
Trust.ID Talk · 2026-06-04 · 15 min
Key moments - from our scoring
Substance score
31 / 100
Five dimensions, 20 points each
Email authentication protocols - SPF, DKIM, and DMARC - have evolved from best practices to mandatory requirements imposed by major mailbox providers like Google, Microsoft, and Yahoo. Brian Westnedge from Redshift (GlobalSign) explains why these acronym-heavy standards matter more than ever as AI-powered phishing attacks become increasingly sophisticated. SPF authenticates the sender, DKIM cryptographically signs messages to prove they haven't been altered in transit, and DMARC layers reporting on top of both. Once DMARC enforcement is achieved, organizations become eligible for BIMI (Brand Indicators for Message Identification) - a visual trust indicator displaying company logos and verified checkmarks next to sender addresses. The conversation covers two certificate types: verified mark certificates (VMCs) requiring registered trademarks, and common mark certificates (CMCs) for organizations using logos informally. This applies to everyone from Fortune 500 companies to small businesses, universities, and government agencies. Looking ahead, Westnedge predicts DKIM2 and DMARC 2.0 will emerge, Microsoft will eventually adopt BIMI support, and email will remain the primary attack vector since it's how most people authenticate into critical accounts across banking, SaaS, and corporate systems.
SPF (Sender Policy Framework) authenticates that mail is coming from legitimate sources; DKIM (DomainKeys Identified Mail) cryptographically signs messages to prove they haven't been altered in transit; and DMARC is the modern protocol that leverages both SPF and DKIM while adding a reporting layer. Once DMARC is implemented at enforcement level, organizations qualify for BIMI.
VMCs require organizations to have a registered trademark for the logo displayed in emails, while CMCs are available for organizations that can prove they've used a logo on their website for the past year without a registered trademark. Both enable the logo display and verified checkmark next to the FROM address in supported email clients like Gmail.
Google, Microsoft, Yahoo, and other major mailbox providers implemented these requirements to ensure legitimate email reaches inboxes, prevent domain spoofing, and combat increasingly sophisticated phishing attacks powered by AI that can now create well-crafted, grammatically correct fraudulent messages.
All organizations that send email need to implement these protocols, including small businesses, educational institutions, state and local government, and any other entity that wants legitimate email delivered to inboxes. The common mark certificate option makes BIMI accessible to organizations of any size.
DMARC implementation must come first as the foundation; once DMARC enforcement is achieved, organizations then qualify for BIMI with either a VMC or CMC to display logos and verified indicators in supported mailbox providers.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode is largely introductory - defining SPF, DKIM, DMARC, and BIMI for a lay audience - with only a handful of mildly substantive points such as the CMC/VMC distinction and the upcoming DKIM2 and DMARC 2.0 protocols. A B2B operator with any prior exposure to email security would learn little here.
There's a new version of DKIM coming out called DKIM2 which offers some enhancements over the existing DKIM protocol. There's a new uh, version of DMARC coming on. We're still on version 1.0
email authentication has always been a best practice as long as that's been around. But it was never a formal requirement until a couple years ago
The episode recycles standard cybersecurity talking points without any contrarian or first-principles framing. The 'attackers only have to be right once' line is one of the most overused phrases in all of security commentary, and the social-media verified-tick analogy for BIMI is a well-worn explanatory device in the space.
The attackers only have to be right once. Defenders have to be right right all the time
it's always an arms race. Attackers try new tactics, defenders try to keep up with those
Brian Westnedge is a genuine practitioner in the email authentication space and demonstrates working knowledge of the protocols, but the episode functions essentially as a GlobalSign/Redshift vendor promotional conversation rather than an independent expert interview, which limits the candour and depth of the perspective offered.
for us in the space that GlobalSign Reds have worked in, that's uh, email authentication, specifically SPF, DKIM and DMARC protocols
obtaining the common mark certificate from GlobalSign is a fairly straightforward process as well
The guest names a handful of real mailbox providers and references upcoming protocol versions, but there are zero metrics, adoption figures, breach statistics, timelines, or dollar figures anywhere in the episode. 'Educational institutions, universities, state and local government' as examples of implementers is vague to the point of being meaningless.
big mailbox providers like Google, Microsoft and Yahoo all came out with sender requirements for domain owners
The elephant in the room is Microsoft. So we expect Microsoft to adopt bimi. They have not yet
The host asks almost exclusively definitional 'can you explain X?' questions with no follow-up pressure, no numerical challenges, and no attempt to probe edge cases or push back on vendor framing. The episode closes with an off-topic 'favourite tech' question that actively wastes time.
