You've done the hard part. SPF is passing. DKIM is signing every message. DMARC is set to quarantine or reject, and spoofed mail bounces off your domain instead of landing in someone's inbox (see our step-by-step guide to preventing email spoofing if you haven't gotten there yet). On paper, your authentication is solid.
So why does your logo still not show up next to your emails in Gmail?
That's what BIMI is for, and it's a step almost no one takes, mostly because almost no one explains it clearly. Here's what it is, why it depends entirely on the authentication work you've already done, and how to set it up.
What Is BIMI?
BIMI stands for Brand Indicators for Message Identification. It's an email standard that lets your verified logo appear as the avatar next to your emails in supporting inboxes: Gmail, Yahoo, Apple Mail, and a growing list of others.
It doesn't change deliverability directly. What it changes is trust after the email lands. A recognizable logo next to your name is a visual signal that says "this is really us," which matters enormously when phishing and impersonation are the reason DMARC exists in the first place.
Why BIMI Doesn't Work Without DMARC Enforcement
This is the part that trips people up. BIMI is not a standalone setup, it's a reward layered on top of strict DMARC.
To even qualify for BIMI, your DMARC policy has to be set to p=quarantine or p=reject, not p=none. Mailbox providers won't display your logo for a domain that's only monitoring spoofing attempts instead of actively blocking them. The logic makes sense: showing a trusted logo next to mail from a domain that still lets spoofed messages through would defeat the entire purpose.
So if you're not at enforcement yet, BIMI isn't your next step. Getting DMARC to reject safely is. That usually means:
- Auditing every legitimate sending source (ESP, CRM, transactional tools, support platforms) so none of them get silently blocked
- Watching DMARC aggregate reports for a few weeks at p=none
- Moving to p=quarantine, confirming nothing legitimate is getting flagged
- Only then moving to p=reject
Our guide on how to prevent email spoofing walks through this authentication sequence in more detail.
What You Need to Implement BIMI
Once DMARC enforcement is stable, BIMI setup has three pieces:
- A qualifying SVG logo. BIMI requires a specific SVG Tiny Portable/Secure (SVG-P/S) format, not just any logo file. It needs to be square, centered, and validated against the BIMI spec.
- A BIMI DNS record. A TXT record at default._bimi.yourdomain.com pointing to the hosted logo URL.
- A VMC or CMC (for most inboxes that matter). Gmail requires a Verified Mark Certificate, essentially a trademark-backed certificate from an authorized certificate authority, before it will display your logo. Some providers accept the newer Common Mark Certificate instead. Without one of these, your BIMI record can be technically valid and your logo still won't show in the inboxes your recipients actually use.
Common Mistakes That Quietly Break BIMI
- Publishing BIMI before DMARC is at enforcement. The record will validate, but nothing will display.
- Using a logo that isn't proper SVG-P/S. A regular SVG export from design software usually fails validation silently.
- Letting DMARC alignment slip after BIMI is live. If a new sending tool gets added later and isn't properly authenticated, it can pull your domain out of alignment, and your logo disappears from inboxes without an obvious warning.
- Treating BIMI as a one-time setup. Like SPF and DKIM, it needs to be re-checked whenever your sending infrastructure changes.
Where List Hygiene Fits Into This
BIMI protects how your identity looks once an email is delivered. It doesn't do anything about whether that email gets delivered in the first place, and that's still decided upstream by your sender reputation, bounce rate, and spam complaint rate.
Domains with high bounce rates get throttled or filtered long before inbox providers even evaluate BIMI. That's the part that verifying every address before you send it protects against, catching invalid, disposable, and high-risk catch-all addresses so your DMARC and BIMI setup isn't undermined by a dirty list. It's the same reasoning behind why sender reputation recovery takes weeks, not hours: authentication and hygiene work together, not separately.
If your domain has taken a reputation hit already, our guides on checking your sender reputation, monitoring and removing blacklist listings, and cleaning your list before your next send are good next steps before layering BIMI on top.
FAQ
Does BIMI improve inbox placement?
Not directly. It's a trust and branding signal shown after a message is already deemed safe enough to deliver. Deliverability still comes down to authentication, reputation, and list quality.
Do I need a trademark to get a VMC?
Yes, in most cases. Verified Mark Certificates are tied to a registered trademark. This is the single biggest blocker for smaller companies trying to implement BIMI for Gmail specifically.
Will my logo show up everywhere once BIMI is set up?
No. Support varies by mailbox provider, and some don't require a VMC at all, so results differ across Gmail, Yahoo, and Apple Mail.
The Bottom Line
BIMI is the finishing move for a domain that's already doing authentication right, not a substitute for it. If SPF, DKIM, and DMARC enforcement are solid, BIMI is a relatively small lift with a real trust payoff. If they're not, it's worth fixing that first with a clean, verified list, because BIMI simply won't activate without it.
Start cleaning your list instantly.
No credit card required.
.jpg)
