Go back

BIMI what it is and how to configure it to display your logo in email

Every day we receive dozens of emails. Some come from legitimate companies. Others try to impersonate them.

That’s why email providers have been strengthening authentication systems for years to help distinguish genuine messages from fraudulent ones. In this context, BIMI emerges, a technology that allows displaying a brand’s verified logo directly in the inbox.

If you’re wondering what BIMI is and how to set it up, the quick answer is this: BIMI is a standard that allows your company’s logo to be displayed alongside your emails as long as your domain meets certain authentication requirements, especially DMARC.

In addition to enhancing brand image, it helps reinforce the trust of your recipients and provides an additional layer within a modern email authentication strategy.

What is BIMI

BIMI is a security and branding standard for email that allows companies to display their verified logo alongside the sender of an email.

The acronym BIMI stands for Brand Indicators for Message Identification. Its goal is to help users quickly identify that a message truly comes from the brand it claims to represent.

It’s important to understand that BIMI does not replace SPF, DKIM, or DMARC. In fact, it works on top of them. While these protocols verify the sender’s authenticity, BIMI adds a visual layer that allows the logo to be displayed in compatible emails.

What is BIMI used for

BIMI is used to improve a brand’s trust and visibility within the inbox.

Its main benefits are:

  • Improve brand recognition.
  • Reinforce recipient trust.
  • Facilitate the identification of legitimate emails.
  • Complement corporate email security strategies.
  • Differentiating your messages from other senders.

For companies conducting email marketing campaigns, newsletters, customer service, or frequent commercial communications, it can become an important competitive advantage.

How BIMI looks in practice

When BIMI is correctly configured, some email providers display the company’s logo next to the sender’s name.

For example, in Gmail or Yahoo Mail, it’s common to see the brand icon next to the received email when the domain meets all the required criteria.

However, the display depends on several factors:

  • Email client compatibility.
  • Correct BIMI configuration.
  • Domain reputation.
  • Existence of a VMC certificate when required.

For this reason, configuring BIMI correctly does not automatically guarantee that all users will see the logo.

How BIMI works

BIMI works as an additional validation layer based on prior email authentication.

The general process is as follows:

  1. The domain authenticates its messages via SPF and DKIM.
  2. DMARC verifies that the authentication is valid.
  3. The owner publishes a BIMI DNS record.
  4. The email provider queries that record.
  5. If the requirements are met, it displays the associated logo.

The key is that BIMI only comes into play when the sender’s identity has already been correctly validated.

Relationship between BIMI, SPF, DKIM, and DMARC

To understand BIMI, it’s important to clearly differentiate the various protocols.

  • SPF indicates which servers are authorized to send emails from a domain.
  • DKIM adds a cryptographic signature that allows verifying the integrity of the message.
  • DMARC defines what to do when SPF or DKIM fails and provides authentication reports.
  • BIMI uses that prior authentication to visually display the brand’s identity.

Therefore, when we talk about BIMI and DMARC, we must be clear that DMARC is the essential requirement on which BIMI is built.

Similarly, BIMI with DKIM and BIMI with SPF only works correctly when both mechanisms contribute to DMARC validating the message.

What role does DNS play in the configuration

BIMI is published via a TXT record within the domain’s DNS zone.

This record contains the necessary information to locate the logo and, optionally, the associated certificate.

Typically, the selector used is:

default._bimi.yourdomain.com

When a compatible provider receives an email, it queries this record to check the published configuration.

Requirements to configure BIMI

Before starting the configuration, it’s advisable to review several prerequisites.

Have SPF and DKIM well configured

SPF and DKIM are the foundation of any modern email authentication system.

Before considering how to configure BIMI, ensure that both records work correctly and do not present validation errors.

A poor prior configuration will prevent BIMI from ever working.

Additionally, email security is increasingly important.

Implement DMARC with a valid policy

DMARC is mandatory for BIMI.

