Brand Indicators for Message Identification (BIMI) is an email standard that lets an organization publish its logo so that participating mailbox providers can display it next to messages from its domain. The logo only shows on messages that pass DMARC authentication with an enforcement policy, so BIMI works as a visible reward for, and signal of, properly authenticated email. Whether and how the logo appears is decided by each mailbox provider.
At a glance
- BIMI uses a DNS record to point mailbox providers to your logo, and often to a certificate proving your right to use it.
- It requires DMARC at enforcement (quarantine or reject) on the sending domain.
- Many providers also require a mark certificate, such as a Verified Mark Certificate (VMC) or Common Mark Certificate (CMC), depending on the provider.
- Logo display depends on the mailbox provider; support and rules vary, and some providers do not display BIMI logos.
- BIMI is a brand and trust feature; the security benefit comes from the DMARC enforcement behind it.
What problem it solves
Recipients have few ways to tell a real email from a spoofed one. A display name can say anything, and most people don’t check domains. Organizations that send mail to customers, such as banks, retailers and software companies, are frequent targets for phishing that imitates them.
Email authentication through SPF, DKIM and DMARC lets receiving systems check that mail really comes from the domain it claims, but that check is invisible to the reader. BIMI makes the result visible: messages that pass authentication from a domain at DMARC enforcement can show the brand’s logo, which helps recipients recognize genuine mail and gives marketing teams a reason to support the authentication work. It also nudges organizations to move DMARC from monitoring-only to enforcement, which is what actually blocks spoofing.
How it works
Authentication first. The sending domain must publish a DMARC policy of quarantine or reject, and legitimate mail must pass DMARC through aligned Sender Policy Framework (SPF) or DomainKeys Identified Mail (DKIM) results. Providers may set further conditions, such as applying the policy to all mail.
Logo file. The organization prepares its logo in a specific, restricted SVG format and hosts it at a secure web address.
Mark certificate. For many providers, the organization obtains a mark certificate from an approved certificate authority. A Verified Mark Certificate is generally based on a registered trademark; a Common Mark Certificate can cover logos that have been in use for a period of time without being registered. Eligibility rules are set by the certificate authorities and industry groups, so confirm them with the issuer.
DNS record. A BIMI TXT record in the domain’s DNS points to the logo and, where used, the certificate.
Display. When a supporting mailbox provider receives a message that passes its checks, it fetches the logo and may display it in the inbox and message view. Some providers also show a verified checkmark for certain certificate types.
When it matters for buyers
- When you send a lot of email to consumers. Brand recognition in the inbox matters most for banks, retailers and consumer services.
- When finishing a DMARC project. BIMI is a natural final step once DMARC is at enforcement, and it fits alongside the authentication rules in bulk sender requirements.
- When marketing wants inbox visibility. It aligns marketing and security goals around the same authentication work.
- When choosing email security and sending platforms. See our secure email gateway overview for the wider set of email security options.
- When budgeting. Mark certificates are an annual cost, and trademark registration can take time if you don’t already have one.
Questions to ask vendors
- Can you get our sending domains, including third-party senders, to DMARC enforcement without breaking legitimate mail?
- Which mailbox providers currently display BIMI logos, and what does each require?
- Do we need a VMC or a CMC for the providers we care about, and what does each cost per year?
- Do our email marketing and transactional platforms support DMARC alignment for BIMI?
- Can you prepare the logo in the required SVG format and publish the DNS record?
- How will we monitor whether our logo is displaying and whether authentication keeps passing?
How it differs from DMARC
DMARC tells receiving systems how to handle messages when neither SPF nor DKIM passes with alignment to the domain in the visible From address, and provides reports about domain use. It is the security control. BIMI sits on top of DMARC: it adds nothing to authentication itself but lets supporting providers show your logo on mail that passes. You can have DMARC without BIMI, but BIMI requires DMARC at enforcement first.
