The shortest description of BIMI is “the technology that puts a logo next to your email.” That’s not wrong, but it’s incomplete. The logo a recipient sees is the last step in a longer chain: authenticated sending, DMARC enforcement, a published BIMI record, a compliant logo asset, often a mark certificate, and a mailbox provider choosing to support all of it. BIMI is the standardised connection between those layers — not a single switch that turns a logo on.
This guide covers what BIMI is, how it relates to SPF, DKIM, DMARC, VMC and CMC, and what it can and cannot do — not DNS syntax, SVG construction or certificate purchasing. See the BIMI implementation knowledge base for that.
What is BIMI?
BIMI—Brand Indicators for Message Identification—is an email specification that allows an organisation to publish a brand-controlled logo for possible display beside authenticated messages in supporting email clients. BIMI does not authenticate email by itself. It builds on aligned email authentication and enforcement-level DMARC, then gives participating mailbox providers a standardised way to retrieve and evaluate the organisation’s logo and, where required, its mark certificate.
BIMI connects an authenticated sending domain with a brand-controlled logo for display at participating mailbox providers. A successful deployment combines legitimate sender management, aligned SPF or DKIM, DMARC enforcement, a correctly published BIMI record, a compliant logo and, for many major mailbox experiences, a VMC or CMC. The strongest BIMI programs also assign ongoing ownership for DNS, hosted assets, certificate renewal, reputation and brand changes rather than treating the project as a one-time logo setup.
What BIMI Is — and What It Isn’t
BIMI touches authentication, DNS, design and certificates at once, so it’s often described inconsistently:
| BIMI is | BIMI is not |
|---|---|
| An email specification | A certificate |
| A DNS-published brand-identity mechanism | An authentication protocol |
| A bridge between authenticated sending and visible identity | A trademark registration |
| Dependent on mailbox-provider participation | A reputation score |
| Part of a broader authentication, certificate and hosting system | A deliverability product, a universal verification badge, a display guarantee, a phishing-prevention system, or a safety guarantee |
BIMI gives participating mailbox providers a standardised way to retrieve a logo published by an authenticated sending domain, so a brand’s visual identity can appear consistently once the underlying authentication, policy and — where required — certificate conditions are already in place. The purpose is coordination, not proof: BIMI does not itself decide whether a message is safe, and it does not force a mailbox provider to render anything.
The BIMI Identity Chain: Six Layers Behind a BIMI Logo Display
Explaining BIMI as a single DNS record understates how many layers have to hold at once for a logo to appear. VMCcerts calls these the BIMI Identity Chain. Every layer is necessary; none is sufficient alone.
Legitimate sending sources
An organisation needs an accurate inventory of everything that sends mail on its behalf — marketing, transactional, support and billing systems, plus any regional or subsidiary domains. An unmanaged sender can break alignment even when the primary platform is correctly configured. See DMARC Alone Isn’t Enough for BIMI and DMARC Services.
SPF and DKIM authentication
SPF authorises sending infrastructure for an envelope domain, while DKIM applies a cryptographic signature using a signing domain — together they provide the authentication signals DMARC needs. BIMI doesn’t replace either mechanism, and it doesn’t evaluate them itself; it depends on at least one aligned, passing result existing for DMARC and the mailbox provider to assess. See the BIMI implementation hub for configuration detail.
DMARC alignment and enforcement
DMARC evaluates whether a passing SPF or DKIM result aligns with the domain the recipient sees, then applies the domain owner’s published policy. BIMI requires DMARC at an enforcement level, not simply present — a monitor-only p=none policy is not enforcement, and this is a common reason a “configured” domain isn’t yet BIMI-ready. See Why DMARC Alone Isn’t Enough for BIMI and DMARC Services.
The BIMI DNS record
Published in DNS, pointing mailbox providers to the logo asset and, where required, the mark certificate. Selectors let an organisation run more than one configuration, but a wrong selector, a broken asset URL, or unreliable hosting will quietly prevent display even when every other layer is correct — a pattern documented further below. Full syntax lives in the BIMI setup guide.
Logo and mark validation
The logo has to meet BIMI’s asset requirements — most commonly the SVG Tiny PS profile. Some of the strongest provider experiences additionally require a VMC or CMC, validating the relationship between an organisation and the mark being displayed through different eligibility routes (see why trademark validation is required for a VMC). Both are certificates used within certain BIMI deployments, not BIMI itself.