In most cases, a policy like:

  • p=quarantine
  • p=reject

will be necessary to activate the display.

On the other hand, simply using:

  • p=none

will usually not be enough to display the logo in the email.

Prepare the logo in SVG Tiny PS format

One of the most common mistakes is assuming that any SVG works for BIMI.

It is not so.

The standard requires using SVG Tiny PS, a specific variant that meets certain technical restrictions.

Additionally, the file must:

  • Be square.
  • Have a transparent background.
  • Be correctly validated.
  • Maintain a reduced size.

Before publishing it, it’s advisable to verify the file with specialized tools.

Consider if you need a VMC certificate

A VMC Verified Mark Certificate officially certifies that the company owns both the brand and the logo used.

Some providers require this certificate to display the logo.

Others allow certain scenarios without VMC.

Therefore, it’s advisable to review the specific requirements of the email provider where you want your brand to appear.

How to configure BIMI step by step

Now, let’s see the complete process.

Step 1. Verify domain authentication

Before publishing BIMI:

  • Check SPF.
  • Check DKIM.
  • Check DMARC.
  • Verify that all messages pass validations correctly.

You can use DNS analysis tools and DMARC validators to confirm that everything works correctly.

Step 2. Publish an appropriate DMARC policy

A basic example could be:

v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com;

If you are still implementing DMARC, it may be advisable to first monitor the reports before progressively tightening the policy.

The logo must meet the SVG Tiny PS specifications.

Some good practices are:

  • Simple and recognizable design.
  • Good readability in small sizes.
  • Avoid excessive text.
  • Maintain consistency with corporate identity.

Remember that the goal is for users to recognize the brand at a glance.

Step 4. Host the SVG file on a secure URL

The file must be available via HTTPS.

Additionally:

  • It must be publicly accessible.
  • It should not require authentication.
  • It’s advisable to avoid unnecessary redirects.

For example:

https://www.yourdomain.com/logo-bimi.svg

Step 5. Add the BIMI record in DNS

A basic configuration would look like this:

Host: default._bimi.yourdomain.com
Type: TXT
Value: v=BIMI1; l=https://www.yourdomain.com/logo-bimi.svg;

If you use VMC, you should also add the corresponding reference to the certificate.

The specific syntax may vary slightly depending on the DNS provider used.

Step 6. Wait for propagation and validate the configuration

DNS changes need to propagate.

Depending on the TTL and the provider, this can take from a few minutes to several hours.

During this time, it’s advisable to validate:

  • The BIMI record.
  • The DMARC record.
  • The accessibility of the SVG.
  • The validity of the VMC certificate.

Once propagation is complete, conduct real tests by sending emails to different providers.

It’s important to remember that:

  • Not all clients support BIMI.
  • Some require VMC.
  • Domain reputation also influences.

Example of BIMI record

Let’s see two practical examples.

Basic example without VMC

Host: default._bimi.yourdomain.com

TXT:
v=BIMI1;
l=https://www.yourdomain.com/logo.svg;

Meaning of each parameter:

  • v= defines the BIMI version.
  • l= indicates the location of the logo.
  • default is the standard selector used by default.

Example with VMC

Host: default._bimi.yourdomain.com

TXT:
v=BIMI1;
l=https://www.yourdomain.com/logo.svg;
a=https://www.yourdomain.com/certificate.pem;

In this case:

  • a= references the VMC certificate.
  • The provider can validate both the logo and the ownership of the brand.

Advantages of using BIMI in your corporate email

Beyond the technical aspect, BIMI provides clear benefits for any business using professional email.

More brand visibility in the inbox

The logo makes it easier for users to quickly identify your company.

In crowded inboxes, this visual difference can make a big impact.

Greater recipient trust

Users are increasingly aware of the risks associated with phishing.

Seeing a validated logo generates a perception of greater legitimacy.

Reinforcement of email security strategy

BIMI does not prevent attacks by itself.

