{"id":482,"date":"2026-09-25T04:38:39","date_gmt":"2026-09-24T23:08:39","guid":{"rendered":"https:\/\/emailalias.io\/blog\/?p=482"},"modified":"2026-09-25T04:40:34","modified_gmt":"2026-09-24T23:10:34","slug":"what-is-bimi","status":"publish","type":"post","link":"https:\/\/emailalias.io\/blog\/what-is-bimi\/","title":{"rendered":"Email Security 101 (Part 4): What Is BIMI and Do You Need It?"},"content":{"rendered":"<p class=\"series-nav\"><em>Email Security 101 \u2014 a 4-part series. \u2190 Part 1: <a href=\"https:\/\/emailalias.io\/blog\/remove-yourself-from-data-brokers\/\">Remove Yourself From Data Brokers<\/a> \u00b7 Part 2: <a href=\"https:\/\/emailalias.io\/blog\/email-data-breach-what-to-do\/\">What to Do After an Email Data Breach<\/a> \u00b7 Part 3: <a href=\"https:\/\/emailalias.io\/blog\/types-of-phishing-attacks\/\">Types of Phishing Attacks<\/a>. You&#8217;re on Part 4 \u2014 the finale.<\/em><\/p>\n\n<div class=\"post-tldr\">\n  <p class=\"post-tldr__title\">The short version<\/p>\n  <ul>\n    <li><strong>BIMI puts a verified brand logo next to authenticated emails<\/strong> in Gmail, Apple Mail, and Yahoo \u2014 a visual &#8220;this really is who it says&#8221; for legitimate senders.<\/li>\n    <li><strong>It&#8217;s a sender feature, not an inbox setting.<\/strong> You don&#8217;t turn BIMI on for yourself; brands set it up, which requires DMARC at full enforcement and a paid certificate.<\/li>\n    <li><strong>For you, BIMI is a trust signal to recognise \u2014 not a guarantee.<\/strong> A verified logo is reassuring, but its absence doesn&#8217;t prove a scam, so it complements your other defences rather than replacing them.<\/li>\n  <\/ul>\n<\/div>\n\n<p>So, what is BIMI, and does it actually matter to you? BIMI \u2014 Brand Indicators for Message Identification \u2014 is the email standard that makes a company&#8217;s logo appear next to its messages in your inbox, but only when that mail is genuinely authenticated. It&#8217;s the visible tip of the email-authentication iceberg we&#8217;ve been building toward across this series: the point where all the invisible plumbing of SPF, DKIM, and DMARC finally shows up as something you can see. This final part of Email Security 101 explains what BIMI is, how it works, what it looks like, who really needs it, and \u2014 just as importantly \u2014 what it can&#8217;t do.<\/p>\n\n<nav class=\"post-toc\" aria-label=\"Table of contents\">\n  <h2 class=\"post-toc__title\">Table of contents<\/h2>\n  <ol class=\"post-toc__list\">\n    <li><a href=\"#what\">What is BIMI?<\/a><\/li>\n    <li><a href=\"#history\">Why BIMI exists: a short history<\/a><\/li>\n    <li><a href=\"#how\">How BIMI works<\/a><\/li>\n    <li><a href=\"#inbox\">What BIMI looks like in your inbox<\/a><\/li>\n    <li><a href=\"#vmc-cmc\">VMC vs CMC: the two certificates<\/a><\/li>\n    <li><a href=\"#setup\">What it takes to set up BIMI<\/a><\/li>\n    <li><a href=\"#need\">Do you need BIMI?<\/a><\/li>\n    <li><a href=\"#limits\">What BIMI can&#8217;t do<\/a><\/li>\n    <li><a href=\"#stack\">What is BIMI compared to SPF, DKIM, and DMARC?<\/a><\/li>\n    <li><a href=\"#fit\">What is BIMI&#8217;s place in your email security?<\/a><\/li>\n    <li><a href=\"#final-thoughts\">Final thoughts: the series in one line<\/a><\/li>\n    <li><a href=\"#faq\">Frequently asked questions<\/a><\/li>\n  <\/ol>\n<\/nav>\n\n<h2 id=\"what\">What Is BIMI?<\/h2>\n<p>BIMI stands for <strong>Brand Indicators for Message Identification<\/strong>. In plain terms, it&#8217;s a way for an organisation to display its official logo right next to its emails in your inbox \u2014 the little brand icon you sometimes see beside a message from a big company. The whole point is trust: the logo only appears when the message has passed <a href=\"https:\/\/en.wikipedia.org\/wiki\/Email_authentication\" rel=\"noopener\" target=\"_blank\">email authentication<\/a>, so it acts as a visible badge that the mail really came from the domain it claims to.<\/p>\n<p>Crucially, BIMI is not an anti-spam filter or an encryption tool. It&#8217;s a <em>presentation<\/em> standard maintained by the <a href=\"https:\/\/bimigroup.org\/\" rel=\"noopener\" target=\"_blank\">AuthIndicators Working Group (the BIMI Group)<\/a> that sits on top of existing authentication. A sender publishes a small record in their domain&#8217;s DNS pointing to a hosted logo; when a supporting inbox provider receives an authenticated message from that domain, it looks up the record and shows the logo. If the mail isn&#8217;t authenticated, no logo appears. That simple rule \u2014 &#8220;logo only for verified mail&#8221; \u2014 is what turns a decorative icon into a security signal.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> BIMI (Brand Indicators for Message Identification) displays a sender&#8217;s official logo next to their emails, but only when the message passes authentication. It&#8217;s a trust-signalling presentation standard layered on top of SPF, DKIM, and DMARC \u2014 not a filter or an encryption tool.