DMARC pct=100: the tag that silently kills BIMI
Set pct=100 on your DMARC record, or the logo never renders and nothing tells you why
The threat
Your DMARCDMARCEmail authDomain-based Message Authentication: a DNS policy telling receivers what to do with mail that fails SPF or DKIM, and which emails you a report of everyone spoofing you. record is valid. Every checker on the internet gives it a green tick. Your mail is enforcing, SPF and DKIM pass, your logo is on your web host in the right format at the right URL, and your logo still never appears next to your name in a single inbox. No bounce, no warning, no error line anywhere. The aggregate reports arriving at your rua= address say nothing about it, because as far as DMARC is concerned nothing is wrong.
The mechanism is one tag: pctpct=DMARC policyA DMARC setting that applies your policy to only a share of your mail while you test, for example nine messages in ten. Anything below 100 quietly disqualifies you from BIMI even though every DMARC checker still calls the record valid.. BIMIBIMIEmail authBrand Indicators for Message Identification: a DNS record that tells email apps to show your logo beside your messages in the inbox. It only takes effect once DMARC is set to quarantine or reject, so the logo doubles as visible proof your email security is switched on. evaluators require pct=100pct=DMARC policyA DMARC setting that applies your policy to only a share of your mail while you test, for example nine messages in ten. Anything below 100 quietly disqualifies you from BIMI even though every DMARC checker still calls the record valid. exactly, or the tag absent (100 is the default). At pct=90, receivers apply your policy to 90 percent of failing mail and let the rest through, so the domain is not fully enforcing, so BIMI refuses it. v=DMARC1; p=reject; pct=90 is a strong DMARC record and a dead BIMI domain. That one digit floors you at BIMI T0 blocked no matter how perfect the rest of the chain is.
The exact fix
Edit your single _dmarc TXT record so pctpct=DMARC policyA DMARC setting that applies your policy to only a share of your mail while you test, for example nine messages in ten. Anything below 100 quietly disqualifies you from BIMI even though every DMARC checker still calls the record valid. reads 100, or remove the tag entirely. Both are correct. Explicit is easier to audit later.
| Field | Value |
|---|---|
| Type | TXT |
| Name | _dmarc (→ _dmarc.yourdomain.com, not @) |
| Value | v=DMARC1; p=reject; rua=mailto:dmarc@yourdomain.com; fo=1; pct=100 |
| TTL | 3600 |
Keep p=quarantinep=quarantineDMARC policyDMARC policy that sends failing (likely spoofed) mail to the spam folder instead of the inbox. if that is where you are today, quarantine and reject both satisfy BIMI. Only the pctpct=DMARC policyA DMARC setting that applies your policy to only a share of your mail while you test, for example nine messages in ten. Anything below 100 quietly disqualifies you from BIMI even though every DMARC checker still calls the record valid. value changes. Edit the record in place, never publish a second _dmarc record, receivers treat two as none. The full policy ladder is in DMARC.
pctpct=DMARC policyA DMARC setting that applies your policy to only a share of your mail while you test, for example nine messages in ten. Anything below 100 quietly disqualifies you from BIMI even though every DMARC checker still calls the record valid. was never a BIMI dial, and that is the trap. It is a DMARC rollout throttle, so operators set it to 10, then 50, then 90, then move to the next task. Nothing in DMARC penalizes stopping at 90. BIMI does, silently, forever.
Verify it
dig +short TXT _dmarc.yourdomain.com
Exactly one record comes back, and it either ends in pct=100pct=DMARC policyA DMARC setting that applies your policy to only a share of your mail while you test, for example nine messages in ten. Anything below 100 quietly disqualifies you from BIMI even though every DMARC checker still calls the record valid. or contains no pct=pct=DMARC policyA DMARC setting that applies your policy to only a share of your mail while you test, for example nine messages in ten. Anything below 100 quietly disqualifies you from BIMI even though every DMARC checker still calls the record valid. at all. Any other number is your entire BIMI failure, in one token.
Proof
dev3lop.com publishes v=DMARC1; p=quarantine; rua=mailto:dmarc@dev3lop.com; fo=1; pct=100, and a live scan today grades it A at score 100. That one digit is what let it climb. default._bimidefault._bimiEmail authThe exact DNS name a BIMI record has to live at, written as default._bimi.yourdomain.com. Publish the same text anywhere else and email apps will never find it. now serves v=BIMI1;l=https://dev3lop.com/bimi/dev3lop-mark.svg, and the asset answers HTTP 200 as image/svg+xml, 15,472 bytes, zero redirect hops, tiny-psbaseProfile="tiny-ps"BIMI assetA line inside the logo file declaring that it follows the strict BIMI image rules. Email apps and certificate issuers look for it, and a file without it is treated as the wrong format even when it looks identical. at 400x400 with <title> as the first child. It is live at BIMI T3, self-asserted, rendering in Yahoo, AOL and Apple Mail. Gmail withholds it until a certificate exists, and the mark’s archive clock started 2026-05-04, so a CMCCMCTLS / PKICommon Mark Certificate: the cheaper certificate for businesses with no registered trademark, granted once the issuer confirms you have used the same logo publicly for at least twelve months. Apple Mail accepts it, Gmail still asks for the full trademark version. is not purchasable until May 2027. A domain one digit off, at pct=90, sits at BIMI T0 blocked and never starts.