Verified by an independent party
R7.4Does a third party bind the seller's legal entity to the domain?
- Why it matters
- Outside verification carries more weight than a seller vouching for itself.
- What Lens looks for
- We looked for a credential an independent verifier has issued for your domain, such as a verified mark certificate.
- Where it sits
- Seller · Check 3 of 3
- Needed for
- No stage needs it. It counts toward its group.
- Builds on
- A registered company behind the site R7.3
- Needed by
- Nothing
- Usually fixed by
- Marketing · Weeks to months
What to do
Obtain a Verified Mark or Common Mark Certificate for the domain and publish it in its BIMI record, or a Digital Identity Anchor from your business register linked from your DID document.
Seller
Who is selling?
The definition
- Definition
- Any of: a Verified Mark Certificate or Common Mark Certificate for the domain, named by the a= tag of its BIMI record (default._bimi.<registrable domain>, read through DNS-over-HTTPS); a UNTP Digital Identity Anchor for a DID the origin links (its did:web document, or a did:web its DID configuration links by a Domain Linkage Credential that verifies), found through the DID document's untp:dia service and secured with JOSE; or a vLEI linked to the domain through a KERI-based DID (did:webs). Trust roots are versioned lists in this rubric: lists.markVerifyingAuthorities (root certificates, by SHA-256) and lists.identityAnchorIssuers (register DIDs, empty in this version: no published UNTP register names a business register that issues anchors).
- Passes when
- One such credential verifies and, where R7.3 found an organisation, names the same one (under R7.3's normalisation, or a DIA by its registered identifier). A mark certificate: BIMI's extended key usage, a VMC or CMC mark type, the domain among its subject alternative names, a path to a listed root with every certificate valid at the probe's time, and the certificate not on its issuer's current CRL (a CRL that cannot be read, or none named, is inconclusive; OCSP is not queried; embedded SCTs are recorded, not verified). A DIA: its signature verifies with a key its issuer's DID document lists for assertion (ES256 or EdDSA), type DigitalIdentityAnchor, its subject the linked DID, current, its issuer on the list, and no status list (one it names is not read, so inconclusive); while the list is empty, an anchor that passes every other check is not tested. A vLEI is not tested: no maintained TypeScript verifier runs in a Worker. The best result over the credentials counts; a site with none of them is not met.
- Decided by
- A rule
- Evidence
- The BIMI record, the mark certificate chain and its CRLs; the DID documents, the anchor and its issuer's DID document
- Steps
- wellknown, registers
- Made as
- anon, lens
- Standards
- BIMI (draft-brand-indicators-for-message-identification)VMC and CMC (BIMI Group)RFC 5280 (X.509, CRLs)UNTP Digital Identity Anchor (v0.7.0)W3C VC 2.0 and VC-JOSE-COSEISO 17442-3 (vLEI)