<\/aside>\n\n<h2 id=\"history\">Why BIMI Exists: A Short History<\/h2>\n<p>To really grasp what BIMI is, it helps to know the problem it was invented to solve. For decades, the inbox gave you almost no reliable way to tell a genuine sender from an impostor. A message could claim to be from your bank, and short of inspecting raw headers, you had little to go on but the display name \u2014 which anyone can forge. The email world answered this with a stack of authentication standards: <a href=\"https:\/\/en.wikipedia.org\/wiki\/Sender_Policy_Framework\" rel=\"noopener\" target=\"_blank\">SPF<\/a> to declare which servers may send for a domain, <a href=\"https:\/\/en.wikipedia.org\/wiki\/DomainKeys_Identified_Mail\" rel=\"noopener\" target=\"_blank\">DKIM<\/a> to cryptographically sign messages, and DMARC to tie the two together and tell receivers what to do with mail that fails. Powerful \u2014 but completely invisible to the person reading the email.<\/p>\n<p>That invisibility was the gap BIMI set out to close. Introduced by the AuthIndicators Working Group in the early 2020s, its premise was simple: give brands a visible reward for doing authentication properly, and give recipients a visible cue they can actually use. If a domain had gone all the way to DMARC enforcement, it could now show its logo \u2014 and people would start to associate that logo with legitimacy, nudging more senders to authenticate. BIMI was as much about incentives as about icons.<\/p>\n<p>The standard has kept evolving. Early on, displaying a logo required a Verified Mark Certificate tied to a registered trademark, which shut out any organisation without one. The arrival of the Common Mark Certificate in late 2024 loosened that requirement, and Gmail&#8217;s blue verified checkmark added a premium tier for trademark-backed senders. The trajectory is clear: what began as a big-brand experiment is slowly widening into something more of the ecosystem can use \u2014 even if, as we&#8217;ll see, it&#8217;s still far from universal. Understanding that arc is part of understanding what BIMI is: not a finished, everyone-gets-it feature, but an incentive scheme for better authentication that is still maturing.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> BIMI exists to make invisible email authentication visible. SPF, DKIM, and DMARC verify senders behind the scenes; BIMI rewards domains that reach DMARC enforcement with a logo recipients can see, nudging more senders to authenticate. The 2024 Common Mark Certificate widened access beyond trademark holders, but it&#8217;s still maturing.<\/aside>\n\n<h2 id=\"how\">How BIMI Works<\/h2>\n<p>BIMI is the last link in an authentication chain, so it only makes sense once you see what comes before it. The mechanism has four moving parts:<\/p>\n<ul>\n  <li><strong>DMARC at enforcement comes first.<\/strong> Before BIMI does anything, the sender&#8217;s domain must pass <a href=\"https:\/\/emailalias.io\/blog\/what-is-dmarc\/\" rel=\"noopener\" target=\"_blank\">DMARC<\/a> with an enforcement policy \u2014 <code>p=quarantine<\/code> or <code>p=reject<\/code> covering all their mail. No enforcement, no BIMI. This is deliberate: BIMI won&#8217;t put a logo on mail unless the domain has already committed to blocking spoofed messages.<\/li>\n  <li><strong>A specially formatted logo.<\/strong> The brand&#8217;s logo has to be a square <a href=\"https:\/\/en.wikipedia.org\/wiki\/Scalable_Vector_Graphics\" rel=\"noopener\" target=\"_blank\">SVG<\/a> file in a specific profile (SVG Tiny PS), under about 32 KB, hosted over HTTPS. The tight format keeps the icon crisp at any size and hard to tamper with.<\/li>\n  <li><strong>A BIMI DNS record.<\/strong> The sender publishes a small TXT record in their DNS that points to the logo file (and, usually, to a certificate \u2014 more on that below).<\/li>\n  <li><strong>The inbox provider displays it.<\/strong> When a supporting provider receives an authenticated message from that domain, it reads the BIMI record and renders the logo beside the message.<\/li>\n<\/ul>\n<p>The elegance is that BIMI reuses the authentication a well-run domain already has. If a company has done the hard work of getting to DMARC enforcement \u2014 which is genuinely the important security step \u2014 BIMI is the reward that makes that invisible work visible to recipients. It&#8217;s authentication you can finally see.<\/p>\n\n<figure class=\"wp-block-image size-large\">\n  <img data-recalc-dims=\"1\" src=\"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/what-is-bimi-example.jpg?resize=1080%2C608&#038;ssl=1\"\n       alt=\"what is BIMI: a message passing SPF, DKIM, and DMARC checks before earning a verified brand badge\"\n       width=\"1080\" height=\"608\" loading=\"lazy\" decoding=\"async\" \/>\n  <figcaption>BIMI is the last link in the chain: a message passes SPF, DKIM, and DMARC first, and only then earns the verified logo you see in the inbox.