Mailbox-provider evaluation and display
Each provider independently decides whether to support BIMI and what governs display — reputation, complaint rates, certificate validity, DNS configuration and policy can all factor in. Correct configuration makes display possible, not certain. See Gmail BIMI Verification Process and Microsoft 365 BIMI Support.
| Identity-chain layer | What it contributes | What must still be managed separately | Relevant VMCcerts resource |
|---|---|---|---|
| 1. Legitimate sending sources | An accurate map of who sends on the domain’s behalf | Sender inventory and governance | DMARC Services |
| 2. SPF and DKIM | Authorisation and message-integrity signals | Correct authentication and alignment | Getting Started with BIMI |
| 3. DMARC | Policy applied to aligned authentication results | Enforcement policy and reporting | Why DMARC Alone Isn’t Enough for BIMI |
| 4. BIMI DNS record | The published pointer to logo and certificate assets | DNS accuracy and reliable asset hosting | Getting Started with BIMI |
| 5. Logo and mark validation | A compliant asset and, where required, certificate-backed mark validation | Asset compliance and certificate eligibility | BIMI Certificates |
| 6. Mailbox-provider evaluation | The provider’s decision on whether and how to display the logo | Provider policy, reputation and display decisions | Gmail BIMI Verification Process |
How SPF, DKIM, DMARC, BIMI, VMC and CMC Fit Together
These six components are frequently conflated. The table below separates what each one actually is, its main role, and what it does not do.
| Component | What it is | Main role | What it does not do |
|---|---|---|---|
| SPF | Email-authentication mechanism for authorising sending infrastructure | Provides a passing SPF result for the envelope domain | Does not independently authenticate the visible From domain |
| DKIM | Cryptographic message-signing mechanism | Provides a verifiable signature tied to a signing domain | Does not independently prove the visible sender identity |
| DMARC | Authentication-alignment and policy protocol | Evaluates whether passing SPF or DKIM aligns with the visible From domain and applies policy | Does not display a logo or prevent every form of abuse |
| BIMI | Email specification and DNS-published brand-identity mechanism | Publishes logo information for mailbox-provider evaluation | Does not authenticate email or force display |
| VMC | Mark certificate commonly based on accepted mark evidence | Validates the organisation-logo-mark relationship under CA rules | Does not replace the BIMI record or authenticate the message |
| CMC | Mark certificate using an alternative evidence route centred on prior use and logo rights | Validates an eligible organisation-logo relationship where a qualifying VMC trademark route may not be available | Does not remove evidence requirements or guarantee provider display |
The practical hierarchy: BIMI is the specification that makes a logo eligible for evaluation. SPF and DKIM supply authentication signals; DMARC evaluates alignment and applies policy before a provider will consider the record at all. VMC and CMC validate the organisation’s relationship to the mark through different evidence routes — organisations with a qualifying trademark typically start with Verified Mark Certificate, while others check Common Mark Certificate eligibility. No pricing, CA comparison or eligibility detail here — compare BIMI certificate paths directly.
No. BIMI is a brand-identity and display specification, not an authentication protocol. SPF and DKIM provide authentication signals, while DMARC evaluates whether a passing authentication result aligns with the visible From domain and applies policy. The receiving mailbox provider evaluates those conditions before considering the BIMI record and deciding whether the logo is eligible for display.
Does BIMI Require a Certificate?
BIMI is conceptually distinct from any certificate — a domain can technically publish a record without one. Requirements vary by provider: some certificate-backed experiences require a VMC or CMC, and a bare record doesn’t guarantee display. Not every provider accepts both types, and requirements aren’t identical across providers, so confirm current target-provider requirements rather than assume one path applies everywhere. Review VMC and CMC certificate options against a specific provider.
BIMI does not universally require a VMC or CMC, but some major mailbox-provider experiences require a mark certificate. BIMI supplies the DNS-based logo-publishing mechanism, while a VMC or CMC validates the organisation’s relationship to the mark under the issuer’s rules. The practical certificate requirement depends on the mailbox providers and visual experience the organisation is targeting.
