Skip to Content
Email Security

What is BIMI (verified logo in the inbox)?

BIMI is the standard that makes a company's official logo appear next to its messages in the recipient's inbox. It does not add a new layer of security: it is the visible reward for having done everything else, because it is only displayed for domains that keep DMARC at enforcement, meaning a blocking policy. It is the only email authentication control the end customer actually sees, and therefore the one that best justifies the work behind the other three.

Zamak TechnologiesUpdated on August 6, 2026

How BIMI works

BIMI, short for Brand Indicators for Message Identification, is the last link in a chain: it is only evaluated after the message has cleared all authentication and the domain's policy has proven to be in force. Without that, the logo simply does not appear.

1

Get DMARC to enforcement, with full coverage

The standard requires the policy to be at quarantine or reject, applied to every message. A domain in monitoring, or with partial application, does not get past this step.

2

Prepare the logo in the required format

The logo must sit in SVG Tiny PS, a restricted vector image profile created specifically for this use: solid background, square, no external elements. It is a simple conversion, but with strict rules.

3

Obtain the certificate proving your right to the mark

A certification authority verifies that the company genuinely holds rights to that logo and issues a certificate. The most widely accepted one requires a registered trademark; there is an alternative for unregistered logos, with narrower support.

4

Publish the record and providers display it

A text record in DNS points to the logo file and to the certificate. From there, each provider decides by its own criteria when to show the image.

Source: the implementation guide from BIMI Group, the body that maintains the standard, which defines the requirement of DMARC at enforcement with full coverage, the accepted image profile and the difference between certificate types.

What the logo does not buy

  • It is not a protection layer. BIMI blocks nothing, filters nothing and prevents no message. It is the consequence of protection that already exists, and a domain without DMARC at blocking gains nothing by publishing the record.
  • It does not guarantee display. Each provider applies its own criteria, which include sending reputation, and none commits to always showing the logo. Publishing is a necessary condition, not a sufficient one.
  • The uncertified version has limited reach. It is possible to declare the logo without going through a certification authority, but support for that route is far narrower among providers.
  • The trademark requirement is a real barrier. The most accepted certificate rests on a registered trademark, which involves cost and registration time. Check the status of the mark before promising the board a logo in the inbox.

The three routes to the logo

  • Certificate on a registered trademark (VMC) The most widely accepted route. The certification authority validates the trademark registration and issues the certificate that accompanies the logo. It requires the mark to be genuinely registered.
  • Certificate without a registered trademark (CMC) An alternative created for companies with an established logo they never registered as a trademark. Validation works differently and provider acceptance is narrower.
  • Declaration with no certificate (self-asserted BIMI) Publishing the record pointing only at the logo file, with no external validation. It is the cheapest route and the one with the least reach, useful mainly as preparation.
  • Beyond the three: the common prerequisite None of them works without DMARC at enforcement, and the requirement extends to subdomains: the standard asks for the same enforcement on the organizational domain and on the subdomain policy, with full coverage (pct=100) and no partial application. It is what it checks before anything else, and what most often fails domains that believe they are ready.

Why the logo is usually what unlocks the project

100%
is the required coverage of the DMARC policy: the logo does not appear with partial application or in monitoring mode (BIMI Group)
95%
of the Fortune 500 already adopt DMARC, and more than 80% have reached a blocking policy, exactly the rung BIMI requires (EasyDMARC, 2026 Adoption Report)
1
single vector image profile is accepted for the logo, SVG Tiny PS, created specifically for this use (BIMI Group)

There is a useful irony in BIMI. SPF, DKIM and DMARC are invisible: they work without anyone noticing, and so they compete badly for budget and for board attention against any project that produces something visible. BIMI flips that, because it puts the company's brand in front of the customer, inside the inbox, next to messages that today show up with a generic initial. The practical effect is that the logo gives the authentication work a sponsor it usually lacks: whoever wants the brand in the inbox needs DMARC at enforcement first, and ends up defending the very project the technical team had already been asking for. The path always runs that way, never the reverse: there is no shortcut that delivers the image without the authentication work behind it. When someone pitches BIMI as a standalone brand improvement, the arithmetic does not add up: what is being bought is the end result of a complete rollout.

How to get the logo into the inbox

The sequence is rigid, because each stage depends on the previous one being provably complete:

  1. Confirm DMARC at blocking, not merely publishedBefore anything else, verify the policy is at quarantine or reject with full coverage. This is the stage that fails most domains, and none of the later ones compensates for its absence.
  2. Check the status of your trademarkIf the logo is registered as a trademark, the most accepted route is open. If it is not, decide between starting the registration or going the narrower alternative, knowing the limit.
  3. Prepare the file within the rulesConverting to the accepted format is quick, but the rules are strict about background, proportion and image content. A file outside the profile is a silent reason for non-display.
  4. Issue the certificate and publish the recordWith the certificate issued, publish the DNS record pointing to both the logo file and the certificate. From there, each provider decides when to display.
  5. Treat display as an indicator, not a deliverableTrack where the logo shows and where it does not. Absence usually points to sending reputation or a file outside the profile, and both are actionable.

In practice

The logo in the inbox is a photo badge: it is not what grants access, it is what shows the identity was already verified beforehand. That is why no shortcut exists. When a customer sees the brand next to a message, what they are actually seeing is SPF, DKIM and DMARC working, translated into the only form an ordinary person can perceive.

How Zamak handles BIMI

Zamak Technologies treats BIMI as the closing of a body of work, not as a standalone item: first it takes the domain's DMARC to blocking with measurement, and only then prepares the logo, the certificate and the record, alongside the team that already looks after the brand and the domain. It is the same path applied to the domains Zamak uses to talk to the market. The email spoofing check shows in seconds whether your domain already sits on the rung the logo requires. Running that sequence is part of Managed Email Security and of Managed Cybersecurity in the Zamak Method.

Frequently asked questions about BIMI

Does BIMI make my email more secure?
Not on its own. It blocks nothing, filters nothing and prevents no message. The security comes from DMARC at a blocking policy, which is the prerequisite for the logo to appear at all. BIMI is the visible translation of that protection, and its value lies in recognition and trust, not in defense.
I published the record and the logo does not appear. Why?
The three most common causes are: DMARC is not at a blocking policy with full coverage, the logo file falls outside the required image profile, or the provider simply decided not to display it, which is its prerogative. Check in that order, because the first is by far the most frequent.
Do I really need a registered trademark?
For the most widely accepted certificate, yes. There is an alternative designed for established logos without a trademark registration, but provider support for it is narrower. If the mark is not yet registered, the decision is between starting the registration or accepting narrower reach for now.
Does the logo appear at every provider?
No. Each provider has its own criteria for when to show the image, and sending reputation weighs on that decision. That makes display a useful health indicator for the domain: when it disappears at one provider, there is usually something to fix.
Does it make sense to invest in BIMI before fixing the rest?
No, and the reverse order is not even possible. The standard checks the DMARC policy before anything else, so the logo is literally unreachable while authentication is not complete and in force. In practice, wanting the logo is usually what finally gives the authentication work the priority it needed.

Related terms