Back to the blog
deliverabilitybimidmarcmerk
New

BIMI: your logo in the inbox — what it requires and whether it is worth it

BIMI is a standard that lets receiving mail providers show your logo next to your messages. It requires a DMARC policy of quarantine or reject, a logo in a strict SVG format at a public location, an extra DNS record and, at the largest providers, a paid certificate tied to a registered trademark. It does not directly improve your delivery; it is recognition and protection against imitation. For anyone who already has DMARC enforced, it is a small step. For anyone who does not, it is the wrong priority.

What BIMI actually does

The acronym stands for Brand Indicators for Message Identification. When a message from your domain passes all authentication checks, the receiving provider looks in your DNS for a BIMI record. If there is one, it fetches the logo and shows it next to your sender name in the message list. So not a logo in the HTML of your mail, but one the provider fetches itself and only shows once your domain has proven the message really came from you.

Requirement 1: DMARC with enforcement

This is the threshold where most organisations stall. Your DMARC policy must be quarantine at a hundred percent, or reject. A policy of none is not enough, because then your domain proves nothing. Anyone still on none first has to go through the path to enforcement: read the reports, align every sender, tighten gradually. That is the work that makes BIMI worthwhile, and it is also the work that takes the most time. Everything about those three records is on our SPF, DKIM and DMARC page.

Requirement 2: a logo in the right format

The logo must be an SVG file in a restricted profile of that standard, with no scripts, no external references and without a number of common elements. Your usual logo file almost never complies straight away; usually a designer has to re-export it and someone has to validate it. The logo also has to be square, on a solid background, and reachable over a secure connection at a fixed address.

Requirement 3: the DNS record

A small TXT record at a fixed location under your domain points to the logo and, if you have one, to the certificate. Technically this is the easiest step.

Requirement 4: the certificate

This is where providers differ. Some show the logo as soon as the first three requirements are met. The largest, Gmail first among them, additionally require a Verified Mark Certificate: a certificate, issued by a limited number of parties, proving that the logo belongs to a registered trademark. That usually requires a trademark registration, and the certificate costs money every year. Lighter certificate variants now exist that suffice at some providers; what applies where changes from time to time, so check the current conditions before you set aside budget.

Is it worth it?

That depends on two questions. Is your brand being imitated? Then BIMI is a visible difference between your real mail and the forgery, and it is justified. Do you send large volumes to consumers, where recognition in a crowded inbox counts? Then it can pay off too. For a company that mainly sends invoices and quotes to existing customers, the return is limited: those customers already know you, and a logo changes nothing about whether the message arrives.

What it delivers in any case, even if you never buy the certificate, is that you have set DMARC to enforcement. That is the real gain: your domain can no longer be freely forged. In that sense BIMI is a good excuse to finally do that work.

The order in practice

  1. SPF and DKIM for every sender, including the small ones. An SMTP relay that bundles everything per application keeps this manageable.
  2. DMARC at none with reporting, read for at least a month.
  3. Tighten to quarantine and then reject.
  4. Have the logo exported and validated, place it at a fixed address.
  5. Publish the BIMI record.
  6. Decide on the certificate based on who your recipients are.

Frequently asked questions

Does BIMI improve my delivery?

Not directly. The stricter DMARC policy it requires does help, because forgers can no longer damage your reputation.

Can I use BIMI without a certificate?

Yes, and some providers will show the logo already. The largest require a certificate. Start without and decide later.

Does it work on every subdomain?

The record can sit per domain or subdomain. If you send newsletters from a subdomain, put it there as well.

#bimi#set up bimi#verified mark certificate#logo in inbox#bimi dmarc
Call us
Send an email