BIMI DMARC Quarantine PCT 100 Requirement Explained
Understand the BIMI DMARC quarantine PCT 100 requirement and how to meet it. Test your domain’s alignment and deliverability with real-world verification.
What does the BIMI DMARC quarantine PCT 100 requirement actually mean?
You send a transactional email. It lands in the spam folder. Not because of content, but because your domain’s DMARC policy isn’t enforcing 100% alignment. That’s the cost of falling short on the BIMI DMARC quarantine PCT 100 requirement.
BIMI isn’t just a logo in the inbox. It’s proof your brand is authenticated at scale. And to qualify, email providers like Google and Yahoo don’t just check records — they enforce a hard rule: 100% of messages must pass DMARC alignment or they get quarantined.
This isn’t a setting you flip on. It’s a gate. If your domain sends even one email that fails alignment — even a test or a misconfigured transactional message — it can trigger quarantine for your entire sending domain, regardless of content or reputation.
Key takeaways
- The BIMI DMARC quarantine PCT 100 requirement means every email from your domain must pass DMARC alignment checks without exception.
- Even a single non-aligned email can cause all messages from your domain to be quarantined by Google and Yahoo.
- BIMI is not a branding feature — it’s a deliverability gate with strict, non-negotiable compliance requirements.
Why is BIMI DMARC quarantine PCT 100 required for brand visibility?
DMARC’s PCT 100 requirement ensures only senders with full authentication compliance—even in the face of a single failed message—can display their brand logo via BIMI. Without a 100% alignment, email providers quarantine the entire domain, preventing any BIMI logo from appearing, regardless of how well-configured other parts of the system are. This rule blocks spammers and rogue senders from exploiting BIMI visibility, even if they pass other checks.
Making BIMI Visible Means Full Compliance
Let’s be clear: even if your SPF, DKIM, and DMARC policies are set up correctly, a single message that fails authentication can trigger a full BIMI quarantine if your PCT isn’t set to 100. Email providers enforce this strictly because BIMI is a trust signal. If a sender doesn’t control all outbound traffic perfectly, they aren’t trustworthy enough to represent a brand visually.
For example, a third-party vendor sending on your behalf with a misaligned header can trigger DMARC failure. If your policy is PCT 90, that one failure is allowed. But that’s enough to trigger a quarantine that blocks BIMI across the whole domain. You can’t have a partial logo. Either you’re fully compliant or you’re not visible at all.
Preventing Spoofing Through Mandatory Alignment
The 100% requirement isn’t arbitrary—it’s designed to prevent spoofing. A single misconfigured or compromised email stream could otherwise hijack brand recognition if BIMI were allowed with lower thresholds. By requiring complete alignment, providers ensure that only senders who consistently authenticate every message can gain logo visibility.
Industry standards back this up. The DMARC standard (RFC 7483) defines quarantine policies as a way to isolate unauthenticated sources. Providers like Google, Yahoo, and Microsoft apply this rule when enforcing BIMI. You can verify your DMARC policy and alignment with real email testing: test inbox placement and verify your entire list to catch misconfigurations before they impact visibility.
Think of it this way: BIMI is a premium feature. You don’t get access to it unless you prove you can maintain consistency at every step. That’s why PCT 100 isn’t a hurdle—it’s a gatekeeper. Without it, your brand loses visibility, no matter how strong your email program appears on paper.
How is the PCT 100 compliance measured across major email providers?
Major email providers like Google and Yahoo measure PCT 100 compliance by tracking the percentage of a domain’s outbound messages that pass DMARC alignment—meaning either SPF or DKIM checks pass—over time. Even a single misaligned message in a high-volume sending stream can push the overall rate below 100%, triggering quarantine for future messages. This metric isn’t fixed; it evolves with ongoing sending behavior and sender reputation, making consistent alignment critical.
Real-world behavior over time
Let’s say you send 100,000 emails in a day. If 99,999 pass DMARC alignment and only one doesn’t, that’s 99.999%—which is technically below 100%. The system doesn’t wait for perfection across every single message. Instead, it evaluates alignment trends over a rolling window, often days or weeks. So even brief lapses—due to a misconfigured campaign send or an unauthorized third-party tool—can impact the score.
That’s why consistency matters more than perfection. The system tracks alignment not just per message but over time, weighing recent patterns against historical behavior. As a result, a brief dip in alignment can trigger quarantine even if your overall infrastructure is sound. The same goes for sudden spikes in volume or changes in sending domains without proper alignment.