<\/figcaption>\n<\/figure>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> BIMI works in four steps: the domain must first pass DMARC at enforcement (p=quarantine or p=reject), publish a square SVG logo hosted over HTTPS, add a BIMI DNS record pointing to it, and then supporting inboxes display the logo on authenticated mail. It&#8217;s a visible reward for authentication a domain already does.<\/aside>\n\n<h2 id=\"inbox\">What BIMI Looks Like in Your Inbox<\/h2>\n<p>From your side, BIMI is subtle. On a supporting provider, an authenticated message from a BIMI-enabled brand shows the company&#8217;s round logo where an avatar or a grey initial would otherwise be. Support is now broad: Gmail, Apple Mail, Yahoo Mail, and Fastmail all render BIMI logos, which is why you&#8217;ve probably seen more brand icons in your inbox over the last couple of years without knowing why.<\/p>\n<p>There&#8217;s one extra layer worth knowing about: the <strong>blue verified checkmark<\/strong> in <a href=\"https:\/\/support.google.com\/a\/answer\/10911320\" rel=\"noopener\" target=\"_blank\">Gmail<\/a>. When a sender not only enables BIMI but backs it with a Verified Mark Certificate (tied to a registered trademark), Gmail shows a blue checkmark next to the logo \u2014 an even stronger &#8220;this is the real, trademark-verified brand&#8221; signal. A logo without the checkmark still means the mail is authenticated; the checkmark just adds a layer of trademark verification on top. Different providers set the bar differently, which is exactly what the certificate section below is about.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> On Gmail, Apple Mail, Yahoo, and Fastmail, BIMI shows a brand&#8217;s logo where an avatar would normally sit. In Gmail, a sender who backs BIMI with a Verified Mark Certificate also earns a blue verified checkmark \u2014 an added trademark-verification signal on top of the logo.<\/aside>\n\n<h2 id=\"vmc-cmc\">VMC vs CMC: The Two Certificates<\/h2>\n<p>Most inbox providers now want a sender to prove they&#8217;re entitled to the logo they&#8217;re displaying, and that proof comes as a mark certificate. There are two kinds, and the difference decides both the cost and whether you get that Gmail checkmark.<\/p>\n\n<figure class=\"wp-block-table\"><table><caption>BIMI&#8217;s two mark certificates \u2014 VMC vs CMC \u2014 and what each gets you<\/caption>\n  <thead>\n    <tr><th><\/th><th>VMC (Verified Mark Certificate)<\/th><th>CMC (Common Mark Certificate)<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Requires a registered trademark?<\/td><td>Yes<\/td><td>No \u2014 proof of ~12 months&#8217; logo use<\/td><\/tr>\n    <tr><td>Gmail blue checkmark?<\/td><td>Yes<\/td><td>No (logo shows, no checkmark)<\/td><\/tr>\n    <tr><td>Logo displays in supporting inboxes?<\/td><td>Yes<\/td><td>Yes<\/td><\/tr>\n    <tr><td>Typical yearly cost<\/td><td>~$650 (reseller) to ~$1,750<\/td><td>~$1,500\u20133,000<\/td><\/tr>\n    <tr><td>Best for<\/td><td>Brands with a trademark that want the checkmark<\/td><td>Brands without a registered trademark<\/td><\/tr>\n  <\/tbody>\n<\/table><\/figure>\n\n<p>The CMC is the newer option \u2014 introduced in late 2024 \u2014 and it opened BIMI up to organisations that don&#8217;t hold a registered trademark, which had been the biggest barrier. Provider rules vary: Gmail will display a logo with at least a CMC (and adds the checkmark only for a VMC), Yahoo will show a logo with no certificate at all, and Apple Mail requires a VMC. So the certificate you choose depends on which inboxes and which visual signals you&#8217;re aiming for.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> A VMC needs a registered trademark and unlocks Gmail&#8217;s blue checkmark; the newer CMC needs only proof of logo use but shows no checkmark. Gmail accepts either (checkmark for VMC only), Yahoo needs no certificate, and Apple Mail requires a VMC \u2014 so the right choice depends on your trademark status and target inboxes.<\/aside>\n\n<h2 id=\"setup\">What It Takes to Set Up BIMI<\/h2>\n<p>If you&#8217;re a sender considering BIMI, here&#8217;s the honest scope of the work, roughly in order:<\/p>\n<ol>\n  <li><strong>Get SPF and DKIM right<\/strong> for every source that sends mail as your domain \u2014 newsletters, support tools, transactional systems, the lot.<\/li>\n  <li><strong>Reach DMARC enforcement.<\/strong> Move your DMARC policy from monitoring (<code>p=none<\/code>) to <code>p=quarantine<\/code> or <code>p=reject<\/code> at 100%, without breaking legitimate mail. For most organisations this is the biggest and most valuable part of the whole project.<\/li>\n  <li><strong>Prepare the logo.<\/strong> Convert your logo to the required square SVG Tiny PS format, under 32 KB, and host it over HTTPS.