What Is BIMI (Brand Indicators for Message Identification)?

Related problems: Want our logo to show next to our emails in customers' inboxes; Customers can't easily tell our real emails from spoofed ones; Marketing asking for a brand logo in Gmail and other mailboxes; Already set up DMARC and want visible benefit from it

Brand Indicators for Message Identification (BIMI) is an email standard that lets an organization publish its logo so that participating mailbox providers can display it next to messages from its domain. The logo only shows on messages that pass DMARC authentication with an enforcement policy, so BIMI works as a visible reward for, and signal of, properly authenticated email. Whether and how the logo appears is decided by each mailbox provider.

At a glance

  • BIMI uses a DNS record to point mailbox providers to your logo, and often to a certificate proving your right to use it.
  • It requires DMARC at enforcement (quarantine or reject) on the sending domain.
  • Many providers also require a mark certificate, such as a Verified Mark Certificate (VMC) or Common Mark Certificate (CMC), depending on the provider.
  • Logo display depends on the mailbox provider; support and rules vary, and some providers do not display BIMI logos.
  • BIMI is a brand and trust feature; the security benefit comes from the DMARC enforcement behind it.

What problem it solves

Recipients have few ways to tell a real email from a spoofed one. A display name can say anything, and most people don’t check domains. Organizations that send mail to customers, such as banks, retailers and software companies, are frequent targets for phishing that imitates them.

Email authentication through SPF, DKIM and DMARC lets receiving systems check that mail really comes from the domain it claims, but that check is invisible to the reader. BIMI makes the result visible: messages that pass authentication from a domain at DMARC enforcement can show the brand’s logo, which helps recipients recognize genuine mail and gives marketing teams a reason to support the authentication work. It also nudges organizations to move DMARC from monitoring-only to enforcement, which is what actually blocks spoofing.

How it works

Authentication first. The sending domain must publish a DMARC policy of quarantine or reject, and legitimate mail must pass DMARC through aligned Sender Policy Framework (SPF) or DomainKeys Identified Mail (DKIM) results. Providers may set further conditions, such as applying the policy to all mail.

Logo file. The organization prepares its logo in a specific, restricted SVG format and hosts it at a secure web address.

Mark certificate. For many providers, the organization obtains a mark certificate from an approved certificate authority. A Verified Mark Certificate is generally based on a registered trademark; a Common Mark Certificate can cover logos that have been in use for a period of time without being registered. Eligibility rules are set by the certificate authorities and industry groups, so confirm them with the issuer.

DNS record. A BIMI TXT record in the domain’s DNS points to the logo and, where used, the certificate.

Display. When a supporting mailbox provider receives a message that passes its checks, it fetches the logo and may display it in the inbox and message view. Some providers also show a verified checkmark for certain certificate types.

When it matters for buyers

  • When you send a lot of email to consumers. Brand recognition in the inbox matters most for banks, retailers and consumer services.
  • When finishing a DMARC project. BIMI is a natural final step once DMARC is at enforcement, and it fits alongside the authentication rules in bulk sender requirements.
  • When marketing wants inbox visibility. It aligns marketing and security goals around the same authentication work.
  • When choosing email security and sending platforms. See our secure email gateway overview for the wider set of email security options.
  • When budgeting. Mark certificates are an annual cost, and trademark registration can take time if you don’t already have one.

Questions to ask vendors

  • Can you get our sending domains, including third-party senders, to DMARC enforcement without breaking legitimate mail?
  • Which mailbox providers currently display BIMI logos, and what does each require?
  • Do we need a VMC or a CMC for the providers we care about, and what does each cost per year?
  • Do our email marketing and transactional platforms support DMARC alignment for BIMI?
  • Can you prepare the logo in the required SVG format and publish the DNS record?
  • How will we monitor whether our logo is displaying and whether authentication keeps passing?

How it differs from DMARC

DMARC tells receiving systems how to handle messages when neither SPF nor DKIM passes with alignment to the domain in the visible From address, and provides reports about domain use. It is the security control. BIMI sits on top of DMARC: it adds nothing to authentication itself but lets supporting providers show your logo on mail that passes. You can have DMARC without BIMI, but BIMI requires DMARC at enforcement first.

Frequently Asked Questions

What do we need before we can use BIMI?
At minimum, DMARC set to an enforcement policy (quarantine or reject) on your sending domain, with SPF or DKIM passing with alignment for your legitimate mail, a logo in the required SVG format, and a BIMI DNS record. Many mailbox providers also require a mark certificate. Check each provider's current sender documentation for the full list.
What is a Verified Mark Certificate (VMC)?
A VMC is a digital certificate from an approved certificate authority that confirms your organization's right to use a logo, typically based on a registered trademark. A newer Common Mark Certificate (CMC) can be issued for logos that are not registered trademarks under certain conditions. Which certificate a provider accepts, and whether it shows a verified checkmark, depends on the provider.
Does BIMI guarantee our logo will appear?
No. Display depends on each mailbox provider, which decides whether to support BIMI, what certificate it requires and whether a given message qualifies. Some providers do not support BIMI at all, and good sending reputation may also be a factor.
Does BIMI improve deliverability?
Not directly. BIMI shows a logo; it is not a filtering signal you can rely on. The DMARC enforcement it requires does help protect your domain from spoofing and is expected by large mailbox providers for bulk senders.
Does BIMI stop phishing?
Not by itself. It gives recipients a visual cue on authenticated mail from your domain, but attackers can still use lookalike domains or compromised accounts. The protection comes mainly from the DMARC enforcement behind it.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.