So maybe if we just take a little kind of step back for a second and kind of just have a little talk about some of the elements of kind of DMARC encryption
what one piece of tech could you not live without and don't see email?
Computed from the transcript - who did the talking, and the words that came up most.
Got a question? Send us an email at trust.idtalk@globalsign.com In this episode of Trust.ID Talk: The Digital Certificate and Identity Security Podcast, host Steve Hall is joined by Brian Westnedge, VP of Alliances & Partnerships at Red Sift, to unpack the fundamentals of email authentication, from SPF, DKIM, and DMARC to the visual trust indicators offered by BIMI, VMCs, and CMCs. What You’ll Learn: How to implement the email authentication stack Why DMARC enforcement is your gateway to brand protection and inbox placement The difference between Verified Mark Certificates (VMCs) and Common Mark Certificates (CMCs) How BIMI and visual trust indicators combat AI-generated phishing Why email remains the primary attack vector despite being decades old Brian Westnedge is an email security expert and VP of Alliances & Partnerships at Red Sift, specializing in email authentication protocols and domain security. With extensive knowledge of SPF, DKIM, DMARC, and BIMI implementations, Brian brings practical expertise in helping organizations of all sizes strengthen their email security posture.
Transcribed and scored by The B2B Podcast Index.
Speaker A: It's always an arms race. Everything is evolving, it feels like at a very rapid pace right now.
Speaker B: Email may appear to be seen as a click form of communication, but let's face facts, it still represents the number one form of communication between organizations and customers. And it's vital that given the proper respect as a security threat, with the rapidly increased use of AI and the complexity of attack methods and frequency of the last 12 months, it's become essential for both organizations and end users to not only be vigilant, but structured and organized in how they protect themselves. You're listening to Trusted Talk and I'm your host, Steve Hall. To help us unravel growing complexities around email trends and requirements, we're joined today by Brian Westage from Redshift. Welcome Brian.
Speaker A: Thanks Steve. Great to be with you.
Speaker B: So email has uh, consistently remained one of the biggest threat vectors for businesses and yet when it comes to the wider strategy, it's still tagged on the end as kind of an afterthought when it could actually become a built in advantage now. So what are the basics that organizations are missing from when it comes to
Speaker A: email and communication security? Sometimes email gets taken for granted because it's been around for so long and it's become embedded in our work lives. And I think a lot of times people think, well, somebody in my organization must be looking after our email program. Email is not the bright shiny toy like potentially social media and other forms of communication. But the reality is a lot of companies are missing some of the basics for us in the space that GlobalSign Reds have worked in, that's uh, email authentication, specifically SPF, DKIM and DMARC protocols, which I realize are heavy acronyms, but very important in today's world not only to stop spoofing and some malicious uses of your domain, but also to ensure your legitimate m email gets delivered to the inbox.
Speaker B: So I mean, you just reeled off a whole bunch of acronyms there. Now I know what they are, but uh, most of our listeners probably don't. So maybe if we just take a little kind of step back for a second and kind of just have a little talk about some of the elements of kind of DMARC encryption. You have an SPF for example, and then maybe a little bit about bimi.
Speaker A: Absolutely. So email was not designed with security in mind. So in today's world, we're essentially bolting on email authentication security to a protocol that's been around for decades. So the first email authentication protocol, the idea being authenticate your legitimate email to prove in some way to a recipient that the mail is genuine. SPF or Sender Policy framework that's been around couple of decades now, uh, it was followed by dkim or dkim domain keys identified mail. That's a way for the sender of the message to cryptographically sign the message to prove to the recipient that it hasn't been altered in transit. And then finally DMARC is the modern email authentication protocol, leveraging SPF and dkim, adding a reporting layer. And then the good news for our viewers is once you implement DMARC at enforcement, you're eligible for something called BIMI or Brimming Brand Indicators for message Identification. So I like to think of it as the cherry on top or the top of the pyramid of the email authentication stack.
Speaker B: Thanks Ain. So I mean that does it all sound, I guess to third party, quite complicated. I'm guessing that obviously some large organizations will have the resources there to know kind of what to do. They're probably very familiar with that technology and how it's implemented. But what about smaller organizations? I mean, they must struggle, right, with that sort of thing.