<\/li>\n  <li><strong>Buy a certificate.<\/strong> Obtain a VMC (if you have a registered trademark and want the Gmail checkmark) or a CMC (if you don&#8217;t), from an approved certificate authority.<\/li>\n  <li><strong>Publish the BIMI DNS record<\/strong> pointing to your logo and certificate, then verify it renders in a supporting inbox.<\/li>\n<\/ol>\n<p>Realistic effort is significant \u2014 commonly 10 to 40 hours of technical and admin work over several weeks, plus the annual certificate cost. Note that steps 1 and 2 are things every domain owner should do anyway for security; BIMI just gives you a visible payoff for finishing them. If you run a <a href=\"https:\/\/emailalias.io\/blog\/custom-domain-email-alias\/\" rel=\"noopener\" target=\"_blank\">custom domain<\/a>, that authentication groundwork also makes your everyday mail more trusted, with or without the logo.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> Setting up BIMI means getting SPF\/DKIM right, reaching DMARC enforcement, preparing a square SVG logo, buying a VMC or CMC, and publishing a DNS record \u2014 commonly 10\u201340 hours plus an annual certificate cost. The DMARC-enforcement step is the real security win; BIMI is the visible reward.<\/aside>\n\n<h2 id=\"need\">Do You Need BIMI?<\/h2>\n<p>Here&#8217;s the honest answer, and it depends entirely on which side of the inbox you&#8217;re on.<\/p>\n<p><strong>As a regular person protecting your own inbox, no<\/strong> \u2014 BIMI isn&#8217;t something you set up, and there&#8217;s no toggle for it in your email app. It&#8217;s configured by the brands that send <em>to<\/em> you, not by you. What BIMI gives you as a recipient is a signal to recognise: when you see a verified logo (and especially a blue checkmark in Gmail), you can be a bit more confident the mail is genuinely from that brand and passed authentication. That&#8217;s useful, but it&#8217;s passive \u2014 you benefit from BIMI without doing anything.<\/p>\n<p><strong>As a business, organisation, or serious domain owner, possibly yes.<\/strong> BIMI is worth considering if a recognisable, trusted logo in the inbox has real value for you \u2014 it can lift brand recognition and, some senders find, engagement, and the blue checkmark is a strong legitimacy cue in a world of <a href=\"https:\/\/emailalias.io\/blog\/what-is-email-spoofing\/\" rel=\"noopener\" target=\"_blank\">spoofing<\/a>. But weigh it honestly: it costs money and effort, it only helps once you&#8217;re at DMARC enforcement, and it does nothing to stop the many scams that don&#8217;t impersonate your exact domain. For most small operations, getting to DMARC enforcement is the goal that matters; BIMI is an optional flourish on top.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> As an individual, you don&#8217;t set up BIMI \u2014 you just read it as a trust signal on incoming mail. As a business or domain owner, it can be worth it for brand trust and the Gmail checkmark, but only after DMARC enforcement, which is the real security goal; BIMI is an optional payoff on top.<\/aside>\n\n<h2 id=\"limits\">What BIMI Can&#8217;t Do<\/h2>\n<p>BIMI is genuinely useful, but it&#8217;s easy to over-trust, so it&#8217;s worth being clear about its limits:<\/p>\n<ul>\n  <li><strong>It doesn&#8217;t stop look-alike-domain phishing.<\/strong> BIMI authenticates <em>your<\/em> domain, but a scammer using a similar domain (a &#8220;cousin&#8221; domain) simply won&#8217;t have your logo \u2014 and won&#8217;t be blocked by your BIMI record either. The types of tricks in <a href=\"https:\/\/emailalias.io\/blog\/types-of-phishing-attacks\/\" rel=\"noopener\" target=\"_blank\">Part 3 on phishing attacks<\/a> mostly don&#8217;t rely on spoofing your exact domain, so BIMI never touches them.<\/li>\n  <li><strong>Absence of a logo doesn&#8217;t mean a scam.<\/strong> Plenty of legitimate senders \u2014 smaller businesses, individuals, anyone without the budget or trademark \u2014 will never show a BIMI logo. So &#8220;no logo&#8221; tells you almost nothing on its own; treating a missing logo as a red flag would flag most of your real mail.<\/li>\n  <li><strong>It&#8217;s not encryption or privacy.<\/strong> BIMI does nothing to hide your address, stop tracking, or keep your mail confidential. It&#8217;s purely about verifying a sender&#8217;s identity to the recipient.<\/li>\n  <li><strong>It&#8217;s costly and sender-side.<\/strong> The certificate and setup burden mean BIMI will always be a big-brand-first feature, not a universal one. It raises trust for the senders who can afford it, not the ecosystem as a whole.<\/li>\n<\/ul>\n<p>None of this makes BIMI bad \u2014 it&#8217;s a solid trust signal when present. It just means BIMI is one narrow tool: helpful for confirming a known brand, useless for the broader flood of scams, tracking, and exposure that make up most of your real risk.