BIMI: the verified logo you earn by getting authentication right

· 11 min read · Web Involved

What is BIMI and how do you get it?

BIMI (Brand Indicators for Message Identification) puts your verified brand logo next to your emails in Gmail, Yahoo and Apple Mail — and it’s the reward for enforcing authentication, not a shortcut to the inbox. It builds directly on DMARC, so it has one hard prerequisite: a DMARC policy at enforcement (p=quarantine or p=reject, covering 100% of your mail). At p=none, no provider will show your logo, which is exactly why BIMI can’t be skipped to — you earn it by doing the authentication work first. Once you’re enforced, there are three tiers of logo verification: a free self-asserted logo (supported by Yahoo and Apple but not Gmail), a Common Mark Certificate ($1,500–3,000/year, no trademark required, shows your logo in Gmail without the blue checkmark), and a Verified Mark Certificate ($1,500–5,000+/year, requires a registered trademark, and is the only thing that triggers Gmail’s blue verified checkmark). The logo itself must be a strict square SVG in the Tiny Portable/Secure format, published in a DNS record at default._bimi.yourdomain. Two honest points frame the whole thing: BIMI is a trust and display feature that tends to lift open rates a few points, not a deliverability fix — it won’t rescue a poor sender — and you should start with the free or CMC path before paying for a VMC. Its deepest value is that a phisher can’t obtain a certificate for a brand they don’t own, so the verified logo is a trust signal no impersonator can forge.

What BIMI actually is, and what it isn’t

BIMI is an open technical standard that acts as an instruction set in your DNS, telling a mailbox provider where to find your brand logo and how to verify it, so that supporting inboxes can display it next to your authenticated mail (BIMI Group, 2026). It works alongside SPF, DKIM and DMARC rather than replacing any of them, and because a logo appears only when a message authenticates and aligns, it makes visual spoofing harder and raises the bar for impersonators (BIMI Group, 2026).

What BIMI is not is a way into the inbox. A verified logo doesn’t improve deliverability, and it won’t rescue a sender with a poor list or a damaged reputation — a VMC assures reputable logo display but does not guarantee inbox placement (Mailwarm, 2026). The useful way to hold it is as the visible proof of control our pillar on whether your email reaches the inbox describes: a reward layered on top of authentication that’s earned, not bought.

The prerequisite that trips everyone: DMARC at enforcement

There’s one gate before any logo appears, and it’s the reason BIMI belongs at the end of the authentication story rather than the start. BIMI requires DMARC at an enforcement policy — p=quarantine or p=reject with pct=100 — and no mailbox provider will process a BIMI record while your domain is still at p=none (SSLInsights, 2026). A DMARC policy of quarantine or reject tells providers you’re actively preventing spoofed mail from being treated as legitimate, which is the trust signal that makes showing your logo reasonable in the first place (DigiCert, 2026).

For a certificate specifically, providers want that enforcement to have held for at least 30 consecutive days before display (Startup Booted, 2026). This is why the honest sequence runs authentication first: confirm every legitimate sender passes, roll DMARC from none to quarantine to reject, and only then pursue BIMI — the exact staged rollout our guide on SPF, DKIM and DMARC lays out. BIMI is, in the most literal sense, the payoff for finishing that work.

The three tiers of logo verification

Once you’re enforced, how your logo appears depends on which certificate you hold, and there are three levels with very different costs and requirements.

TierRequirementCostWhere it shows
Self-assertedDMARC enforcement + compliant SVG, no certificateFreeYahoo, AOL, Fastmail — not Gmail
CMC (Common Mark Certificate)12 months of public logo use, no trademark~$1,500–3,000/yrGmail logo (no checkmark), Yahoo, Apple
VMC (Verified Mark Certificate)Registered trademark~$1,500–5,000+/yrGmail blue checkmark, Yahoo purple, Apple

The self-asserted logo is the attainable entry point and a sensible place to start, needing only your DMARC enforcement and a compliant logo on an HTTPS server (Validity, 2026). The Common Mark Certificate, which Google introduced in early 2025, widened eligibility considerably by dropping the trademark requirement in favour of proof that your logo has been publicly displayed for at least a year — a genuine opening for SaaS startups and mid-market brands without a registered mark (PowerDMARC, 2026). The Verified Mark Certificate remains the only route to Gmail’s blue verified checkmark, and it requires a registered trademark with a recognized IP office (SSLInsights, 2026).

Provider support in 2026

Where your logo shows up varies more than people expect. Gmail requires at minimum a CMC to display a logo and reserves its blue verified checkmark for VMCs specifically (SSLInsights, 2026). Yahoo and AOL are the most permissive, displaying self-asserted logos with no certificate at all, and awarding a purple checkmark for a VMC (Validity, 2026). Apple Mail supports BIMI as well, and Apple runs a separate brand-verification system, Apple Business Connect, that surfaces your logo across Apple apps including Mail, Apple Pay and incoming calls (Validity, 2026).

Microsoft is the notable gap: as of early 2026 its BIMI support is limited, acknowledging the protocol but not yet offering full verified-logo display, which remains primarily a Gmail, Yahoo and Apple experience (Startup Booted, 2026). Support is expanding over time, but it’s worth setting expectations by where your recipients actually read their mail rather than assuming a logo shows everywhere.

The logo file and the DNS record

BIMI’s technical requirements are unusually strict about the logo itself, and this is where many setups stall. The logo must be an SVG in the Tiny Portable/Secure (SVG P/S) format — standard design-software exports won’t pass validation — with a 1:1 square aspect ratio, a non-transparent background, and no scripts, external references or animations (SSLInsights, 2026). Gmail adds its own rule of a minimum 96×96 pixels with the size specified in absolute pixels, and because the logo renders small, it should stay recognizable at favicon size (DigiCert, 2026).