Google’s published guidance on DMARC enforcement underscores that alignment isn’t a one-time check—it’s a continuous validation. You can see the broader context in the Google DMARC guide, which notes alignment is evaluated based on real-world email traffic patterns, not static rules. Yahoo similarly uses inbound traffic analysis to assess compliance, adjusting quarantine status as alignment trends shift.
Even if you’re confident in your SPF and DKIM setup, misalignment can happen in practice—especially when using third-party tools, templates, or embedded links that don’t preserve sender identity. That’s where consistent verification helps. Use tools like MailTester’s bulk verification to test your send lists before deployment, or inbox placement testing to check deliverability before scaling. The goal isn’t just to avoid bounces—it’s to maintain that 100% alignment score over time.
What are the prerequisites for a BIMI policy with PCT 100 compliance?
You must have a fully aligned DMARC policy set to p=quarantine or p=reject, with valid SPF and DKIM signatures using domain-aligned selectors. All emails must pass either SPF or DKIM alignment and match the From: domain. Your domain must not have triggered spam traps or sustained high bounce rates in the last 30 days. A reporting mechanism (rua/ruf) is required. BIMI with PCT 100 also demands that your email infrastructure is stable and reputationally clean. If any of these elements are missing or misconfigured, BIMI enforcement will fail.
Core technical foundations
- Ensure your SPF record includes every authorized sending source—no gaps, no missing IPs or domains.
- Use a DKIM selector that aligns with your sending domain; ensure the private key is signed and the public key is published in DNS.
- Set your DMARC policy to
p=quarantineorp=reject—p=noneblocks PCT 100 compliance. - Include at least one
ruaaddress (for aggregate reports) and onerufaddress (for forensic reports) in your DMARC record.
Alignment and reputation checks
- Every email must pass SPF or DKIM authentication and align with the From: domain (i.e., the “from” address must match the domain in SPF or DKIM).
- Review your recent sending history: avoid high bounce rates—more than 2% in 30 days typically breaks compliance.
- Check for spam trap hits. If you’ve triggered any, your domain may be flagged—even one hit can trigger rejection under strict BIMI policies.
- Use a real-time verification tool to test your sending domains and catch invalid or risky addresses before they harm your reputation.
For teams managing multiple domains or high-volume sends, tools like the MailTester bulk verification service can help identify and remove problematic addresses before deployment. The Email API allows for real-time address validation during registration or onboarding, reducing the risk of sending to invalid or risky domains. These checks help maintain a clean sender reputation, which is essential for PCT 100.
For deeper validation, inbox placement testing simulates real-world delivery across major providers. While BIMI PCT 100 is a technical and policy-based requirement, inbox placement and engagement are part of the broader ecosystem that supports it. Refer to the DMARC specification and DMARC.org for authoritative guidance on policy formatting and alignment standards.
How can you verify whether your domain meets the PCT 100 threshold?
You can verify your domain meets the PCT 100 threshold by checking your DMARC policy enforcement, analyzing aggregate reports for alignment, monitoring sender reputation and engagement, and testing inbox placement in real-world conditions. No single tool gives the full picture—you need a layered approach across configuration, reporting, and delivery testing.
- Validate your DMARC record syntax and policy using public tools. Enter your domain into MxToolbox or Spamhaus to check for correct SPF alignment, DKIM signing, and whether your policy is set to
rejectorquarantine. A misconfigured record may showp=noneor missing DNS entries, which prevents enforcement. - Aggregate DMARC reports regularly via a monitoring service. Use platforms like PowerDMARC or Dmarcian to collect and analyze daily or weekly reports. These show how many messages are aligned vs. unaligned, and whether your domain is being spoofed or used in phishing attempts. Consistently high alignment (95%+) is a strong indicator of readiness for PCT 100.
- Check inbox placement and engagement metrics monthly. High open and click rates matter—but so does sending volume consistency. Sudden spikes or drops can trigger automated filters. Tools like MailTester’s inbox placement tester simulate real user inboxes and confirm your messages land in primary folders.
- Test message delivery in a sandboxed environment. Before sending bulk mail, run a test with real messages through a domain-specific inbox placement service. This confirms whether your domain is trusted by providers like Gmail, Outlook, or Yahoo. If messages land in spam or are quarantined, your sender reputation may still be under review.
Why PCT 100 isn’t just a number
Even if your DMARC reports show 100% alignment, that doesn’t guarantee inbox delivery. Some domains enforce PCT 100 but still flag messages based on historical spam patterns or low engagement. A domain with low open rates—even if technically compliant—can still face quarantine.
How to act when you’re close but not at 100%
If reports show 97%, don’t panic—this is common in large organizations. Focus on identifying the root cause: is it misaligned SPF? Missing DKIM? Or low engagement from older or invalid addresses? Clean your list using a service like MailTester’s bulk verification to remove risky or non-existent addresses before sending.
