BIMI

BIMI (Brand Indicators for Message Identification) is an email specification that lets a domain display its logo next to authenticated messages in supporting inboxes. It requires DMARC at enforcement and, at Gmail, a verified mark certificate.

Deliverability & Email InfrastructureUpdated September 30, 2026

In short

BIMI shows a brand's logo beside its emails, but only for domains with strong DMARC protection and, in Gmail, a certified logo.

Key points

  1. BIMI is published as a TXT DNS Record at default._bimi.example.com that points to an SVG logo and, optionally, a certificate file [1].
  2. The domain must have DMARC set to quarantine or reject; a p=none policy does not qualify [1][2].
  3. Gmail requires a Verified Mark Certificate (VMC) or a Common Mark Certificate (CMC) from a supported certificate authority [2].
  4. A VMC needs a registered trademark for the logo; a CMC is an option for logos without one, but does not earn Gmail's blue checkmark [2].
  5. BIMI does not improve Inbox Placement directly; it rewards domains that already have solid Email Authentication.
  6. Yahoo also displays BIMI logos for qualifying senders, while support varies across other mailbox providers [3].

How BIMI works

BIMI builds on top of DMARC. When a message passes DMARC under an enforced policy, a supporting receiver looks up the BIMI record for the From domain, usually at default._bimi plus the domain. The record contains an l= tag with the HTTPS address of the logo, which must be in the restricted SVG Tiny PS format, and an a= tag pointing to a certificate that proves the domain is entitled to use the mark [1]. If everything checks out, the mailbox shows the logo in the sender's avatar slot. Gmail's setup guide lists the steps: create the SVG, obtain a VMC or CMC, host the PEM file, publish the DNS record and confirm DMARC enforcement [2]. Nothing about BIMI changes how a message is authenticated; it only changes how an authenticated message looks.

Costs and requirements

The main hurdle is the certificate. A Verified Mark Certificate requires that the logo be a registered trademark with a recognized intellectual property office, and it is issued after identity checks by a small number of certificate authorities [2]. That process takes time and carries an annual fee. Common Mark Certificates relax the trademark rule and instead ask for other evidence that the organization has used the logo, but Gmail does not show its verified checkmark for them. The DMARC requirement is equally strict: every legitimate service that sends as the domain must already pass SPF (Sender Policy Framework) or DKIM (DomainKeys Identified Mail) with Domain Alignment, or it will be quarantined or rejected once the policy is enforced. For many small teams, getting to that point is the real work.

Is BIMI worth it for outbound teams?

For consumer brands that send large volumes of marketing mail, a recognizable logo can lift trust and open rates. For Cold Email and B2B outreach, the case is weaker. Messages come from a named person, recipients judge them on relevance, and many outreach setups use a Secondary Sending Domain that is unlikely to carry a trademarked logo. The work BIMI demands is still valuable, though: moving a domain to DMARC enforcement closes spoofing gaps and strengthens Domain Reputation. The BIMI Group, which maintains the specification, lists supporting mailbox providers and tools for checking a record [3]. A reasonable order is to fix Email Authentication first, reach p=reject, and only then decide whether a certificate is worth the cost.

Sources
  1. Brand Indicators for Message Identification (BIMI), Internet-Draft — IETF Datatracker
  2. Set up BIMI — Google Workspace Admin Help
  3. Brand Indicators for Message Identification — BIMI Group
External sources open in a new tab.

Related terms

Mentioned in

Outreach without the busywork.

PineLead finds new B2B prospects every day, qualifies them against your criteria and writes the first email in your voice. You approve — PineLead sends.

Start free with 100 credits →