How Widely Is BIMI Actually Deployed?
| Industry | Detectable BIMI configurations | Dataset share |
|---|---|---|
| Technology/SaaS | 5,217 | 25.8% |
| Banking | 3,332 | 16.5% |
| Retail | 3,142 | 15.5% |
| Healthcare | 1,069 | 5.3% |
BIMI Industry Adoption Report 2026
Global BIMI Adoption Report 2026
(dataset v2026.2, snapshot 2026-07-02)
The Conceptual Order Behind a BIMI Deployment
Not a setup guide — no DNS syntax, certificate files or SVG source. Just the order these pieces typically fall into place, and why skipping steps tends to produce a published record with no visible logo.
Nine-step conceptual sequence
- Inventory legitimate sending sources across marketing, transactional and support mail.
- Establish aligned SPF and DKIM.
- Move DMARC to enforcement gradually, watching for legitimate mail caught in transition.
- Prepare a logo asset meeting BIMI’s format requirements.
- Determine whether a VMC or CMC is required for the target providers.
- Publish the BIMI DNS record once earlier steps are stable.
- Validate that logo and certificate files are reliably hosted and reachable.
- Test rendering across the providers that matter to the organisation.
- Monitor display and plan for certificate, DNS and asset continuity.
Logo preparation and certificate-evidence gathering are common sources of avoidable delay, particularly when begun only after authentication work is complete. Mechanics live in How to Get a Mark Certificate, the BIMI implementation hub, the BIMI Checker and the BIMI readiness assessment.
Why a Technically Valid Setup Can Still Not Display
The gap between “technically configured” and “actually displaying” is worth naming directly.
In one documented case, a consumer retail brand had an issued certificate and a published record, yet the logo wasn’t displaying. The cause wasn’t the certificate — a selector pointing to brand._bimi instead of the default, a non-compliant SVG, and a certificate file hosted somewhere unreachable. See the DNS selector and hosting correction scenario — BIMI failures are usually multi-layer configuration problems, not certificate problems.
Mark-validation has its own patterns: a registered word mark versus a stylised, figurative logo submitted for certification, resolved in the figurative trademark alignment scenario; a multi-domain organisation piecing together prior-use evidence across regional domains with different histories, in the multi-domain prior-use evidence scenario; and a renewal blocked by a logo on file that no longer matched the current asset, in the renewal logo-mismatch scenario.
How Widely Is BIMI Actually Deployed?
Adoption data answers “how common is this,” without implying anything about performance. The BIMI Industry Adoption Report 2026 (dataset v2026.2, snapshot 2026-07-02) identified approximately 5,217 Technology/SaaS domains with a detectable BIMI configuration, representing about 25.8% of the dataset. Domains with a detectable configuration also included around 3,332 Banking (16.5%), 3,142 Retail (15.5%) and 1,069 Healthcare (5.3%). The Global BIMI Adoption Report 2026 covers total tracked-domain counts across all industries.
Who Decides Whether a BIMI Logo Actually Appears?
Several parties each control part of the outcome, and none can force a result alone. The sender publishes and maintains the logo asset, DNS record and, where applicable, the certificate. The CA validates the mark, where used. The mailbox provider evaluates authentication and reputation history, certificate validity and its own display policy, then decides whether to render anything — the outcome can differ by provider, device, account and over time, even with a technically perfect record.
No. A valid, correctly published BIMI record is necessary but not sufficient. Mailbox providers evaluate authentication history, certificate validity where required, sender reputation and their own internal policy before deciding whether to render a logo, and that decision can vary by provider, account and time — even when the underlying record is technically correct.
What Business Problem Does BIMI Actually Address?
BIMI addresses a narrower problem than the marketing language around it sometimes suggests. High-volume customer-email senders often have a fragmented brand identity across sending systems, no visible link between authenticated mail and the brand customers recognise, inconsistent sender identity, no controlled way to publish a logo, and no cross-team process for governing the certificates and assets involved. BIMI addresses those gaps: a standardised, controlled path to publish a brand logo tied to authenticated sending, and a framework for the governance that keeps it working.
What it does not do matters equally: BIMI does not guarantee brand recognition, credibility, instant trust, engagement, competitive advantage, faster customer action, or the disappearance of phishing. It can support recognisability and consistent identity where displayed, but customer behaviour should be measured, not assumed.