DMARC enforcement is only as strong as your alignment and sender behavior. Syntax alone does not guarantee inbox placement.
Can you use BIMI without PCT 100 compliance?
No — email providers will not display your BIMI logo unless your domain has PCT 100 alignment across all authenticated messages. Even if you publish a BIMI record, it’s ignored if DMARC alignment fails at the sender or return-path level. This is by design: PCT 100 ensures only legitimate, fully aligned senders can use brand logos in inboxes, preventing abuse.
Why PCT 100 is non-negotiable for BIMI
Let’s be clear: BIMI isn’t a branding feature you can skip the rules for. It’s a trust signal. If your DMARC policy is set to 'p=none' or 'p=quarantine', providers will not display your logo — even if the BIMI record is present. This is because a BIMI icon could otherwise be used to impersonate a brand that doesn’t fully control its email stream.
DMARC alignment requires both SPF and DKIM to pass successfully for each message. If one or both fail, even with a valid BIMI tag, the provider treats the alignment check as negative. The result? The logo is not rendered. And even if you publish BIMI, providers like Gmail, Yahoo, and Outlook will skip it unless PCT 100 is confirmed.
How PCT 100 safeguards email integrity
This isn't arbitrary. It's a core part of the security model behind BIMI. The goal is to prevent spoofing, brand impersonation, and phishing attacks that rely on trusted-looking logos. As described in RFC 8714 (the BIMI specification), providers use PCT 100 as a gatekeeper — a way to validate that your organization is both authenticated and consistently compliant.
Even if you’ve implemented BIMI, a single misaligned email or failed DKIM signature can break the chain. This is why ongoing monitoring is essential. Tools that verify your DMARC and BIMI records in real time — like inbox placement testers — help ensure your branding is both visible and secure.
If you’re setting up BIMI, don’t assume it will appear until you’ve confirmed: 1) SPF and DKIM are properly configured, 2) DMARC is published with a policy of 'p=reject' or 'p=quarantine', and 3) all messages pass alignment checks at scale. Only then will providers consider displaying your logo. Without PCT 100, your BIMI logo remains invisible — by design.
For teams managing high-volume sends, checking alignment and deliverability before sending is critical. You can run a full verification of your domain’s authentication setup using bulk verification, or test individual messages via the email verification API.
How does BIMI PCT 100 relate to sender reputation and deliverability?
Passing BIMI PCT 100 means your domain’s authentication alignment is consistent across every send, signaling strong infrastructure and sender hygiene. This consistency correlates directly with high deliverability and trusted sender reputation—domains that repeatedly fail alignment often have poor list management or weak technical setup, which email providers penalize over time.
PCT 100 as a hygiene signal
Let’s be clear: a BIMI PCT 100 isn’t a magic badge. It’s a measurable proxy for how well you’re maintaining your email infrastructure. When every message from your domain aligns properly with SPF, DKIM, and DMARC, you’re not just complying—you’re demonstrating operational discipline. This kind of consistency is a known signal to inbox providers, and it’s one of the few metrics that shows up in some provider-level reputation scoring, like those used by Google and Microsoft.
Repeated alignment failures, especially with DMARC, raise flags. A domain that occasionally fails alignment might be a one-off issue, but consistent misses indicate unreliable sending practices—possibly outdated infrastructure, poor list hygiene, or compromised accounts. Such patterns are commonly detected by filtering engines and often lead to gradual downgrades in inbox placement, even if you're not explicitly blocked.
How PCT 100 connects to real engagement metrics
High PCT 100 scores don’t exist in isolation. They tend to align with strong performance across deliverability indicators: low bounce rates, low complaint rates, high engagement, and consistent inbox placement. The reason? Email providers reward consistent, well-formed messages that land in inboxes and get opened. If your PCT is low, you’re likely sending to addresses that are invalid, unengaged, or outright ignored—not a good signal to receivers.
RFC 7624 (which defines BIMI) doesn’t require PCT 100, but real-world adoption by providers like Gmail has made it de facto a benchmark for trusted senders. You don't need PCT 100 to send—just to be seen as credible at scale. And unlike some metrics, PCT 100 is based on real email behavior, not just data feeds.
For brands aiming to verify their authentication health and test how their messages perform in real inboxes, tools like MailTester’s inbox placement tester can simulate how your emails are received across provider inboxes, including PCT behavior and BIMI rendering. It’s one way to spot hidden alignment issues before they impact deliverability.
What happens to messages if your domain fails PCT 100?