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> BIMI can&#8217;t stop look-alike-domain phishing, and a missing logo doesn&#8217;t indicate a scam \u2014 most legitimate senders will never have one. It&#8217;s not encryption or privacy, and its cost keeps it big-brand-first. Treat a verified logo as a helpful &#8220;yes,&#8221; never a missing one as a &#8220;no.&#8221;<\/aside>\n\n<h2 id=\"stack\">What Is BIMI Compared to SPF, DKIM, and DMARC?<\/h2>\n<p>Because BIMI is usually mentioned in the same breath as SPF, DKIM, and DMARC, it&#8217;s worth being precise about what is BIMI&#8217;s distinct job versus theirs. They form a stack, each doing exactly one thing, and BIMI sits on top of all of them:<\/p>\n<ul>\n  <li><strong>SPF<\/strong> declares which mail servers are allowed to send for a domain.<\/li>\n  <li><strong>DKIM<\/strong> attaches a cryptographic signature so a receiver can verify a message wasn&#8217;t tampered with and really came from the domain.<\/li>\n  <li><strong>DMARC<\/strong> ties SPF and DKIM together, tells receivers what to do when a message fails (nothing, quarantine, or reject), and reports results back to the domain owner.<\/li>\n  <li><strong>BIMI<\/strong> does none of that verifying itself \u2014 it&#8217;s the display layer that shows a logo once DMARC is already passing at enforcement.<\/li>\n<\/ul>\n<p>So the honest one-line answer to what is BIMI in relation to the others is this: SPF, DKIM, and DMARC do the security work, and BIMI simply shows the result. That ordering matters, because it explains why BIMI can never be a shortcut \u2014 you can&#8217;t buy a logo to skip the authentication underneath it. A domain has to earn its way up the stack first, which is precisely why the valuable part of any BIMI project is the DMARC enforcement beneath the surface, not the icon on top.<\/p>\n<p>It&#8217;s also why security professionals tend to be lukewarm on BIMI as a <em>security<\/em> measure while still recommending the work it depends on. Reaching DMARC enforcement genuinely reduces domain spoofing; adding a logo afterwards is mostly a branding and trust decision. If you ever hear BIMI described as &#8220;the last 5% that&#8217;s 95% marketing,&#8221; that&#8217;s the idea \u2014 the heavy lifting is the authentication, and the logo is the visible flourish that rewards it. Understanding what BIMI is really means understanding that split: valuable groundwork, optional decoration.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> In the authentication stack, SPF, DKIM, and DMARC do the verifying, and BIMI is only the display layer that shows a logo once DMARC passes at enforcement. BIMI can&#8217;t be a shortcut \u2014 the valuable work is the DMARC enforcement underneath; the logo is the reward on top.<\/aside>\n\n<h2 id=\"fit\">What Is BIMI&#8217;s Place in Your Email Security?<\/h2>\n<p>BIMI is the natural closing note for this series because it sits at the very top of the authentication stack \u2014 but it also shows the limit of what senders and standards can do for you. Authentication (SPF, DKIM, DMARC, BIMI) protects the <em>identity of the sender&#8217;s domain<\/em>. It&#8217;s essential infrastructure, and it&#8217;s why domain spoofing is harder than it used to be. But it can&#8217;t protect <em>your<\/em> address, contain a breach, or stop a look-alike scam \u2014 the risks that actually dominate everyday email.<\/p>\n<p>That&#8217;s the gap your own habits fill, and it&#8217;s the thread running through all four parts of Email Security 101. You shrink your exposure by <a href=\"https:\/\/emailalias.io\/blog\/remove-yourself-from-data-brokers\/\" rel=\"noopener\" target=\"_blank\">getting off data-broker lists<\/a> (Part 1); you contain the damage when a service is breached (Part 2); you learn to spot the scams that authentication can&#8217;t stop (Part 3); and you read signals like BIMI for what they&#8217;re worth (Part 4). Tying it together is the single most practical habit: giving every service its own <a href=\"https:\/\/emailalias.io\/blog\/what-is-an-email-alias\/\" rel=\"noopener\" target=\"_blank\">email alias<\/a>, so your real address stays private, breaches stay contained, and any leak becomes traceable. Sender authentication and recipient hygiene are two halves of the same lock \u2014 BIMI is the half the brands do; aliasing is the half you do.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> Authentication like BIMI protects the sender&#8217;s domain identity, but not your address, your breaches, or look-alike scams \u2014 that&#8217;s your job. The through-line of the whole series is recipient hygiene, above all a per-service alias, which is the half of email security you actually control.