Email Authentication Glossary
Certificate & VMC
BIMIhigh

Certificate Can't Be Accessed Automatically

“Certificate can't be accessed automatically” means an automated client is denied, challenged, or otherwise prevented from downloading the published certificate. The BIMI and VMC drafts describe the e

The exact error

Certificate can't be accessed automatically
cert-forbidden

What Does “Certificate Can't Be Accessed Automatically” Mean?

“Certificate can't be accessed automatically” means an automated client is denied, challenged, or otherwise prevented from downloading the published certificate. The BIMI and VMC drafts describe the evidence location as publicly retrievable over HTTPS. Brand Indicators for Message Identification draft 14 documents the controlling requirement or boundary.

Automated evidence validation cannot proceed. Different receivers use different request identities, so a browser success alone is insufficient.

Why Does Certificate Can't Be Accessed Automatically Appear?

Certificate can't be accessed automatically appears when authentication, bot mitigation, JavaScript challenges, cookies, geo rules, or request filtering block non-browser retrieval. The exact diagnostic should be read at the scope of public VMC or mark-certificate resource rather than as proof that every BIMI layer failed.

How Do You Fix Certificate Can't Be Accessed Automatically?

To fix Certificate can't be accessed automatically, serve the certificate at a stable public HTTPS URL that does not require interactive or authenticated access.

Removing access controls does not validate the PEM contents or chain.

What Should You Verify After Fixing Certificate Can't Be Accessed Automatically?

After fixing Certificate can't be accessed automatically, fetch the exact URL from a clean command-line client and from outside the hosting network. Verification should use the exact public selector, URL, record, or file evaluated by the receiver.

The correction clears only this condition; it does not guarantee that a receiver will display an indicator.

Key Takeaways

  • The affected object is public VMC or mark-certificate resource.
  • The direct correction is to serve the certificate at a stable public HTTPS URL that does not require interactive or authenticated access.
  • Removing access controls does not validate the PEM contents or chain.
Check your BIMI record

See exactly which checks your domain passes and fails.

Email Authentication Glossary