If your domain fails the PCT 100 requirement in DMARC, email providers may quarantine or mark your messages as spam—even if they pass SPF and DKIM. Without PCT 100, you lose trust signals that gate inbox placement. BIMI won’t display, and your sender reputation begins to erode over time. Check your DMARC policy at RFC 7483.
How providers react when PCT 100 isn't met
- Messages may be marked as spam by providers like Gmail, Outlook, or Yahoo—each applies their own quarantine rules based on aggregate sender behavior, not just DMARC.
- Even if delivery succeeds, BIMI icons won’t appear in recipient inboxes because BIMI relies on a fully compliant DMARC policy with PCT 100.
- Reputational damage compounds over time: repeated failures reduce sender reputation scores, leading to lower inbox placement rates, especially across large platforms like Microsoft or Apple.
- Some providers enforce a hard drop when PCT 100 is missing, especially for high-volume senders or domains with a history of abuse.
Long-term consequences of failing PCT 100
- Subscribers may begin to view your emails as less trustworthy, increasing unsubscriptions and spam complaints—both directly hurt deliverability.
- Future campaigns suffer: senders who don’t meet PCT 100 often see their message volume throttled over time, even with compliant technical settings.
- Rebuilding trust takes time. A single DMARC policy change that fixes PCT 100 doesn’t instantly repair reputation—historical sending patterns matter.
- Providers use aggregate data across domains to assess risk. Without PCT 100, your domain is treated as unproven, even if your individual emails are technically valid.
Let’s be clear: PCT 100 isn’t optional if you want full inbox access and BIMI. You’re essentially saying “we’re not taking email security seriously” to providers.
DMARC is only effective when implemented with strict policy enforcement—even partial compliance undermines the system. DMARC.org
Use inbox placement testing to simulate real-world delivery across top providers. Or, bulk-verify your email list with MailTester's list verification before sending campaigns to avoid sending to invalid or risky addresses. Your deliverability depends on both sender policy and list hygiene.
How can MailTester help validate your BIMI DMARC requirements?
You need 100% alignment between BIMI and DMARC to avoid quarantine, and MailTester helps you enforce it. Check individual emails in real time, verify entire lists for validity and alignment, test inbox placement before launch, and integrate directly into your senders (Mailchimp, SendGrid, HubSpot) to catch issues before they reach the inbox. This stops DMARC failures at the source.
Validate alignment before every send
- Use the real-time API to verify each email’s SPF, DKIM, and DMARC alignment before sending. Only send to addresses where all three protocols match your domain.
- Check whether the BIMI record is correctly published and linked to your DMARC policy, and whether the domain in the BIMI tag aligns with your sender domain. Misalignment causes BIMI to fail, which can trigger quarantine.
- Many BIMI issues stem from inconsistent sender domains or broken DNS records. MailTester flags these as "invalid" or "risky" so you avoid sending to addresses where BIMI cannot display.
Prevent DMARC failures at scale
- Run bulk list verification via MailTester’s bulk tool to catch invalid, catch-all, or role-based addresses that can break DMARC alignment or trigger quarantine.
- Test inbox placement across Gmail, Yahoo, Outlook, and other major providers with MailTester’s inbox placement tester during campaign build. You’ll see early signals of quarantine or foldering before live sends.
- Integrate with Mailchimp, SendGrid, or HubSpot to enforce clean addresses and alignment rules upstream. The integration automatically rejects or flags problematic emails before they’re sent.
- DMARC policies with quarantine or reject enforcement demand strict alignment. Even a single misaligned address in a large campaign can trigger a bulk quarantine. Catching it early is the only way to meet the 100% requirement.
DMARC alignment is not optional if you're using BIMI. The email ecosystem treats misalignment as a failure point, leading to quarantine or delivery disruption.
For reference, DMARC’s alignment requirements are defined in RFC 7489, which clarifies that both SPF and DKIM must align with the domain in the From header. The DMARC.org site offers guidance on enforcement, but the only way to enforce it consistently is through automation and real-time validation.
By combining real-time checks, bulk verification, inbox testing, and pre-send integration, MailTester turns BIMI and DMARC compliance from a manual process into a reliable, repeatable workflow. You’re not guessing — you’re verifying.
What are common missteps in achieving PCT 100 compliance?
You often fail PCT 100 compliance not because of technical flaws, but because of overlooked details: misaligned SPF policies, shared DKIM keys across subdomains, stale or bouncing emails in your list, and unvalidated content or links. These issues create alignment gaps or trigger reputation spikes that DMARC quarantines. Let’s break down the real problems teams face.
