Email Security 101 — a 4-part series. ← Part 1: Remove Yourself From Data Brokers · Part 2: What to Do After an Email Data Breach · Part 3: Types of Phishing Attacks. You’re on Part 4 — the finale.

The short version

  • BIMI puts a verified brand logo next to authenticated emails in Gmail, Apple Mail, and Yahoo — a visual “this really is who it says” for legitimate senders.
  • It’s a sender feature, not an inbox setting. You don’t turn BIMI on for yourself; brands set it up, which requires DMARC at full enforcement and a paid certificate.
  • For you, BIMI is a trust signal to recognise — not a guarantee. A verified logo is reassuring, but its absence doesn’t prove a scam, so it complements your other defences rather than replacing them.

So, what is BIMI, and does it actually matter to you? BIMI — Brand Indicators for Message Identification — is the email standard that makes a company’s logo appear next to its messages in your inbox, but only when that mail is genuinely authenticated. It’s the visible tip of the email-authentication iceberg we’ve been building toward across this series: the point where all the invisible plumbing of SPF, DKIM, and DMARC finally shows up as something you can see. This final part of Email Security 101 explains what BIMI is, how it works, what it looks like, who really needs it, and — just as importantly — what it can’t do.

What Is BIMI?

BIMI stands for Brand Indicators for Message Identification. In plain terms, it’s a way for an organisation to display its official logo right next to its emails in your inbox — the little brand icon you sometimes see beside a message from a big company. The whole point is trust: the logo only appears when the message has passed email authentication, so it acts as a visible badge that the mail really came from the domain it claims to.

Crucially, BIMI is not an anti-spam filter or an encryption tool. It’s a presentation standard maintained by the AuthIndicators Working Group (the BIMI Group) that sits on top of existing authentication. A sender publishes a small record in their domain’s DNS pointing to a hosted logo; when a supporting inbox provider receives an authenticated message from that domain, it looks up the record and shows the logo. If the mail isn’t authenticated, no logo appears. That simple rule — “logo only for verified mail” — is what turns a decorative icon into a security signal.

Why BIMI Exists: A Short History

To really grasp what BIMI is, it helps to know the problem it was invented to solve. For decades, the inbox gave you almost no reliable way to tell a genuine sender from an impostor. A message could claim to be from your bank, and short of inspecting raw headers, you had little to go on but the display name — which anyone can forge. The email world answered this with a stack of authentication standards: SPF to declare which servers may send for a domain, DKIM to cryptographically sign messages, and DMARC to tie the two together and tell receivers what to do with mail that fails. Powerful — but completely invisible to the person reading the email.

That invisibility was the gap BIMI set out to close. Introduced by the AuthIndicators Working Group in the early 2020s, its premise was simple: give brands a visible reward for doing authentication properly, and give recipients a visible cue they can actually use. If a domain had gone all the way to DMARC enforcement, it could now show its logo — and people would start to associate that logo with legitimacy, nudging more senders to authenticate. BIMI was as much about incentives as about icons.

The standard has kept evolving. Early on, displaying a logo required a Verified Mark Certificate tied to a registered trademark, which shut out any organisation without one. The arrival of the Common Mark Certificate in late 2024 loosened that requirement, and Gmail’s blue verified checkmark added a premium tier for trademark-backed senders. The trajectory is clear: what began as a big-brand experiment is slowly widening into something more of the ecosystem can use — even if, as we’ll see, it’s still far from universal. Understanding that arc is part of understanding what BIMI is: not a finished, everyone-gets-it feature, but an incentive scheme for better authentication that is still maturing.

How BIMI Works

BIMI is the last link in an authentication chain, so it only makes sense once you see what comes before it. The mechanism has four moving parts:

  • DMARC at enforcement comes first. Before BIMI does anything, the sender’s domain must pass DMARC with an enforcement policy — p=quarantine or p=reject covering all their mail. No enforcement, no BIMI. This is deliberate: BIMI won’t put a logo on mail unless the domain has already committed to blocking spoofed messages.
  • A specially formatted logo. The brand’s logo has to be a square SVG file in a specific profile (SVG Tiny PS), under about 32 KB, hosted over HTTPS. The tight format keeps the icon crisp at any size and hard to tamper with.
  • A BIMI DNS record. The sender publishes a small TXT record in their DNS that points to the logo file (and, usually, to a certificate — more on that below).
  • The inbox provider displays it. When a supporting provider receives an authenticated message from that domain, it reads the BIMI record and renders the logo beside the message.

