Open Gmail on any phone and scroll through the inbox. Most messages show a default circle with a sender initial. A few show a real brand logo: Bank of America, Amazon, Uber, and a handful of others. Those logos are not pulled from a contact card or a profile picture. They are displayed because the sender has set up BIMI: a protocol that lets verified brands publish their logo and have it rendered next to every authenticated message.
For brands that depend on email for customer trust banks, retailers, healthcare providers, anyone whose messages compete with phishing attempts BIMI is one of the few visual signals available to differentiate genuine mail from forgery. For everyone else, it is a question of cost versus impact, and the calculation is not always obvious.
What BIMI Is and What It Does
BIMI stands for Brand Indicators for Message Identification. It is a published DNS record that points to a logo image and, optionally, to a certificate that proves the logo belongs to the brand. When a participating mailbox provider receives a message from a domain with a valid BIMI record, and the message passes strict authentication checks, the receiving mail client displays the brand’s logo alongside the message in the inbox.
The mechanism is straightforward. The brand publishes a DNS record at default._bimi.brand.com that contains a URL pointing to a square SVG logo and, where required, a URL pointing to a Verified Mark Certificate. The receiving mail server reads the record on incoming messages, validates the certificate where required, and instructs the mail client to render the logo.
BIMI is not a deliverability protocol. It does not increase the chances of an email landing in the inbox. It does not change spam scoring. What it does is provide a strong visual trust signal to recipients who do receive the message, on the assumption that recipients are more likely to engage with a message that visibly comes from a recognised brand.
Where BIMI Shows Up?
BIMI support varies by mail client and continues to expand. The major implementers are Gmail (web and mobile), Yahoo Mail, AOL Mail, Apple Mail (iOS 16 and later, macOS Ventura and later), and Fastmail. Microsoft Outlook does not currently render BIMI logos, which is a significant gap given Outlook’s enterprise share. La Poste in France and several smaller providers in Europe also support BIMI.
The practical implication is that a BIMI deployment will be visible to Gmail and Apple Mail users in a meaningful portion of consumer email traffic but will not affect what Outlook users see. Brands evaluating BIMI should weigh the rendering coverage against their actual recipient mix.
BIMI Prerequisites: DMARC, VMC, and a Square Logo
BIMI has hard prerequisites. Without all of them in place, the BIMI record will exist, but no mailbox provider will render the logo.
Why DMARC at p=quarantine or p=reject is Mandatory
The most significant prerequisite is DMARC enforcement. A domain must have a published DMARC record with a policy of p=quarantine or p=reject, and the policy must apply to the entire domain, not just a partial percentage. A DMARC policy of p=none, which is where many domains sit by default, will not qualify.
This requirement exists because BIMI relies on DMARC to prove that the message is genuinely from the claimed sender. A domain at p=none is allowing unauthenticated mail to pass through, which means the logo could end up displayed on phishing messages. Mailbox providers will not extend brand recognition to a domain that has not committed to authentication enforcement.
For most domains, getting to quarantine takes several months of DMARC monitoring and configuration cleanup. Every legitimate sending service the brand uses marketing platforms, transactional providers, internal mail servers has to be aligned correctly. Until that cleanup is done, BIMI is not available.
What a VMC Actually Costs?
Gmail and several other providers require a Verified Mark Certificate (VMC) before they will display a BIMI logo. A VMC is a paid certificate, issued by approved certificate authorities (currently DigiCert and Entrust), that verifies the brand owns the trademark for the logo being displayed.
The trademark requirement is strict. The logo must be a registered trademark in a jurisdiction recognised by the certificate authority. Pending trademarks do not qualify. Common-law marks do not qualify. The certificate authority verifies the trademark against official trademark office records before issuing the VMC.
Pricing varies but typically runs $1,200-1,700 per year for a VMC, depending on the certificate authority and any volume agreements. For brands that already hold registered trademarks, the certificate itself is the main cost. For brands that do not, the trademark registration process itself, which can take 12-24 months and several thousand dollars, must be completed first.
Logo Format Requirements
The logo must be provided as an SVG file in a specific subset of SVG called SVG Tiny Portable/Secure. This subset restricts certain SVG features for security reasons: no scripts, no external references, no animations. The logo must be square in aspect ratio, with content centred and the design legible at small sizes (the rendered logo is typically displayed at around 64×64 pixels in mobile clients).
Most brand logos do not arrive in SVG Tiny PS format and need to be converted, usually by a graphic designer familiar with the format. Online converters exist but produce unreliable results.
Step-by-Step BIMI Setup
Assuming DMARC enforcement is in place and a VMC has been obtained, the remaining BIMI setup steps are operational.
First, host the SVG logo file at a publicly accessible HTTPS URL. The file must be served with the correct MIME type (image/svg+xml). Many brands use a dedicated subdomain for this, such as bimi.brand.com/logo.svg.
Second, host the VMC PEM file at a publicly accessible HTTPS URL, alongside or near the logo. Both files must be reachable by the mailbox providers’ validation servers.
