4 ms·
Gmail deploys support BIMI security standard
- technion 5y agoI looked into this when it came out because the associated mail delivery technologies are something I try to keep on top of. But I really think it's a stretch to call BIMI a "security standard". It reads a lot more like "The CA industry wants to make super expensive EV certs relevant again", and I'm not convinced it does much else.
- WaitWaitWha 5y ago> With today’s announcement, Gmail now joins Yahoo, AOL, and Fastmail as the only email providers to support BIMI-authenticated logos inside their email clients. [...] > Today, only DigiCert and Entrust can issue VMCs for BIMI authentication... As a cynic, it feels like I am herded into "trusted", and "secure" solution, to abandon my personal or non-megalodon mail server, that does not have the verified logo.
- brongondwana 5y agoThe verification side is easy enough to add to your server if you want to see BIMI-authenticated logos from other sites (fsvo "easy"). Having your own logo authenticated is much trickier, you need trademarks and stuff - because it's supposed to have some phishing protection. Also it's designed to coerce brands into making sure all their email authentication alignment is correct, because BIMI won't display unless all the DKIM and SPF checks out.
- deleted 5y ago[deleted]