The elegance is that BIMI reuses the authentication a well-run domain already has. If a company has done the hard work of getting to DMARC enforcement — which is genuinely the important security step — BIMI is the reward that makes that invisible work visible to recipients. It’s authentication you can finally see.

what is BIMI: a message passing SPF, DKIM, and DMARC checks before earning a verified brand badge
BIMI is the last link in the chain: a message passes SPF, DKIM, and DMARC first, and only then earns the verified logo you see in the inbox.

What BIMI Looks Like in Your Inbox

From your side, BIMI is subtle. On a supporting provider, an authenticated message from a BIMI-enabled brand shows the company’s round logo where an avatar or a grey initial would otherwise be. Support is now broad: Gmail, Apple Mail, Yahoo Mail, and Fastmail all render BIMI logos, which is why you’ve probably seen more brand icons in your inbox over the last couple of years without knowing why.

There’s one extra layer worth knowing about: the blue verified checkmark in Gmail. When a sender not only enables BIMI but backs it with a Verified Mark Certificate (tied to a registered trademark), Gmail shows a blue checkmark next to the logo — an even stronger “this is the real, trademark-verified brand” signal. A logo without the checkmark still means the mail is authenticated; the checkmark just adds a layer of trademark verification on top. Different providers set the bar differently, which is exactly what the certificate section below is about.

VMC vs CMC: The Two Certificates

Most inbox providers now want a sender to prove they’re entitled to the logo they’re displaying, and that proof comes as a mark certificate. There are two kinds, and the difference decides both the cost and whether you get that Gmail checkmark.

BIMI’s two mark certificates — VMC vs CMC — and what each gets you
VMC (Verified Mark Certificate)CMC (Common Mark Certificate)
Requires a registered trademark?YesNo — proof of ~12 months’ logo use
Gmail blue checkmark?YesNo (logo shows, no checkmark)
Logo displays in supporting inboxes?YesYes
Typical yearly cost~$650 (reseller) to ~$1,750~$1,500–3,000
Best forBrands with a trademark that want the checkmarkBrands without a registered trademark

The CMC is the newer option — introduced in late 2024 — and it opened BIMI up to organisations that don’t hold a registered trademark, which had been the biggest barrier. Provider rules vary: Gmail will display a logo with at least a CMC (and adds the checkmark only for a VMC), Yahoo will show a logo with no certificate at all, and Apple Mail requires a VMC. So the certificate you choose depends on which inboxes and which visual signals you’re aiming for.

What It Takes to Set Up BIMI

If you’re a sender considering BIMI, here’s the honest scope of the work, roughly in order:

  1. Get SPF and DKIM right for every source that sends mail as your domain — newsletters, support tools, transactional systems, the lot.
  2. Reach DMARC enforcement. Move your DMARC policy from monitoring (p=none) to p=quarantine or p=reject at 100%, without breaking legitimate mail. For most organisations this is the biggest and most valuable part of the whole project.
  3. Prepare the logo. Convert your logo to the required square SVG Tiny PS format, under 32 KB, and host it over HTTPS.
  4. Buy a certificate. Obtain a VMC (if you have a registered trademark and want the Gmail checkmark) or a CMC (if you don’t), from an approved certificate authority.
  5. Publish the BIMI DNS record pointing to your logo and certificate, then verify it renders in a supporting inbox.

Realistic effort is significant — commonly 10 to 40 hours of technical and admin work over several weeks, plus the annual certificate cost. Note that steps 1 and 2 are things every domain owner should do anyway for security; BIMI just gives you a visible payoff for finishing them. If you run a custom domain, that authentication groundwork also makes your everyday mail more trusted, with or without the logo.

Do You Need BIMI?

Here’s the honest answer, and it depends entirely on which side of the inbox you’re on.

As a regular person protecting your own inbox, no — BIMI isn’t something you set up, and there’s no toggle for it in your email app. It’s configured by the brands that send to you, not by you. What BIMI gives you as a recipient is a signal to recognise: when you see a verified logo (and especially a blue checkmark in Gmail), you can be a bit more confident the mail is genuinely from that brand and passed authentication. That’s useful, but it’s passive — you benefit from BIMI without doing anything.