SPF alignment and key management pitfalls
- Over-allowing SPF mechanisms like
includeorallwithout ensuring the sender domain matches the header From domain. This breaks SPF alignment, a core requirement for PCT 100. The SPF specification (RFC 7208) requires explicit, honest alignment; blanket includes dilute this. - Using a single DKIM key for all subdomains fails to enforce domain-specific signing. DMARC checks alignment per subdomain. A mismatch here results in failure even with valid signatures. Use per-domain keys or properly signed subdomain records.
List hygiene and content validation
- Failing to monitor and clean out stale or bouncing addresses leads to low engagement, high bounce rates, and damaged sender reputation. MailTester’s bulk verification helps identify invalid or risky addresses before sending: verify your list.
- Not checking message content or link integrity can trigger DMARC quarantines. Misleading content, broken links, or unexpected redirects increase the risk of being flagged as suspicious. Even if your DNS setup is perfect, poor content behavior undermines trust.
DMARC’s “PCT 100” requirement isn’t just about DNS records—it’s about consistent, aligned behavior across every step of email delivery. A single misaligned subdomain, an outdated email address, or an unverified link can trigger a quarantine.
“Consistent alignment and strong list hygiene are the foundation of DMARC success.” — Sender Policy Framework documentation, RFC 7208
How do you maintain PCT 100 compliance over time?
Compliance is not a one-time setup. It requires consistent, automated checks after every change to your sending infrastructure.
Automate alignment testing
Run automated domain alignment tests immediately after new deployments, DNS updates, or changes to email templates. Manual checks are too slow and error-prone.
Hygiene and monitoring
Perform monthly list hygiene using trusted verification tools like MailTester to catch degrading addresses before they cause issues. Monitor DMARC reports monthly to detect alignment drops early.
Proactive adjustments and analysis
When reports show alignment failures, update SPF or DKIM records before delivery rates decline. Use MailTester’s in-app AI assistant to parse complex report anomalies and receive targeted repair suggestions.
Sources
- DMARC adoption among top domains surged 75% between 2023 and 2025 — from 27.2% to 47.7% — in the wake of Google and Yahoo's bulk-sender authentication requirements. — EasyDMARC 2025 DMARC Adoption Report (2025)
- Since May 5, 2025, Microsoft Outlook requires SPF, DKIM, and DMARC from domains sending 5,000+ emails per day, rejecting non-compliant mail outright at the SMTP level with error 550 5.7.515. — Microsoft Outlook requirements (via MailOver bulk-sender requirements guide) (2025)
Keep reading
- Email authentication: SPF, DKIM, DMARC, BIMI and MTA-STS (complete guide)
- Verifying DMARC rua External Domain Records with _report._dmarc
- DKIM ed25519 Keys Support Status 2026: What You Need to Know
- PTR Record Does Not Match HELO Hostname Rejection 2026
- BIMI Without a Registered Trademark: What You Can Do in 2026
Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.
Frequently asked questions
What happens if my domain’s PCT drops below 100?
Your messages may be delivered to spam or quarantined by providers like Google or Yahoo, and BIMI will be disabled.
Does BIMI work with all email providers?
Only providers that support BIMI, such as Gmail and Yahoo, will display the logo—regardless of PCT 100 alignment.
How long does it take to achieve PCT 100 after fixing authentication issues?
It can take 3–7 days for providers to recalculate the percentage based on new message patterns.
Can a single bad message break PCT 100 compliance?
Yes—any misaligned message sent from your domain can temporarily drop the PCT percentage below 100.
Is PCT 100 required for DMARC policy to work?
No—but for BIMI, PCT 100 is mandatory to avoid quarantine and ensure logo display.
What should I check if BIMI isn’t appearing in Gmail?
Verify your DMARC policy, correct DKIM/SPF alignment, and confirm that your domain is in the BIMI registry with valid logo data.
How accurate is MailTester’s verification for DMARC alignment?
MailTester’s accuracy is 98.9% across email verification, including detection of misconfigured senders and invalid addresses.
Can I test BIMI compliance without sending real emails?
Yes—use MailTester’s inbox placement testing to simulate delivery and observe how providers treat your domain.
Do role accounts affect PCT 100 compliance?
Role accounts like admin@ or support@ don’t directly affect PCT scores—but they can increase bounce or spam rates if misused.
What is the role of list hygiene in maintaining PCT 100?
Dirty lists increase bounce rates and spam complaints, which hurt sender reputation and make PCT 100 harder to maintain.
Can I use MailTester’s free credits to test BIMI domains?
Yes—100 free verifications are available to start, with no expiring credits for paid plans.
Does BIMI require HTTPS for the logo URL?
Yes—a valid HTTPS URL is required to serve the BIMI logo, and the domain must be verified and publicly accessible.