What is BIMI (verified logo in the inbox)?
BIMI is the standard that makes a company's official logo appear next to its messages in the recipient's inbox. It does not add a new layer of security: it is the visible reward for having done everything else, because it is only displayed for domains that keep DMARC at enforcement, meaning a blocking policy. It is the only email authentication control the end customer actually sees, and therefore the one that best justifies the work behind the other three.
How BIMI works
BIMI, short for Brand Indicators for Message Identification, is the last link in a chain: it is only evaluated after the message has cleared all authentication and the domain's policy has proven to be in force. Without that, the logo simply does not appear.
Get DMARC to enforcement, with full coverage
The standard requires the policy to be at quarantine or reject, applied to every message. A domain in monitoring, or with partial application, does not get past this step.
Prepare the logo in the required format
The logo must sit in SVG Tiny PS, a restricted vector image profile created specifically for this use: solid background, square, no external elements. It is a simple conversion, but with strict rules.
Obtain the certificate proving your right to the mark
A certification authority verifies that the company genuinely holds rights to that logo and issues a certificate. The most widely accepted one requires a registered trademark; there is an alternative for unregistered logos, with narrower support.
Publish the record and providers display it
A text record in DNS points to the logo file and to the certificate. From there, each provider decides by its own criteria when to show the image.
Source: the implementation guide from BIMI Group, the body that maintains the standard, which defines the requirement of DMARC at enforcement with full coverage, the accepted image profile and the difference between certificate types.
What the logo does not buy
- It is not a protection layer. BIMI blocks nothing, filters nothing and prevents no message. It is the consequence of protection that already exists, and a domain without DMARC at blocking gains nothing by publishing the record.
- It does not guarantee display. Each provider applies its own criteria, which include sending reputation, and none commits to always showing the logo. Publishing is a necessary condition, not a sufficient one.
- The uncertified version has limited reach. It is possible to declare the logo without going through a certification authority, but support for that route is far narrower among providers.
- The trademark requirement is a real barrier. The most accepted certificate rests on a registered trademark, which involves cost and registration time. Check the status of the mark before promising the board a logo in the inbox.
The three routes to the logo
- Certificate on a registered trademark (VMC) The most widely accepted route. The certification authority validates the trademark registration and issues the certificate that accompanies the logo. It requires the mark to be genuinely registered.
- Certificate without a registered trademark (CMC) An alternative created for companies with an established logo they never registered as a trademark. Validation works differently and provider acceptance is narrower.
- Declaration with no certificate (self-asserted BIMI) Publishing the record pointing only at the logo file, with no external validation. It is the cheapest route and the one with the least reach, useful mainly as preparation.
- Beyond the three: the common prerequisite None of them works without DMARC at enforcement, and the requirement extends to subdomains: the standard asks for the same enforcement on the organizational domain and on the subdomain policy, with full coverage (pct=100) and no partial application. It is what it checks before anything else, and what most often fails domains that believe they are ready.
Why the logo is usually what unlocks the project
There is a useful irony in BIMI. SPF, DKIM and DMARC are invisible: they work without anyone noticing, and so they compete badly for budget and for board attention against any project that produces something visible. BIMI flips that, because it puts the company's brand in front of the customer, inside the inbox, next to messages that today show up with a generic initial. The practical effect is that the logo gives the authentication work a sponsor it usually lacks: whoever wants the brand in the inbox needs DMARC at enforcement first, and ends up defending the very project the technical team had already been asking for. The path always runs that way, never the reverse: there is no shortcut that delivers the image without the authentication work behind it. When someone pitches BIMI as a standalone brand improvement, the arithmetic does not add up: what is being bought is the end result of a complete rollout.
How to get the logo into the inbox
The sequence is rigid, because each stage depends on the previous one being provably complete:
- Confirm DMARC at blocking, not merely publishedBefore anything else, verify the policy is at quarantine or reject with full coverage. This is the stage that fails most domains, and none of the later ones compensates for its absence.
- Check the status of your trademarkIf the logo is registered as a trademark, the most accepted route is open. If it is not, decide between starting the registration or going the narrower alternative, knowing the limit.
- Prepare the file within the rulesConverting to the accepted format is quick, but the rules are strict about background, proportion and image content. A file outside the profile is a silent reason for non-display.
- Issue the certificate and publish the recordWith the certificate issued, publish the DNS record pointing to both the logo file and the certificate. From there, each provider decides when to display.
- Treat display as an indicator, not a deliverableTrack where the logo shows and where it does not. Absence usually points to sending reputation or a file outside the profile, and both are actionable.
In practice
The logo in the inbox is a photo badge: it is not what grants access, it is what shows the identity was already verified beforehand. That is why no shortcut exists. When a customer sees the brand next to a message, what they are actually seeing is SPF, DKIM and DMARC working, translated into the only form an ordinary person can perceive.
How Zamak handles BIMI
Zamak Technologies treats BIMI as the closing of a body of work, not as a standalone item: first it takes the domain's DMARC to blocking with measurement, and only then prepares the logo, the certificate and the record, alongside the team that already looks after the brand and the domain. It is the same path applied to the domains Zamak uses to talk to the market. The email spoofing check shows in seconds whether your domain already sits on the rung the logo requires. Running that sequence is part of Managed Email Security and of Managed Cybersecurity in the Zamak Method.