As a business, organisation, or serious domain owner, possibly yes. BIMI is worth considering if a recognisable, trusted logo in the inbox has real value for you — it can lift brand recognition and, some senders find, engagement, and the blue checkmark is a strong legitimacy cue in a world of spoofing. But weigh it honestly: it costs money and effort, it only helps once you’re at DMARC enforcement, and it does nothing to stop the many scams that don’t impersonate your exact domain. For most small operations, getting to DMARC enforcement is the goal that matters; BIMI is an optional flourish on top.

What BIMI Can’t Do

BIMI is genuinely useful, but it’s easy to over-trust, so it’s worth being clear about its limits:

  • It doesn’t stop look-alike-domain phishing. BIMI authenticates your domain, but a scammer using a similar domain (a “cousin” domain) simply won’t have your logo — and won’t be blocked by your BIMI record either. The types of tricks in Part 3 on phishing attacks mostly don’t rely on spoofing your exact domain, so BIMI never touches them.
  • Absence of a logo doesn’t mean a scam. Plenty of legitimate senders — smaller businesses, individuals, anyone without the budget or trademark — will never show a BIMI logo. So “no logo” tells you almost nothing on its own; treating a missing logo as a red flag would flag most of your real mail.
  • It’s not encryption or privacy. BIMI does nothing to hide your address, stop tracking, or keep your mail confidential. It’s purely about verifying a sender’s identity to the recipient.
  • It’s costly and sender-side. The certificate and setup burden mean BIMI will always be a big-brand-first feature, not a universal one. It raises trust for the senders who can afford it, not the ecosystem as a whole.

None of this makes BIMI bad — it’s a solid trust signal when present. It just means BIMI is one narrow tool: helpful for confirming a known brand, useless for the broader flood of scams, tracking, and exposure that make up most of your real risk.

What Is BIMI Compared to SPF, DKIM, and DMARC?

Because BIMI is usually mentioned in the same breath as SPF, DKIM, and DMARC, it’s worth being precise about what is BIMI’s distinct job versus theirs. They form a stack, each doing exactly one thing, and BIMI sits on top of all of them:

  • SPF declares which mail servers are allowed to send for a domain.
  • DKIM attaches a cryptographic signature so a receiver can verify a message wasn’t tampered with and really came from the domain.
  • DMARC ties SPF and DKIM together, tells receivers what to do when a message fails (nothing, quarantine, or reject), and reports results back to the domain owner.
  • BIMI does none of that verifying itself — it’s the display layer that shows a logo once DMARC is already passing at enforcement.

So the honest one-line answer to what is BIMI in relation to the others is this: SPF, DKIM, and DMARC do the security work, and BIMI simply shows the result. That ordering matters, because it explains why BIMI can never be a shortcut — you can’t buy a logo to skip the authentication underneath it. A domain has to earn its way up the stack first, which is precisely why the valuable part of any BIMI project is the DMARC enforcement beneath the surface, not the icon on top.

It’s also why security professionals tend to be lukewarm on BIMI as a security measure while still recommending the work it depends on. Reaching DMARC enforcement genuinely reduces domain spoofing; adding a logo afterwards is mostly a branding and trust decision. If you ever hear BIMI described as “the last 5% that’s 95% marketing,” that’s the idea — the heavy lifting is the authentication, and the logo is the visible flourish that rewards it. Understanding what BIMI is really means understanding that split: valuable groundwork, optional decoration.

What Is BIMI’s Place in Your Email Security?

BIMI is the natural closing note for this series because it sits at the very top of the authentication stack — but it also shows the limit of what senders and standards can do for you. Authentication (SPF, DKIM, DMARC, BIMI) protects the identity of the sender’s domain. It’s essential infrastructure, and it’s why domain spoofing is harder than it used to be. But it can’t protect your address, contain a breach, or stop a look-alike scam — the risks that actually dominate everyday email.

That’s the gap your own habits fill, and it’s the thread running through all four parts of Email Security 101. You shrink your exposure by getting off data-broker lists (Part 1); you contain the damage when a service is breached (Part 2); you learn to spot the scams that authentication can’t stop (Part 3); and you read signals like BIMI for what they’re worth (Part 4). Tying it together is the single most practical habit: giving every service its own email alias, so your real address stays private, breaches stay contained, and any leak becomes traceable. Sender authentication and recipient hygiene are two halves of the same lock — BIMI is the half the brands do; aliasing is the half you do.