Speaker A: I think up until a few years ago, a lot of small organizations maybe weren't as aware of protocols like DMARC and bimi. And really what we saw in the last couple years in particular is big mailbox providers like Google, Microsoft and Yahoo all came out with sender requirements for domain owners to uh, adhere to if they want to get their legitimate mail delivered to the inbox. So I would say email authentication has always been a best practice as long as that's been around. But it was never a formal requirement until a couple years ago. And now really what's happened is if you want to get your legitimate mail delivered to the inbox, you have to use spf, dkim and dmarc. And that's mandated by big mailbox providers. So even if you're a small business, those standards will apply to you. And you need to make sure that you're educated on these protocols. Again, not only prevent spoofing and illegitimate uses of your domain, but also to ensure that your marketing, mail and other business communications make it to the inbox.
Speaker B: So why are these standards kind of so crucial now? I mean, especially with the growing threats like AI, how can users reclaim that trust in their inboxes? I mean, I personally, you know, I have several emails I use for signing up for certain stuff and the number of emails that come in and it gets complicated.
Speaker A: I think we all get a lot of email, as you mentioned. Uh, we're all very busy. A lot of times we're reading our email on our mobile devices and skimming our inboxes. So you're right, a lot of us work in technology, sometimes become their family help desk for their extended relatives, especially their parents. So a lot of times I get questions from my parents saying, hey, Brian, is this a legitimate message? Because of these, uh, threat and risk factors like artificial intelligence, it's not easy to look at an email and be able to figure out, hey, is this legitimate or not? It used to be you could look at an email and there'd be misspellings or maybe a dodgy attachment or link to kind of set off your alarm bells. And the reality is, in today's world, attackers are using AI. They might be constructing very well crafted, well worded messages. Even if the language is not their native language. They can use AI to make it sound really good, look really good. And really where authentication comes in is to ensure that only legitimate mail is delivered to the inbox. And then as we're talking about BIMI adding a visual trust indicator to mail. So when you're looking at a message and you see potentially a customer, uh, company's logo next to the FROM address or a little tick box to say that the message is verified, that is kind of an indicator to the end user that this message is okay to open. So for instance, if you go and look at your personal Gmail account, you might see in your list view of messages, you might see some logos from brands that you recognize. And then if you open those messages, you may see their full logo. And again, there's a verified tick box that comes along with implementing BIMI with a verified mark certificate in that most of us are used to social verified accounts where if you're following your favorite, uh, person or organization on Instagram or Facebook or X, you'll see a little verified tick box next to their name. BIMI with a VMC is really like that for email in that right next to the FROM address there will be a little tick box. And if you hover over that, it'll say this logo and domain have been verified as belonging to the company that sent the message. So it really is a visual trust indicator.
Speaker B: And I know you just mentioned obviously VMCs, uh, or verified mark certificates. But I guess it is important to know there are kind of two kinds of certificate. So we've got verified marked certificates and the common marked certificates. Just explain any difference between those two.
Speaker A: Absolutely. So the verified mark certificate requires that the domain owner have A registered trademark for the logo that they are using in the email. And sometimes companies logos that they use informally, let's say in email communications may not be exactly the same as their trademark logo. Maybe their trademark is an image plus the name of the company. And in email communications they just use the image. So for various reasons the company may not have a registered trademark for the logo image in email. And in those cases the common mark certificate or CMC is certainly an option. As long as you can prove that you've been using that image, let's say on a website for the past year, you can obtain a common mark certificate and you will still get that logo display in Gmail clients next to the from address. So you will still give your email this trust indicator. Because all of us, regardless of whether a message is a marketing message or not, we all want the email we send to be open. And really the CMC is a nice alternative to the VMC if you do not have a registered trademark for that particular logo.
Speaker B: And I guess it's really important, isn't it when we're talking about email security and we're talking about organizations. But I guess it's really easy for people kind of listening in to think, oh, this is big companies, right? It's the Fortune 500, not just large organizations. It could be anything like a florist or acres or car garage down the road, right?