The record itself is a TXT entry published at default._bimi.yourdomain, taking the form v=BIMI1; l=<logo URL>; a=<certificate URL>, with the logo and certificate both hosted over HTTPS with stable URLs (BIMI Group, 2026). Two details cause most failures: the BIMI record and certificate must match the exact domain in your visible From address, since publishing on a subdomain while sending from the org domain breaks alignment, and certificates are valid for a maximum of 398 days, so renewal is an annual task (BIMI Group, 2026). Display is also gradual — even with a perfect setup, logos can take weeks to appear and require ongoing DMARC monitoring to stay lit as your sender mix changes.

What BIMI is worth, and what it isn’t

The case for BIMI is a trust-and-engagement case, and it’s a real one when kept in proportion. Displaying a verified logo is associated with open-rate lifts in the range of roughly 4 to 10%, along with higher consumer confidence and stronger brand recognition in a crowded inbox (Startup Booted, 2026). Its security value is subtler and arguably larger: because a phishing actor cannot obtain a certificate for a trademark or brand they don’t legally own, the verified logo becomes a signal impersonators can’t replicate (SSLInsights, 2026).

Two cautions keep it honest. BIMI won’t fix deliverability, so chasing the logo in the hope it rescues a struggling sender is effort misspent — the fundamentals of hygiene, engagement and reputation still govern whether you reach the inbox at all. And nearly every guide on BIMI is published by a certificate authority or DMARC platform selling the certificate, so the useful principle to hold onto is the sequence, not the vendor: enforce DMARC first, start with a free self-asserted or CMC logo, and pursue a VMC only when the Gmail blue checkmark is worth its annual cost to your brand.

Where brand identity meets deliverability

BIMI is the one point in the email stack where a brand’s visual identity — the logo, the thing our design work produces — becomes a piece of security infrastructure. The mark you put on a homepage is the same mark that, once authentication is enforced and verified, tells a recipient at a glance that a message is really from you before they’ve even opened it. That’s a satisfying convergence: the design and the deliverability, usually treated as separate disciplines, turn out to be the same trust story told in two places.

It also fits how we work, plainly stated. Getting to BIMI means enforcing DMARC, preparing a compliant SVG, and publishing and maintaining the record — the kind of thing we handle as part of the email infrastructure we run, alongside the logo we may well have designed in the first place. But the honest gate holds here as everywhere: we won’t sell you a VMC before your authentication is enforced and clean, because the logo is a reward for that work, not a substitute for it. Do the foundational work our pillar on reaching the inbox describes, and BIMI is the visible proof, in every supporting inbox, that you did.

Frequently asked

What is BIMI?
BIMI (Brand Indicators for Message Identification) is an open standard that lets your verified brand logo appear next to your emails in supported inboxes like Gmail, Yahoo and Apple Mail. It's a DNS-based instruction set that tells mailbox providers where to find your logo and how to verify it, and it builds on top of your existing authentication. It isn't a deliverability tool — it won't get you into the inbox — but it adds a visible trust signal to mail that already authenticates, which raises recognition and tends to lift open rates a few percentage points.
What do I need to set up BIMI?
Three things, in order. First, DMARC at enforcement — a policy of p=quarantine or p=reject covering 100% of your mail, because no provider will process a BIMI record while you're still at p=none. Second, a compliant logo: a square SVG in the strict SVG Tiny Portable/Secure format, with a solid background and no scripts or animations. Third, a BIMI DNS record published at default._bimi.yourdomain pointing to that logo, and for Gmail and Yahoo checkmarks, to a Verified Mark Certificate or Common Mark Certificate as well. The prerequisite that trips people up is the DMARC enforcement — BIMI is the reward for authentication, so you can't skip to it.
What's the difference between a VMC and a CMC?
Both are certificates that prove your right to the logo, but they verify different things. A VMC (Verified Mark Certificate) requires a registered trademark and is the only certificate that triggers Gmail's blue verified checkmark; it typically costs between roughly $1,500 and $5,000 or more a year. A CMC (Common Mark Certificate), introduced by Google in early 2025, doesn't require a trademark — instead it verifies that your logo has been publicly used for at least 12 months — and it unlocks logo display in Gmail without the blue checkmark, at a similar annual cost. There's also a free self-asserted option with no certificate, supported by Yahoo, AOL and others but not Gmail.
Does BIMI improve email deliverability?
Not directly. BIMI is a display and trust feature, not a deliverability booster — a verified logo doesn't get your mail into the inbox, and it won't rescue a sender with poor list hygiene or a damaged reputation. What it does is add a recognizable, hard-to-fake trust signal to mail that already authenticates and reaches the inbox, which studies associate with open-rate lifts in the region of 4 to 10% and higher consumer confidence. The indirect benefit is real, though: qualifying for BIMI forces you to enforce DMARC, and that enforcement genuinely improves your authentication posture.
Do I need a registered trademark for BIMI?
Not anymore, for most of the benefit. A registered trademark is required only for a VMC, which is what unlocks Gmail's blue verified checkmark. Since Google introduced Common Mark Certificates in early 2025, brands without a trademark can display their logo in Gmail using a CMC by proving 12 months of public logo use, and Yahoo and Apple Mail have long supported free self-asserted logos with no certificate at all. So the trademark barrier that once excluded smaller organizations now only stands between you and the blue checkmark specifically, not between you and a logo in the inbox.