BIMI what it is and how to configure it to display your logo in email

Every day we receive dozens of emails. Some come from legitimate companies. Others try to impersonate them.
That’s why email providers have been strengthening authentication systems for years to help distinguish genuine messages from fraudulent ones. In this context, BIMI emerges, a technology that allows displaying a brand’s verified logo directly in the inbox.
If you’re wondering what BIMI is and how to set it up, the quick answer is this: BIMI is a standard that allows your company’s logo to be displayed alongside your emails as long as your domain meets certain authentication requirements, especially DMARC.
In addition to enhancing brand image, it helps reinforce the trust of your recipients and provides an additional layer within a modern email authentication strategy.
What is BIMI
BIMI is a security and branding standard for email that allows companies to display their verified logo alongside the sender of an email.
The acronym BIMI stands for Brand Indicators for Message Identification. Its goal is to help users quickly identify that a message truly comes from the brand it claims to represent.
It’s important to understand that BIMI does not replace SPF, DKIM, or DMARC. In fact, it works on top of them. While these protocols verify the sender’s authenticity, BIMI adds a visual layer that allows the logo to be displayed in compatible emails.
What is BIMI used for
BIMI is used to improve a brand’s trust and visibility within the inbox.
Its main benefits are:
- Improve brand recognition.
- Reinforce recipient trust.
- Facilitate the identification of legitimate emails.
- Complement corporate email security strategies.
- Differentiating your messages from other senders.
For companies conducting email marketing campaigns, newsletters, customer service, or frequent commercial communications, it can become an important competitive advantage.
How BIMI looks in practice
When BIMI is correctly configured, some email providers display the company’s logo next to the sender’s name.
For example, in Gmail or Yahoo Mail, it’s common to see the brand icon next to the received email when the domain meets all the required criteria.
However, the display depends on several factors:
- Email client compatibility.
- Correct BIMI configuration.
- Domain reputation.
- Existence of a VMC certificate when required.
For this reason, configuring BIMI correctly does not automatically guarantee that all users will see the logo.
How BIMI works
BIMI works as an additional validation layer based on prior email authentication.
The general process is as follows:
- The domain authenticates its messages via SPF and DKIM.
- DMARC verifies that the authentication is valid.
- The owner publishes a BIMI DNS record.
- The email provider queries that record.
- If the requirements are met, it displays the associated logo.
The key is that BIMI only comes into play when the sender’s identity has already been correctly validated.
Relationship between BIMI, SPF, DKIM, and DMARC
To understand BIMI, it’s important to clearly differentiate the various protocols.
- SPF indicates which servers are authorized to send emails from a domain.
- DKIM adds a cryptographic signature that allows verifying the integrity of the message.
- DMARC defines what to do when SPF or DKIM fails and provides authentication reports.
- BIMI uses that prior authentication to visually display the brand’s identity.
Therefore, when we talk about BIMI and DMARC, we must be clear that DMARC is the essential requirement on which BIMI is built.
Similarly, BIMI with DKIM and BIMI with SPF only works correctly when both mechanisms contribute to DMARC validating the message.
What role does DNS play in the configuration
BIMI is published via a TXT record within the domain’s DNS zone.
This record contains the necessary information to locate the logo and, optionally, the associated certificate.
Typically, the selector used is:
default._bimi.yourdomain.com
When a compatible provider receives an email, it queries this record to check the published configuration.
Requirements to configure BIMI
Before starting the configuration, it’s advisable to review several prerequisites.
Have SPF and DKIM well configured
SPF and DKIM are the foundation of any modern email authentication system.
Before considering how to configure BIMI, ensure that both records work correctly and do not present validation errors.
A poor prior configuration will prevent BIMI from ever working.
Additionally, email security is increasingly important.
Implement DMARC with a valid policy
DMARC is mandatory for BIMI.
In most cases, a policy like:
- p=quarantine
- p=reject
will be necessary to activate the display.
