, authorization, or delivery. Multiple matching records may invalidate the published policy.",[41,44,47],{"question":42,"answer":43},"What is BIMI?","BIMI (Brand Indicators for Message Identification) lets domain owners display their logo next to authenticated emails in supporting mail clients. It requires a DMARC enforcement policy and a published DNS TXT record pointing to an SVG logo.",{"question":45,"answer":46},"What is TLS-RPT?","TLS-RPT (SMTP TLS Reporting) is a DNS TXT record that tells other mail servers where to send reports about TLS connection failures when delivering email to your domain.",{"question":48,"answer":49},"Does this tool validate my BIMI logo?","No. The tool checks the DNS record syntax and field values but does not download, render, or validate the SVG image or Verified Mark Certificate.",1788868141198]