However, it perfectly complements authentication based on SPF, DKIM, and DMARC.

Better user experience and professional perception

SaaS companies, ecommerce, agencies, and digital businesses use BIMI to reinforce their brand image and convey greater professionalism.

Limitations and aspects to consider

It’s also important to know its limitations.

Not all email providers display it

Compatibility is still evolving.

Some providers offer full support, while others do not yet.

Having BIMI does not guarantee better deliverability on its own

BIMI does not replace good sending practices.

Domain reputation remains one of the most important factors.

VMC can add cost and complexity

For some companies, the certificate may be a justified investment.

For others, it may not provide enough value.

Poor DMARC configuration can affect legitimate email

Applying overly restrictive policies without first analyzing the reports can lead to rejections of valid emails.

Common errors when configuring BIMI

Publishing BIMI without having DMARC properly applied

It is the most common error.

Without DMARC correctly configured, BIMI will not work.

Using an incompatible SVG

Many standard SVG logos do not meet the SVG Tiny PS format.

Incorrectly entering the TXT record in DNS

A simple typographical error can invalidate the entire configuration.

Thinking the logo will be displayed immediately

DNS propagation and validations take time.

Not checking the reputation of the sending domain

Even if BIMI is correctly configured, a poor reputation can limit its effectiveness.

Comparative table: SPF, DKIM, DMARC, and BIMI

TechnologyMain functionMandatory for BIMI?
SPFAuthorize sending serversYes, indirectly
DKIMCryptographically sign messagesYes, indirectly
DMARCValidate authentication and define policiesYes, essential
BIMIDisplay the brand’s verified logoNot applicable

When it is worth implementing BIMI

Not all companies will derive the same benefit.

Companies with frequent corporate email

If you send:

  • Technical support.
  • Customer service.
  • Sales.
  • Billing.
  • Newsletters.

BIMI can quickly add value.

Brands that want to reinforce trust and recognition

Especially useful for ecommerce, fintech, SaaS, and digital businesses.

Organizations with a mature email security strategy

When SPF, DKIM, and DMARC are already under control, BIMI is usually the next logical step.

Conclusion

BIMI allows displaying the logo in email in a verified manner, helping to reinforce recipient trust and your brand’s visibility.

To implement it correctly, you need:

  • SPF configured.
  • DKIM configured.
  • DMARC in an appropriate protection mode.
  • A compatible logo.
  • In some cases, a VMC certificate.

If you already use professional email with your own domain, BIMI can be an excellent way to reinforce both your email branding and your security strategy.

Before activating it, review your DNS, validate your authentication configuration, and ensure that all technical requirements are correctly implemented.

Frequently asked questions about BIMI

What is BIMI in email?

BIMI is a standard that allows displaying a brand’s verified logo in authenticated emails, as long as the domain meets certain requirements like DMARC.

What do I need to configure BIMI?

You need to have SPF and DKIM correctly configured, a valid DMARC policy, and a compatible logo in SVG format. In some cases, a VMC certificate may also be required.

Does BIMI work without DMARC?

Not usually. DMARC is one of the key requirements for BIMI, and an enforcement policy like quarantine or reject is often required.

Does BIMI improve email deliverability?

Not directly. BIMI does not replace good sending practices, but it can improve recipient trust and reinforce domain authentication.

What format should the logo have for BIMI?

The logo must be in SVG Tiny PS format and meet specific technical specifications to be validated by compatible providers.

Do all email providers display BIMI?

No. The display of the logo depends on the email provider, its compatibility with BIMI, and whether the domain meets all necessary requirements.

What is a VMC certificate?

A VMC or Verified Mark Certificate is a digital certificate that validates the ownership of the logo and the brand. Some providers require it to display the logo with BIMI.

How long does it take for the BIMI logo to be visible?

It depends on DNS propagation, email provider validation, and meeting all requirements. It is not usually immediate.

We have solutions for everyone