Third, publish the BIMI DNS record at default._bimi.yourdomain.com. The record value follows the format:
Fourth, send test messages and wait. Logo display does not happen instantly. Mailbox providers cache and validate at their own pace, and it can take several days to weeks before the logo appears consistently. Some providers also accumulate sending reputation before displaying the logo, so a brand-new domain may not see logo rendering immediately, even with everything set up correctly.
How to Check if Your BIMI Is Working?
Several tools validate BIMI deployment without sending test messages. BIMI Group, the protocol’s standards body, maintains a free validator at bimigroup.org. Mailhardener and EasyDMARC both offer BIMI inspectors that check the DNS record, fetch the SVG and VMC, and validate against published rules.
For visual confirmation, the simplest test is to send a real message to a Gmail account and a Yahoo account, open them on mobile, and look for the rendered logo. If the logo does not appear after a week of consistent sending, run the validator and check that DMARC is reporting clean authentication for the domain.
BIMI Without a VMC: The Common Mark Certificate Path
In late 2023, a new certificate option became available: the Common Mark Certificate (CMC). The CMC is intended for brands that have established public usage of a logo but do not hold a formal registered trademark. It is cheaper than a VMC and has lower prerequisites.
Gmail accepts CMCs for BIMI logo display in some contexts, with limitations. Apple Mail does not currently accept CMCs. The CMC route is appropriate for organisations that cannot meet the trademark requirement non-profits, small businesses, public sector entities but want some level of BIMI display in supporting clients.
Is BIMI Worth It? An Honest Cost-Benefit Analysis?
BIMI’s value depends almost entirely on the sender’s profile.
For consumer brands that send high-volume email and depend on visual trust financial services, retail, healthcare, travel, anything where phishing is a recurring problem BIMI is increasingly worth the cost. The visual differentiation from forged mail is real, and the cost (typically $1,500-2,000 per year for the certificate plus a few hours of setup time) is small relative to the brand-protection value.
For B2B SaaS companies, professional services firms, and small businesses, the calculation is harder. The visual logo display only reaches Gmail, Yahoo, and Apple Mail users, none of which dominate the B2B inbox the way Outlook does. The DMARC enforcement that BIMI requires is independently valuable and worth pursuing for its own sake. The VMC cost specifically is harder to justify.
A useful test: would the brand’s recipients recognise the logo if they saw it next to a message? If the answer is yes, BIMI delivers real value. If the answer is “maybe,” the certificate cost is harder to justify, and the DMARC work alone may be the better priority.
Key Takeaways
- BIMI publishes a brand’s logo as a DNS record, and supporting mail clients display that logo next to verified incoming messages.
- The protocol works in Gmail, Yahoo, AOL, Apple Mail, and several smaller providers. It does not work in Outlook.
- BIMI requires DMARC enforcement at p=quarantine or p=reject across the entire domain, a prerequisite that takes most domains several months to achieve.
- A Verified Mark Certificate is required for Gmail and most major providers, costs $1,200-1,700 per year, and requires a registered trademark.
- The Common Mark Certificate offers a lower-cost alternative with reduced provider coverage.
- BIMI does not improve deliverability. It improves visual trust at the inbox, which matters most for high-recognition consumer brands.
Frequently Asked Questions
No. BIMI does not affect spam filtering, inbox placement, or deliverability scoring. It controls only the visual display of a logo next to messages that have already passed authentication checks. The DMARC enforcement that BIMI requires can indirectly improve deliverability, but that benefit comes from DMARC itself, not from BIMI.
In Gmail with a Common Mark Certificate, partially. Without any certificate, mailbox providers will not display the logo even if the DNS record exists. Apple Mail and several other providers require a VMC specifically.
The most common reasons are DMARC policy not at p=quarantine or p=reject across the full domain, recent authentication failures in the domain’s DMARC reports, or insufficient sending reputation for the receiving provider to extend logo display. Newer domains may need to send consistent authenticated mail for several weeks before logos appear.
Yes, as long as the third-party service can send mail with DKIM signatures aligned to the brand’s domain. SendGrid, Mailgun, Postmark, and most major transactional providers support DKIM alignment. The BIMI DNS record sits on the brand’s domain regardless of where the mail is sent from.
For brands with DMARC already enforced and a registered trademark, deployment is two to four weeks (VMC issuance is the slowest step). For brands starting from DMARC at p=none and no trademark, full deployment realistically takes 6-18 months.
Conclusion
BIMI is one of the few email standards that recipients actually see. SPF, DKIM, and DMARC operate silently in the background, but BIMI turns strong authentication into a visible trust signal directly inside the inbox. For brands already investing in domain security and sender reputation, that visibility can strengthen recognition, reduce phishing confusion, and reinforce customer confidence at the moment an email is opened.
For organisations evaluating BIMI in 2025, the real decision is not whether the protocol works; it does. The decision is whether the combination of DMARC enforcement, trademark readiness, and certificate cost aligns with the value of stronger brand visibility in the inbox. For consumer-facing brands with high email volume and recognisable identities, the answer is increasingly yes. Build Trust Directly Inside Inboxes