<\/aside>\n\n<h2 id=\"final-thoughts\">Final Thoughts: The Series in One Line<\/h2>\n<p>Across four parts, Email Security 101 has circled one idea from different angles: the strongest email security comes from limiting your exposure, not from any single feature. Data-broker cleanup, breach containment, phishing awareness, and authentication signals like BIMI each cover a slice of the problem \u2014 but none is a cure, and the ones that depend on big senders or paid certificates will never protect everyone. What ties them together, and what you can start today for free, is treating your real email address as something to protect rather than to spread. So the answer to &#8220;what is BIMI, and do you need it?&#8221; is: it&#8217;s a useful trust signal you&#8217;ll mostly just read, and the security that&#8217;s genuinely in your hands is the alias you give out instead of your real address. That&#8217;s where email security actually begins.<\/p>\n\n<h2 id=\"faq\">Frequently Asked Questions<\/h2>\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list \">\n<div id=\"faq-q-1\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What is BIMI in email?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>BIMI stands for Brand Indicators for Message Identification. It&#8217;s an email standard that lets an organisation display its official logo next to its messages in your inbox \u2014 but only when the message has passed authentication. A sender publishes a record in their domain&#8217;s DNS pointing to a hosted logo, and supporting inbox providers show that logo on authenticated mail from the domain. It&#8217;s a trust-signalling presentation feature layered on top of SPF, DKIM, and DMARC, not a spam filter or an encryption tool.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-2\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">How does BIMI work?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>In four steps. First, the sender&#8217;s domain must pass DMARC at enforcement (a p=quarantine or p=reject policy covering all its mail) \u2014 without that, BIMI does nothing. Second, the brand prepares its logo as a square SVG Tiny PS file, under about 32 KB, hosted over HTTPS. Third, it publishes a BIMI DNS record pointing to the logo (and usually a certificate). Fourth, supporting inbox providers read that record and display the logo next to authenticated messages from the domain. BIMI reuses the authentication a well-run domain already has.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-3\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Which email providers support BIMI?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Support is now broad: Gmail, Apple Mail, Yahoo Mail, and Fastmail all render BIMI logos on authenticated mail, which is why brand icons have become more common in inboxes. The requirements differ, though \u2014 Gmail displays a logo with at least a Common Mark Certificate and adds a blue verified checkmark only for a Verified Mark Certificate; Yahoo shows a logo with no certificate at all; and Apple Mail requires a Verified Mark Certificate. So which inboxes show your logo depends on the certificate you use.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-4\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What is the difference between a VMC and a CMC?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Both are &#8216;mark certificates&#8217; that prove a sender is entitled to the logo BIMI displays. A VMC (Verified Mark Certificate) requires a registered trademark and unlocks Gmail&#8217;s blue verified checkmark; it costs roughly $650 to $1,750 a year. A CMC (Common Mark Certificate), introduced in late 2024, doesn&#8217;t need a trademark \u2014 proof of about 12 months of logo use is enough \u2014 and it makes the logo appear in supporting inboxes but does not earn the blue checkmark. The CMC opened BIMI up to organisations without a registered trademark.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-5\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Do I need BIMI?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>As an individual protecting your own inbox, no \u2014 BIMI isn&#8217;t something you set up; it&#8217;s configured by the brands that send to you. What it gives you as a recipient is a trust signal: a verified logo (and, in Gmail, a blue checkmark) means the mail is authenticated and genuinely from that brand. As a business or domain owner, BIMI can be worth it for brand recognition and the checkmark, but only after you&#8217;ve reached DMARC enforcement \u2014 which is the real security goal \u2014 and it costs money and effort. For most, DMARC enforcement matters far more than the logo.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-6\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Does BIMI stop phishing?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Only partially. BIMI helps confirm that mail genuinely came from a specific brand&#8217;s domain, so it makes exact-domain spoofing more visible. But it doesn&#8217;t stop the many scams that use look-alike &#8216;cousin&#8217; domains \u2014 those simply won&#8217;t have your logo, and BIMI won&#8217;t block them. Just as important, most legitimate senders don&#8217;t have a BIMI logo, so the absence of one tells you almost nothing. Treat a verified logo as a reassuring &#8216;yes&#8217; when it&#8217;s there, but never treat a missing logo as proof of a scam.