BIMI Myths Versus What’s Actually True
| Myth | Reality |
|---|---|
| BIMI authenticates email | SPF, DKIM and DMARC provide the authentication foundation. Mailbox providers evaluate those results before considering the BIMI record. |
| BIMI is a certificate | BIMI is the specification; VMC and CMC are the certificates |
| Publishing a record forces display | Mailbox providers control whether and how a logo displays |
| One deployment covers every sender | Every sending stream needs to be inventoried and authenticated separately |
| Setup ends once the record is published | DNS, hosted files, certificates and reputation all require ongoing maintenance |
Who Tends to Be a Good Fit for BIMI?
A directional guide, not an automatic qualification — organisations that get real value from BIMI tend to share traits like:
- Customer-facing organisations with substantial authenticated email volume
- Brands using both marketing and transactional streams
- Organisations already at DMARC enforcement
- Multi-platform or multi-domain senders willing to govern the deployment
- Brands with an eligible VMC or CMC path
- Agencies managing authenticated email and brand identity for clients
Evaluate the certificate-backed BIMI route before choosing between VMC and CMC.
When BIMI Is Not the Immediate Next Step
Usually sequencing issues, not permanent disqualifications:
- Sending sources not inventoried
- SPF/DKIM alignment unstable
- DMARC still at
p=none - Logo not BIMI-ready
- Certificate path not yet established where required
- Hosting or DNS ownership unclear
- Rebrand underway
- No lifecycle and renewal owner
Each has a clear next step — see DMARC Services, the BIMI readiness assessment, or the BIMI without a trademark overview, depending on the gap.
Who Owns BIMI Inside the Organisation?
Easy to misunderstand as a marketing logo project — successful deployment requires security, DNS, legal, brand and lifecycle ownership working together.
| Function | What it owns |
|---|---|
| Email / Security | SPF, DKIM, DMARC, sending-domain inventory and ongoing monitoring |
| IT / DNS | The BIMI record, selectors, hosting and asset accessibility |
| Brand / Marketing | The approved logo, sender identity and visual consistency |
| Legal / Trademark | Mark ownership, permitted use and any changes to registered marks |
| Certificate owner | VMC or CMC application, deployment and renewal |
| Customer Experience | Consistency of identity across customer-critical messages |
| Procurement / Finance | Certificate subscription and renewal planning |
Measuring BIMI Without Overstating What It Did
Four categories give a realistic picture, not a single unproven ROI number.
Technical deployment
Is the record valid, the logo and certificate (where used) reachable and valid, authentication aligned, DMARC at enforcement, and the expected selectors actually being evaluated.
Exposure
Which providers the domain reaches, whether a seed test shows the logo, an estimate of supported audience share, and whether exposure has stayed continuous.
Operational health
Authentication failure rates, DNS drift, asset and certificate availability (including what happens when a VMC certificate expires), renewal continuity, and reputation trends.
Behavioural context
Clicks, conversions, support feedback, client-adjusted opens and complaint volume — context, not attributed BIMI performance.
Two cautions: behaviour can’t be attributed to BIMI automatically — before/after shows correlation, not causation. And open-rate measurement is affected by privacy features like Apple Mail’s Mail Privacy Protection, plus content and seasonality.
Is your domain technically ready for BIMI?
Start with the fundamentals: authentication alignment, DMARC enforcement level, and record readiness.
Frequently Asked Questions
What does BIMI stand for?
What is BIMI used for?
Is BIMI an email-authentication protocol?
Does BIMI require DMARC?
p=none. Current guidance generally expects p=quarantine or p=reject with full policy application — migration detail lives in Why DMARC Alone Isn't Enough for BIMI and DMARC Services.Does BIMI require a VMC or CMC?
What is the difference between BIMI and a VMC?
Why is my BIMI logo not showing?
Where to Go Next
| If you need to… | Go to |
|---|---|
| Understand BIMI certificate options | BIMI Certificates |
| Evaluate a VMC or CMC route | Verified Mark Certificate / Common Mark Certificate |
| Fix DMARC readiness | DMARC Services / Why DMARC Alone Isn’t Enough for BIMI |
| Learn the setup sequence | How to Get a Mark Certificate / Getting Started with BIMI |
| Check record and readiness | BIMI Checker / BIMI Readiness Assessment |
| Review Gmail and Microsoft support | Gmail BIMI Verification Process / Microsoft 365 BIMI Support |
| Diagnose a missing logo | Why Isn’t My BIMI Logo Showing? |
| Review certificate expiry and renewal | What Happens When a VMC Certificate Expires? |