Skip to content
Integra Lens
Menu
Rubric 0.3.0

Verified by an independent party

R7.4

Does a third party bind the seller's legal entity to the domain?

Why it matters
Outside verification carries more weight than a seller vouching for itself.
What Lens looks for
We looked for a credential an independent verifier has issued for your domain, such as a verified mark certificate.
Where it sits
Seller · Check 3 of 3
Needed for
No stage needs it. It counts toward its group.
Needed by
Nothing
Usually fixed by
Marketing · Weeks to months

What to do

Obtain a Verified Mark or Common Mark Certificate for the domain and publish it in its BIMI record, or a Digital Identity Anchor from your business register linked from your DID document.

The definition
Definition
Any of: a Verified Mark Certificate or Common Mark Certificate for the domain, named by the a= tag of its BIMI record (default._bimi.<registrable domain>, read through DNS-over-HTTPS); a UNTP Digital Identity Anchor for a DID the origin links (its did:web document, or a did:web its DID configuration links by a Domain Linkage Credential that verifies), found through the DID document's untp:dia service and secured with JOSE; or a vLEI linked to the domain through a KERI-based DID (did:webs). Trust roots are versioned lists in this rubric: lists.markVerifyingAuthorities (root certificates, by SHA-256) and lists.identityAnchorIssuers (register DIDs, empty in this version: no published UNTP register names a business register that issues anchors).
Passes when
One such credential verifies and, where R7.3 found an organisation, names the same one (under R7.3's normalisation, or a DIA by its registered identifier). A mark certificate: BIMI's extended key usage, a VMC or CMC mark type, the domain among its subject alternative names, a path to a listed root with every certificate valid at the probe's time, and the certificate not on its issuer's current CRL (a CRL that cannot be read, or none named, is inconclusive; OCSP is not queried; embedded SCTs are recorded, not verified). A DIA: its signature verifies with a key its issuer's DID document lists for assertion (ES256 or EdDSA), type DigitalIdentityAnchor, its subject the linked DID, current, its issuer on the list, and no status list (one it names is not read, so inconclusive); while the list is empty, an anchor that passes every other check is not tested. A vLEI is not tested: no maintained TypeScript verifier runs in a Worker. The best result over the credentials counts; a site with none of them is not met.
Decided by
A rule
Evidence
The BIMI record, the mark certificate chain and its CRLs; the DID documents, the anchor and its issuer's DID document
Steps
wellknown, registers
Made as
anon, lens