Because the certificate does not replace message authentication. SPF and DKIM help establish that the mail actually comes from authorised systems, while BIMI relies on that authenticated and aligned state before it will display a logo. If either mechanism is misaligned, the trust chain breaks and the certificate cannot compensate for the missing identity proof.
Why the mark certificate does not replace SPF and DKIM
BIMI’s certificate is a presentation control, not a substitute for message authentication. It helps a receiving system decide whether it can safely display a brand mark, but that decision still depends on whether the message passed the underlying email-authentication checks and alignment rules. In practice, the certificate sits on top of a trust chain, it does not create that chain by itself.
That is why SPF and DKIM remain part of the control set. SPF verifies which sending systems are authorised for the domain, and DKIM provides a cryptographic signature tied to the message. When those signals are aligned with the visible From domain, they give BIMI the authenticated foundation it needs before a logo can be considered trustworthy.
A useful way to think about it is that BIMI answers, “may I display the mark?”, while SPF and DKIM answer, “does this message actually come from an authorised path and signature state?” Without those answers, the mark certificate has nothing reliable to stand on, because it cannot retroactively prove the message origin or integrity.
What breaks when authentication or alignment fails
The main failure mode is not that the certificate becomes invalid in isolation, but that the email no longer satisfies the prerequisites for BIMI display. If SPF fails, the sending source may not be recognised as authorised. If DKIM fails, the message loses its cryptographic integrity signal. If alignment fails, the authenticated domain and the brand domain no longer line up cleanly enough for the trust decision.
That distinction matters because the certificate is designed to reinforce a proven brand identity, not to rescue an unauthenticated or poorly aligned message. A logo shown without those checks would create exactly the wrong outcome: a visual trust cue without the message-level evidence that justifies it. The control only works when the underlying authentication is already behaving correctly.
This is also why email programmes often treat BIMI as a maturity layer after SPF, DKIM and DMARC are stable. If the authentication posture is inconsistent, the user-visible brand mark can become misleading at best and an abuse opportunity at worst, because recipients may trust the logo more than the mail itself.
How to implement the trust chain correctly
Start by treating SPF and DKIM as operational controls that must be accurate and maintained, not as one-time setup tasks. Mail streams change, vendors rotate infrastructure, and legitimate senders are added or removed over time. If those records drift, BIMI may stop displaying even though the logo file and certificate are still in place.
Next, confirm that the authentication result aligns with the visible sending domain and that DMARC policy enforcement is stable enough to support consistent brand display. If the organisation sends from multiple platforms, the practical question is whether each platform can preserve valid SPF or DKIM alignment without creating exceptions that weaken the trust model.
For the certificate itself, the key decision is whether the organisation can maintain the identity claim behind the mark over time. CA/Browser Forum requirements exist precisely because certificate trust depends on issuance and lifecycle discipline, not just possession of a file. For the lifecycle side of the problem, NIST SP 800-57 Key Management is useful for thinking about key protection, rotation and cryptoperiod management when certificate-backed trust is part of the mail stack.
Risk and Threat Considerations
Brand marks increase perceived legitimacy, so the security risk is strongest when they are shown without strong message authentication behind them. Attackers benefit from any visual cue that reduces user scrutiny, especially in phishing and business email compromise scenarios where the goal is to look like a trusted sender rather than to defeat a technical control outright.
Failure mechanism: An organisation may deploy the mark certificate while leaving SPF, DKIM or alignment gaps unresolved, which means the visual brand indicator can outpace the actual authentication state.
Impact: Users may trust a message that has not been properly authenticated, and the organisation may create a stronger-looking brand surface without the underlying controls that make that surface defensible.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Covers lifecycle management for authentication material behind email trust. |
| SC-12 — Cryptographic Key Establishment and Management | Applies to DKIM-style signing keys and certificate-backed trust. | |
| Recommendation — Manage email-authentication keys and secrets with rotation, revocation, and lifecycle controls. Protect signing keys and enforce renewal and replacement before expiry. | ||
| CIS Controls v8 | CIS-5 — Account Management | Supports maintaining authorised sending systems and removing stale mail paths. |
| Recommendation — Inventory and disable obsolete sender accounts and email systems. | ||
Practitioner Guidance
What to verify: Verify that every legitimate sending path passes SPF or DKIM in a way that aligns with the visible From domain, and confirm that this remains true after vendor changes, mail routing changes or domain migrations. If you cannot explain why a given mail flow is authenticated, it is not ready for BIMI.
What good looks like: The organisation has stable authentication for all branded outbound mail, the BIMI logo displays only when those conditions are met, and exceptions are rare enough to be investigated rather than normalised. That is the point where the certificate adds value instead of masking inconsistency.
Practitioner takeaway: Treat the mark certificate as the last step in the chain, not the control that creates trust. If SPF and DKIM are not consistently working and aligned, BIMI becomes a branding layer without a reliable security foundation.
Related resources from NHI Mgmt Group
- Why do ephemeral credentials still leave risk in machine access models?
- Why do SPF, DKIM, and DMARC all matter for enterprise email security?
- Why do SPF, DKIM, and DMARC still fail in well-managed environments?
- Why do role-based controls still matter when an application already uses passwordless sign-in and OAuth or OIDC?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org