What Is BIMI? How to Get Your Logo Next to Your Emails (2026)

July 29, 2026
What is BIMI hero image

Quick answer: BIMI (Brand Indicators for Message Identification) displays your verified brand logo beside authenticated emails in the inbox. To qualify you need DMARC at enforcement (p=quarantine or p=reject), your logo as an SVG Tiny P/S file, a BIMI DNS record, and — for Gmail and most providers — a Verified Mark Certificate proving you own the logo (BIMI Group).

You have seen it without knowing its name: a little brand logo sitting next to certain emails in Gmail or Apple Mail, instead of a grey initial. That is BIMI, and it is the visible reward for getting your email authentication right. Here is what it is, exactly what you need to earn it, and whether it is worth the cost.

Disclosure: Bluey Email, mentioned near the end, is my own product; it is discussed on the same terms as everything else here.

What is BIMI?

BIMI is a standard that lets brands show a validated logo next to their authenticated messages, driving trust in the inbox and giving recipients a fast visual cue that a message is genuinely from you. It is not an anti-spam tool in itself — it is a reward layer that sits on top of email authentication, which is why it only works once your DMARC is enforced. Google, Yahoo and Apple all support it. As Neil Kumaran, Product Lead for Gmail Anti-Abuse and vice-chair of the AuthIndicators Working Group, said when Google joined the effort, “We believe BIMI is promising and is heading in the right direction; we’re excited to be a part of crafting the future of the standard.”

What do you need to qualify?

Four things, and the order matters because the first is the gatekeeper:

  1. DMARC at enforcement. Your organizational domain must be at p=quarantine or p=reject, with no sp=none and pct=100. A monitoring-only DMARC policy (p=none) does not qualify.
  2. An SVG Tiny P/S logo. BIMI requires a specific square SVG profile — not a PNG or a standard SVG.
  3. A BIMI record in DNS. A TXT record that points to your logo and, where used, your certificate.
  4. A Verified Mark Certificate (for Gmail and most providers). This proves you own the logo.
Checklist infographic of the four BIMI requirements: 1. DMARC at enforcement, p=quarantine or p=reject with no sp=none and pct=100; 2. your logo as an SVG Tiny P/S file; 3. a BIMI record published in your DNS; 4. for Gmail and most inboxes, a Verified Mark Certificate (VMC or CMC). A note explains a VMC needs a registered trademark and is issued by DigiCert or Entrust. Source: BIMI Group.

VMC, CMC and self-asserted logos

There are three certificate paths, per the BIMI Group. A self-asserted logo is published without third-party verification; some providers such as Yahoo and AOL will display it, but Gmail will not. A Verified Mark Certificate (VMC) is issued by a Mark Verifying Authority after you prove a registered trademark for the logo — this is what Gmail requires. A newer Common Mark Certificate (CMC) covers logos that are not registered trademarks but have a history of legitimate use. VMCs and CMCs are currently issued by DigiCert and Entrust and are valid for up to 398 days.

Yahoo was an early mover here, and its results are part of why Google followed. Marcel Becker, then Director of Product Management at Verizon Media, said of Yahoo Mail’s BIMI beta: “We were able to provide better and more accurate brand logos as part of our consumer mail experience and BIMI clearly provided an incentive to accelerate the adoption of DMARC among those brands.” That last point is the strategic heart of BIMI — it gives brands a reason to finish their DMARC journey.

Is BIMI worth it?

It depends on your brand. The upside is real: a logo in the inbox is a trust and recognition signal, and Seth Blank, chair of the AuthIndicators Working Group at Valimail, frames the pilot as brands “deploying BIMI using VMC certificates” to measure exactly that impact. The cost is the friction: a VMC requires a registered trademark (a legal process with its own fees) plus an annual certificate cost, so it suits established brands more than a brand-new sender. But the prerequisite — getting to DMARC enforcement — is worth doing regardless of BIMI, because it is now a bulk-sending requirement at Google and Yahoo.

That prerequisite is where your sending platform helps. On Bluey Email I checked our own sending domains for this article: they run at DMARC p=quarantine with aligned authentication — the enforcement state BIMI needs — handled by the platform rather than by hand-edited DNS. Whatever tool you use, get authentication solid first; our SPF, DKIM and DMARC explainer, deliverability audit and deliverability guide cover the path, and BIMI is the logo you earn at the end of it.

Frequently asked questions

Does BIMI require DMARC? Yes, and at enforcement. Your domain must be at p=quarantine or p=reject with pct=100 and no sp=none — a p=none monitoring policy does not qualify.

Do I need a VMC for BIMI? For Gmail and most providers, yes — a Verified Mark Certificate (or the newer Common Mark Certificate) proves you own the logo. Some providers such as Yahoo and AOL will show a self-asserted logo without one.

How much does a VMC cost? There are two costs: registering a trademark for your logo (a legal process with its own fees) and the annual certificate from an authority such as DigiCert or Entrust. Certificates are valid up to 398 days.

Will BIMI improve my deliverability? Not directly — it is a display feature, not a filtering signal. But its prerequisite, DMARC enforcement, does protect your domain and is required for bulk senders, so the work behind BIMI helps.

References

  1. BIMI Group — Verified Mark Certificates (VMC) and BIMI: https://bimigroup.org/verified-mark-certificates-vmc-and-bimi/
  2. PRNewswire — Google Joins AuthIndicators Working Group and Commits to BIMI Pilot (Kumaran, Becker, Blank quotes): https://www.prnewswire.com/news-releases/google-joins-authindicators-working-group-and-commits-to-bimi-pilot-300890074.html

— Shivam

Leave a Comment