On the other hand, simply using:
- p=none
will usually not be enough to display the logo in the email.
Prepare the logo in SVG Tiny PS format
One of the most common mistakes is assuming that any SVG works for BIMI.
It is not so.
The standard requires using SVG Tiny PS, a specific variant that meets certain technical restrictions.
Additionally, the file must:
- Be square.
- Have a transparent background.
- Be correctly validated.
- Maintain a reduced size.
Before publishing it, it’s advisable to verify the file with specialized tools.
Consider if you need a VMC certificate
A VMC Verified Mark Certificate officially certifies that the company owns both the brand and the logo used.
Some providers require this certificate to display the logo.
Others allow certain scenarios without VMC.
Therefore, it’s advisable to review the specific requirements of the email provider where you want your brand to appear.
How to configure BIMI step by step
Now, let’s see the complete process.
Step 1. Verify domain authentication
Before publishing BIMI:
- Check SPF.
- Check DKIM.
- Check DMARC.
- Verify that all messages pass validations correctly.
You can use DNS analysis tools and DMARC validators to confirm that everything works correctly.
Step 2. Publish an appropriate DMARC policy
A basic example could be:
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com;If you are still implementing DMARC, it may be advisable to first monitor the reports before progressively tightening the policy.
Step 3. Create a BIMI-compatible logo
The logo must meet the SVG Tiny PS specifications.
Some good practices are:
- Simple and recognizable design.
- Good readability in small sizes.
- Avoid excessive text.
- Maintain consistency with corporate identity.
Remember that the goal is for users to recognize the brand at a glance.
Step 4. Host the SVG file on a secure URL
The file must be available via HTTPS.
Additionally:
- It must be publicly accessible.
- It should not require authentication.
- It’s advisable to avoid unnecessary redirects.
For example:
https://www.yourdomain.com/logo-bimi.svgStep 5. Add the BIMI record in DNS
A basic configuration would look like this:
Host: default._bimi.yourdomain.com
Type: TXT
Value: v=BIMI1; l=https://www.yourdomain.com/logo-bimi.svg;If you use VMC, you should also add the corresponding reference to the certificate.
The specific syntax may vary slightly depending on the DNS provider used.
Step 6. Wait for propagation and validate the configuration
DNS changes need to propagate.
Depending on the TTL and the provider, this can take from a few minutes to several hours.
During this time, it’s advisable to validate:
- The BIMI record.
- The DMARC record.
- The accessibility of the SVG.
- The validity of the VMC certificate.
Step 7. Check if compatible providers display the logo
Once propagation is complete, conduct real tests by sending emails to different providers.
It’s important to remember that:
- Not all clients support BIMI.
- Some require VMC.
- Domain reputation also influences.
Example of BIMI record
Let’s see two practical examples.
Basic example without VMC
Host: default._bimi.yourdomain.com
TXT:
v=BIMI1;
l=https://www.yourdomain.com/logo.svg;Meaning of each parameter:
- v= defines the BIMI version.
- l= indicates the location of the logo.
- default is the standard selector used by default.
Example with VMC
Host: default._bimi.yourdomain.com
TXT:
v=BIMI1;
l=https://www.yourdomain.com/logo.svg;
a=https://www.yourdomain.com/certificate.pem;In this case:
- a= references the VMC certificate.
- The provider can validate both the logo and the ownership of the brand.
Advantages of using BIMI in your corporate email
Beyond the technical aspect, BIMI provides clear benefits for any business using professional email.
More brand visibility in the inbox
The logo makes it easier for users to quickly identify your company.
In crowded inboxes, this visual difference can make a big impact.
Greater recipient trust
Users are increasingly aware of the risks associated with phishing.
Seeing a validated logo generates a perception of greater legitimacy.
Reinforcement of email security strategy
BIMI does not prevent attacks by itself.