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-7\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Is BIMI free to set up?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>No. Beyond the technical work of reaching DMARC enforcement and formatting the logo, most inbox providers require a paid mark certificate to display it. A VMC runs roughly $650 to $1,750 per year, and a CMC typically $1,500 to $3,000 per year, on top of 10 to 40 hours of setup work. That cost is why BIMI is a big-brand-first feature rather than a universal one \u2014 it&#8217;s an optional flourish for senders who can justify it, layered on the free-to-implement authentication (SPF, DKIM, DMARC) that every domain should have anyway.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-8\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What&#8217;s the best email security step I can actually take?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Limit your exposure rather than relying on any single feature. Authentication signals like BIMI are configured by senders and only cover part of the risk, so the security that&#8217;s genuinely in your hands is recipient hygiene: get off data-broker lists, contain breaches, stay alert to phishing, and \u2014 the master move that ties it together \u2014 give every service its own email alias instead of your real address. That keeps your address private, contains any breach to one switch-off-able alias, and makes every leak traceable. It&#8217;s free, and it&#8217;s where practical email security begins.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Email Security 101 \u2014 a 4-part series. \u2190 Part 1: Remove Yourself From Data Brokers \u00b7 Part 2: What to Do After an Email Data Breach \u00b7 Part 3: Types&#8230;<\/p>\n","protected":false},"author":3,"featured_media":480,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"rank_math_focus_keyword":"what is bimi","rank_math_title":"What Is BIMI? Verified Email Logos, Explained","rank_math_description":"What is BIMI? The email standard that shows a verified brand logo on authenticated mail. How it works, who really needs it, and what it cannot do.","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[5],"tags":[],"class_list":{"0":"post-482","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-security"},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/what-is-bimi.jpg?fit=1200%2C630&ssl=1","jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":386,"url":"https:\/\/emailalias.io\/blog\/types-of-phishing-attacks\/","url_meta":{"origin":482,"position":0},"title":"Email Security 101 (Part 3): Types of Phishing Attacks and How to Spot Them","author":"Troy Hunt","date":"September 19, 2026","format":false,"excerpt":"Email Security 101 \u2014 a 4-part series. \u2190 Part 1: Remove Yourself From Data Brokers \u00b7 Part 2: What to Do After an Email Data Breach. You're on Part 3. Part 4: What Is BIMI is now live. The short version Phishing isn't one attack \u2014 it's a family. Email\u2026","rel":"","context":"In &quot;Security&quot;","block_context":{"text":"Security","link":"https:\/\/emailalias.io\/blog\/category\/security\/"},"img":{"alt_text":"types of phishing attacks, shown as a fishing hook snagging a sealed envelope","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/types-of-phishing-attacks.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/types-of-phishing-attacks.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/types-of-phishing-attacks.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/types-of-phishing-attacks.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/types-of-phishing-attacks.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":478,"url":"https:\/\/emailalias.io\/blog\/email-privacy-trends-2026\/","url_meta":{"origin":482,"position":1},"title":"Email Privacy Trends in 2026: What&#8217;s Really Changing","author":"Troy Hunt","date":"September 24, 2026","format":false,"excerpt":"The short version Your email address is the new tracking identifier. As browser-level fixes stall, advertisers and data brokers lean harder on the one thing that follows you everywhere: your email. 2026's big shifts: one-click data-broker deletion arrived in California, Google abandoned the cookie phase-out, AI turbo-charged phishing, and email\u2026","rel":"","context":"In &quot;Comparisons&quot;","block_context":{"text":"Comparisons","link":"https:\/\/emailalias.io\/blog\/category\/comparisons\/"},"img":{"alt_text":"email privacy trends in 2026, shown as a signpost of blank direction arrows beside a brass mailbox","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-privacy-trends-2026.