I was cleaning up the DNS records for hansbala.com while setting up tetris.hansbala.com. The dashboard was full of crap left behind by old hosting providers, Squarespace, Cloudflare, and Google Workspace.
DNS is one of those systems where every line looks disposable right until deleting it fucks up something important. The old web records were easy enough. The mail records made me stop and ask: how does the internet know an email claiming to be from my domain actually came from me?
This led me through SPF, DKIM, and DMARC. That part was useful and free. Then I found out getting the little blue checkmark in Gmail costs $1,752 a year.
Spoofing is not hacking
Email was built on an absurd amount of trust. Someone can put person@hansbala.com in the visible From field without knowing that person's password or getting anywhere near their Google account.
It is basically the return address on an envelope. Anyone can write my address there. That does not mean they broke into my house.
The same distinction applies to email. Spoofing my address does not mean my mailbox was hacked. It means the sender made a claim, and the receiving server needs a way to check it.
That is where the alphabet soup comes in.
SPF, DKIM, and DMARC without the bullshit
SPF is a list of servers allowed to send mail for a domain. All legitimate @hansbala.com mail goes through Google Workspace, so my SPF record includes Google:
@ TXT "v=spf1 include:_spf.google.com ~all"
SPF checks the technical envelope or return-path domain, not necessarily the From address a person sees. It can also fail when mail gets forwarded because the final receiver sees the forwarder's server instead of Google's. Useful, but not enough by itself.
DKIM adds a cryptographic signature. Google signs my outgoing mail with a private key, and the matching public key lives in DNS. The receiving server verifies the signature and checks that the signed parts of the message were not changed in transit.
DKIM is not encryption. It does not hide the message. Think tamper-evident seal, not locked box.
DMARC connects those checks to the address people actually see. It passes when SPF or DKIM passes and the passing domain aligns with the visible From domain. It only needs one aligned pass, not both.
DMARC also lets me say what I want receivers to do when a message fails:
p=none: send reports, but do not request enforcement.p=quarantine: treat failures as suspicious, usually by sending them to spam.p=reject: reject them.
I added this:
_dmarc.hansbala.com TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@hansbala.com"
I also created dmarc-reports@hansbala.com. The reports are ugly XML summaries showing which systems sent mail as my domain and whether authentication passed. They do not ordinarily include the messages themselves.
Starting with p=none matters. I think Google is my only sender, but some forgotten contact form or random service could prove me wrong. Going straight to reject is a great way to block your own legitimate mail and feel like a security genius while doing it.
Google recommends monitoring first, then gradually moving to quarantine and reject. Receiving servers still make the final call, but a strict policy gives them a clear signal about mail impersonating my domain.
So far, so good. The stuff that actually reduces spoofing costs nothing beyond the email and domain services I already pay for.
Then I saw Gmail's blue checkmark and thought: neat, I have authenticated mail. Surely I can get that.
Nope.
The fucking checkmark
Gmail's checkmark uses BIMI, or Brand Indicators for Message Identification. BIMI lets participating mail apps show a verified logo next to a sender.
The technical requirements are reasonable. Google requires DMARC at full enforcement, meaning p=quarantine or p=reject with pct=100, plus a specially formatted SVG logo and a BIMI DNS record.
But Gmail also requires a third-party mark certificate. For the blue checkmark, that means a Verified Mark Certificate, or VMC. To get one, the logo generally needs to be a registered trademark.
The USPTO base application fee is currently $350 per class, before extra fees or a lawyer. Google says the trademark process can take six to twelve months.
Then there is the certificate itself. As of August 8, 2026, DigiCert lists a VMC at $1,752 per year. Per year. Recurring. For a fucking checkmark.
There is a Common Mark Certificate for logos without a registered trademark. DigiCert lists that at $1,416 per year, and it may get the logo displayed. It does not get Gmail's blue checkmark. Google reserves that for VMC-verified senders.
DigiCert is not the only issuer. The BIMI Group's current list also includes GlobalSign and SSL.com. I am using DigiCert because it publishes a clear price, and that price is completely bonkers.
None of this is required to authenticate mail. It does not guarantee inbox placement. It does not make the contents of a message safe or true. It is a visual brand-verification signal sitting on top of the actual authentication.
Why can't I sign my own shit?
Technically, I can. I can create a key and self-sign a certificate. Gmail just has no reason to trust my personal assertion that I am definitely me.
That is fair. Anyone can create a self-signed HTTPS certificate too, but browsers warn about it because control of a key is not independent proof of identity. If every domain could award itself a checkmark, scammers would register lookalike domains, copy bank logos, and verify themselves. The badge would mean jack shit.
Certificate authorities do real work. They validate identity and trademark ownership, get audited, maintain revocation systems, and take on liability. I understand why an outside verifier exists.
What I do not accept is that the only workable version of this costs roughly $1,700 every goddamn year.
That price might be noise to a bank or a global retailer. For a person with a personal domain, it is ridiculous. The cryptography is cheap. The useful security standards are free. The expensive part is admission to the trust system, which has been packaged and priced like an enterprise product.
There has to be some ground between "let anyone upload a logo" and "pay four figures a year forever." Verify my identity. Verify that I have controlled this domain for years. Charge me something sane. Just do not pretend a recurring enterprise certificate is the only possible way to establish trust for an individual.
I am going to keep monitoring DMARC and eventually move to enforcement. My mail can be strongly authenticated without a badge, and mail without a badge is not automatically fake or insecure.
SPF, DKIM, and DMARC are worth setting up. Renting credibility from a certificate authority is not.
The internet will verify that a message came from my domain for free. It just will not put a little blue icon next to my name unless I pay the toll every year.
Honestly, fuck Google. But it's pretty much the only email hosting provider you can use these days. That's a rant for another day.
Shit changes so fact check this whenever you're reading this if you care about it