However, it perfectly complements authentication based on SPF, DKIM, and DMARC.
Better user experience and professional perception
SaaS companies, ecommerce, agencies, and digital businesses use BIMI to reinforce their brand image and convey greater professionalism.
Limitations and aspects to consider
It’s also important to know its limitations.
Not all email providers display it
Compatibility is still evolving.
Some providers offer full support, while others do not yet.
Having BIMI does not guarantee better deliverability on its own
BIMI does not replace good sending practices.
Domain reputation remains one of the most important factors.
VMC can add cost and complexity
For some companies, the certificate may be a justified investment.
For others, it may not provide enough value.
Poor DMARC configuration can affect legitimate email
Applying overly restrictive policies without first analyzing the reports can lead to rejections of valid emails.
Common errors when configuring BIMI
Publishing BIMI without having DMARC properly applied
It is the most common error.
Without DMARC correctly configured, BIMI will not work.
Using an incompatible SVG
Many standard SVG logos do not meet the SVG Tiny PS format.
Incorrectly entering the TXT record in DNS
A simple typographical error can invalidate the entire configuration.
Thinking the logo will be displayed immediately
DNS propagation and validations take time.
Not checking the reputation of the sending domain
Even if BIMI is correctly configured, a poor reputation can limit its effectiveness.
Comparative table: SPF, DKIM, DMARC, and BIMI
| Technology | Main function | Mandatory for BIMI? |
|---|---|---|
| SPF | Authorize sending servers | Yes, indirectly |
| DKIM | Cryptographically sign messages | Yes, indirectly |
| DMARC | Validate authentication and define policies | Yes, essential |
| BIMI | Display the brand’s verified logo | Not applicable |
When it is worth implementing BIMI
Not all companies will derive the same benefit.
Companies with frequent corporate email
If you send:
- Technical support.
- Customer service.
- Sales.
- Billing.
- Newsletters.
BIMI can quickly add value.
Brands that want to reinforce trust and recognition
Especially useful for ecommerce, fintech, SaaS, and digital businesses.
Organizations with a mature email security strategy
When SPF, DKIM, and DMARC are already under control, BIMI is usually the next logical step.
Conclusion
BIMI allows displaying the logo in email in a verified manner, helping to reinforce recipient trust and your brand’s visibility.
To implement it correctly, you need:
- SPF configured.
- DKIM configured.
- DMARC in an appropriate protection mode.
- A compatible logo.
- In some cases, a VMC certificate.
If you already use professional email with your own domain, BIMI can be an excellent way to reinforce both your email branding and your security strategy.
Before activating it, review your DNS, validate your authentication configuration, and ensure that all technical requirements are correctly implemented.
Frequently asked questions about BIMI
What is BIMI in email?
BIMI is a standard that allows displaying a brand’s verified logo in authenticated emails, as long as the domain meets certain requirements like DMARC.
What do I need to configure BIMI?
You need to have SPF and DKIM correctly configured, a valid DMARC policy, and a compatible logo in SVG format. In some cases, a VMC certificate may also be required.
Does BIMI work without DMARC?
Not usually. DMARC is one of the key requirements for BIMI, and an enforcement policy like quarantine or reject is often required.
Does BIMI improve email deliverability?
Not directly. BIMI does not replace good sending practices, but it can improve recipient trust and reinforce domain authentication.
What format should the logo have for BIMI?
The logo must be in SVG Tiny PS format and meet specific technical specifications to be validated by compatible providers.
Do all email providers display BIMI?
No. The display of the logo depends on the email provider, its compatibility with BIMI, and whether the domain meets all necessary requirements.
What is a VMC certificate?
A VMC or Verified Mark Certificate is a digital certificate that validates the ownership of the logo and the brand. Some providers require it to display the logo with BIMI.
How long does it take for the BIMI logo to be visible?
It depends on DNS propagation, email provider validation, and meeting all requirements. It is not usually immediate.