Final Thoughts: The Series in One Line

Across four parts, Email Security 101 has circled one idea from different angles: the strongest email security comes from limiting your exposure, not from any single feature. Data-broker cleanup, breach containment, phishing awareness, and authentication signals like BIMI each cover a slice of the problem — but none is a cure, and the ones that depend on big senders or paid certificates will never protect everyone. What ties them together, and what you can start today for free, is treating your real email address as something to protect rather than to spread. So the answer to “what is BIMI, and do you need it?” is: it’s a useful trust signal you’ll mostly just read, and the security that’s genuinely in your hands is the alias you give out instead of your real address. That’s where email security actually begins.

Frequently Asked Questions

What is BIMI in email?

BIMI stands for Brand Indicators for Message Identification. It’s an email standard that lets an organisation display its official logo next to its messages in your inbox — but only when the message has passed authentication. A sender publishes a record in their domain’s DNS pointing to a hosted logo, and supporting inbox providers show that logo on authenticated mail from the domain. It’s a trust-signalling presentation feature layered on top of SPF, DKIM, and DMARC, not a spam filter or an encryption tool.

How does BIMI work?

In four steps. First, the sender’s domain must pass DMARC at enforcement (a p=quarantine or p=reject policy covering all its mail) — without that, BIMI does nothing. Second, the brand prepares its logo as a square SVG Tiny PS file, under about 32 KB, hosted over HTTPS. Third, it publishes a BIMI DNS record pointing to the logo (and usually a certificate). Fourth, supporting inbox providers read that record and display the logo next to authenticated messages from the domain. BIMI reuses the authentication a well-run domain already has.

Which email providers support BIMI?

Support is now broad: Gmail, Apple Mail, Yahoo Mail, and Fastmail all render BIMI logos on authenticated mail, which is why brand icons have become more common in inboxes. The requirements differ, though — Gmail displays a logo with at least a Common Mark Certificate and adds a blue verified checkmark only for a Verified Mark Certificate; Yahoo shows a logo with no certificate at all; and Apple Mail requires a Verified Mark Certificate. So which inboxes show your logo depends on the certificate you use.

What is the difference between a VMC and a CMC?

Both are ‘mark certificates’ that prove a sender is entitled to the logo BIMI displays. A VMC (Verified Mark Certificate) requires a registered trademark and unlocks Gmail’s blue verified checkmark; it costs roughly $650 to $1,750 a year. A CMC (Common Mark Certificate), introduced in late 2024, doesn’t need a trademark — proof of about 12 months of logo use is enough — and it makes the logo appear in supporting inboxes but does not earn the blue checkmark. The CMC opened BIMI up to organisations without a registered trademark.

Do I need BIMI?

As an individual protecting your own inbox, no — BIMI isn’t something you set up; it’s configured by the brands that send to you. What it gives you as a recipient is a trust signal: a verified logo (and, in Gmail, a blue checkmark) means the mail is authenticated and genuinely from that brand. As a business or domain owner, BIMI can be worth it for brand recognition and the checkmark, but only after you’ve reached DMARC enforcement — which is the real security goal — and it costs money and effort. For most, DMARC enforcement matters far more than the logo.

Does BIMI stop phishing?

Only partially. BIMI helps confirm that mail genuinely came from a specific brand’s domain, so it makes exact-domain spoofing more visible. But it doesn’t stop the many scams that use look-alike ‘cousin’ domains — those simply won’t have your logo, and BIMI won’t block them. Just as important, most legitimate senders don’t have a BIMI logo, so the absence of one tells you almost nothing. Treat a verified logo as a reassuring ‘yes’ when it’s there, but never treat a missing logo as proof of a scam.

Is BIMI free to set up?

No. Beyond the technical work of reaching DMARC enforcement and formatting the logo, most inbox providers require a paid mark certificate to display it. A VMC runs roughly $650 to $1,750 per year, and a CMC typically $1,500 to $3,000 per year, on top of 10 to 40 hours of setup work. That cost is why BIMI is a big-brand-first feature rather than a universal one — it’s an optional flourish for senders who can justify it, layered on the free-to-implement authentication (SPF, DKIM, DMARC) that every domain should have anyway.

What’s the best email security step I can actually take?

Limit your exposure rather than relying on any single feature. Authentication signals like BIMI are configured by senders and only cover part of the risk, so the security that’s genuinely in your hands is recipient hygiene: get off data-broker lists, contain breaches, stay alert to phishing, and — the master move that ties it together — give every service its own email alias instead of your real address. That keeps your address private, contains any breach to one switch-off-able alias, and makes every leak traceable. It’s free, and it’s where practical email security begins.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.