Speaker A: Absolutely. I've seen companies, let's say educational institutions, universities, state and local government organizations, small businesses, a lot of organizations you wouldn't necessarily expect to have implemented this protocol. I mean BIMI is an open standard. Anybody can publish a BIMI record in DNS. It is a fairly straightforward protocol. And then obtaining the common mark certificate from GlobalSign is a fairly straightforward process as well. So yes, all of the organizations that we either work for interact with send email. All of them want to ensure the email is delivered and opened and read and acted upon. And the CMC is really a way to make BIMI accessible to really any anybody, as you mentioned.
Speaker B: So of course the DMARC part comes first, right?
Speaker A: Absolutely, yeah. DMARC really is the foundation and the uh, requirement if you want to get that logo display. And that's really because the mailbox providers that support bimi, Google in particular, Apple in the us, Comcast globally, Yahoo really, they want domain owners to authenticate their mail with SPF, DCommand, DMARC. So that is the foundation, if you will. And once you've done that work to authenticate your legitimate mail, then you qualify for BIMI with either a VMC or a cmc. So a lot of companies and maybe folks that are in marketing roles are like, wow, VMCs and CMCs. This sounds really interesting. I want to do this. I want to stand out in the inbox and they may have less control or influence over the DMARC process and they may need to bring others in the organization into the DMARC project. Folks, you know, in IT and infrastructure and technology, people that manage the corporate mail environment, a lot of times need to get involved in the DMARC project. But also the benefit is that a fully, uh, implemented DMARC project will pay off for all of those roles. So IT and security will get the benefit of stopping exact domain impersonation once a domain is at, ah, full DMARC enforcement. And then the marketing department will get the benefit of the logo display once BIMI with a CMC or VMC is implemented.
Speaker B: Perfect, thank you. So where do you think email security is heading in over the next couple of years? And I guess on top of that, what do you think it means for the wider business strategy?
Speaker A: I don't see email volume decreasing over time. I think a lot of companies see email as a fairly inexpensive digital marketing channel relative to other expenditures. So email still, as much as my kids hate it and tell me that it's going away, it's not going away, which they will find out once they enter the working world. But I think targeted attacks will still be prevalent. The attackers only have to be right once. Defenders have to be right right all the time. Right. So I think it's always an arms race. Attackers try new tactics, defenders try to keep up with those. So we'll kind of have this arm trace always of new types of phishing and spoofing campaigns, defenders preventing those. We will see some, uh, new email authentication protocols coming along. So there's a new version of DKIM coming out called DKIM2 which offers some enhancements over the existing DKIM protocol. There's a new uh, version of DMARC coming on. We're still on version 1.0 and there's a 2 version of DMARC, if you will in the future. And then I think also on the logo display side, we'll see more providers likely adopt BIMI support and we will see the benefits of getting a VMC or a CMC increase over time as more mailbox providers adopt it. The elephant in the room is Microsoft. So we expect Microsoft to adopt bimi. They have not yet. They typically lag the email authentication space But I'm not a betting man. But I really would expect Microsoft to start supporting BIMI in the next year or two. Email still is kind of the old standby communication medium. It's the way we log into most of the accounts that we may have with any provider, your bank, obviously your social media accounts, all of your corporate, um, SaaS, uh, services you might use. Your email address is almost always, uh, the login that you use. So email is the way to get into organizations. Most organizations are doing a decent job of protecting their infrastructure. And so the attackers are going to go after the soft targets, which are people, because we're all human. And the way to get access to people is through email.
Speaker B: Absolutely. Before we uh, begin to wrap up here, we have one final question that we would like to end on. And uh, that's kind of what one piece of tech could you not live without and don't see email?
Speaker A: You know, I think. No, I think it's Apple CarPlay for me. So especially I travel a lot and I often rent cars in various locations and often outside of, uh, the US where I'm based. So Apple CarPlay and Maps, in particular your car screen. Pretty much. If a car doesn't have CarPlay these days, I feel a little bit lost. It's like not having your backup camera in your car that you get so used to, you get used to having and you really miss it when you don't have it.
Speaker B: It's funny, isn't it? Could you imagine 15 years ago being able to basically have your phone in your car and just be able to live the same life? So I get it. It's a good one. Thanks for joining us today, um, and obviously helping us kind of dive into that, you know, complex world of email, Brian. But, um, if you have a question about this topic or if there's another topic you'd like us to discuss on this podcast series, um, please leave us a comment or get in touch with us. Ah, @trust.idtalklobalsign.com thanks for listening. This has been trusted talk.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.