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-privacy-trends-2026.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-privacy-trends-2026.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-privacy-trends-2026.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-privacy-trends-2026.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":351,"url":"https:\/\/emailalias.io\/blog\/remove-yourself-from-data-brokers\/","url_meta":{"origin":482,"position":2},"title":"Email Security 101 (Part 1): How to Remove Yourself From Data Brokers","author":"Troy Hunt","date":"September 8, 2026","format":false,"excerpt":"Part 1 of 4 \u2014 Email Security 101. Coming up: Part 2, what to do after an email data breach \u00b7 Part 3, types of phishing attacks \u00b7 Part 4, what BIMI is and whether you need it. The short version Data brokers quietly buy, package, and sell your name,\u2026","rel":"","context":"In &quot;Email Aliases&quot;","block_context":{"text":"Email Aliases","link":"https:\/\/emailalias.io\/blog\/category\/email-aliases\/"},"img":{"alt_text":"remove yourself from data brokers, shown as a locked file drawer of personal records","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/remove-yourself-from-data-brokers.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/remove-yourself-from-data-brokers.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/remove-yourself-from-data-brokers.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/remove-yourself-from-data-brokers.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/remove-yourself-from-data-brokers.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":369,"url":"https:\/\/emailalias.io\/blog\/email-data-breach-what-to-do\/","url_meta":{"origin":482,"position":3},"title":"Email Security 101 (Part 2): What to Do After an Email Data Breach","author":"Troy Hunt","date":"September 15, 2026","format":false,"excerpt":"Email Security 101 \u2014 a 4-part series. \u2190 Part 1: How to Remove Yourself From Data Brokers. You're on Part 2. Part 3: Types of Phishing Attacks is now live. Part 4: What Is BIMI closes the series. The short version Move fast, in order: confirm the breach, change the\u2026","rel":"","context":"In &quot;Security&quot;","block_context":{"text":"Security","link":"https:\/\/emailalias.io\/blog\/category\/security\/"},"img":{"alt_text":"what to do after an email data breach, shown as a forced-open mailbox with mail spilling out and a broken padlock","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-data-breach-what-to-do.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-data-breach-what-to-do.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-data-breach-what-to-do.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-data-breach-what-to-do.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-data-breach-what-to-do.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":453,"url":"https:\/\/emailalias.io\/blog\/forward-aliases-to-multiple-inboxes\/","url_meta":{"origin":482,"position":4},"title":"How to Forward Aliases to Multiple Inboxes","author":"Troy Hunt","date":"September 23, 2026","format":false,"excerpt":"The short version You can send different aliases to different inboxes \u2014 work aliases to your work email, personal ones to your personal inbox \u2014 instead of everything landing in one place. Add and verify each extra inbox once, then pick which verified inbox any alias forwards to. It all\u2026","rel":"","context":"In &quot;Features&quot;","block_context":{"text":"Features","link":"https:\/\/emailalias.io\/blog\/category\/features\/"},"img":{"alt_text":"forward aliases to multiple inboxes, shown as labelled letters sorted into two separate mailboxes","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/forward-aliases-to-multiple-inboxes.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/forward-aliases-to-multiple-inboxes.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/forward-aliases-to-multiple-inboxes.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/forward-aliases-to-multiple-inboxes.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/forward-aliases-to-multiple-inboxes.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":502,"url":"https:\/\/emailalias.io\/blog\/catch-all-email-alias\/","url_meta":{"origin":482,"position":5},"title":"How to Set Up a Catch-All Email Alias on Your Domain","author":"Troy Hunt","date":"October 5, 2026","format":false,"excerpt":"The short version A catch-all email alias turns your whole domain into alias space \u2014 any address at it (anything@yourdomain) works instantly, with no need to create each one first. You switch it on per domain in EmailAlias (Premium, on a verified custom domain): pick the inbox to forward to,\u2026","rel":"","context":"In &quot;Features&quot;","block_context":{"text":"Features","link":"https:\/\/emailalias.io\/blog\/category\/features\/"},"img":{"alt_text":"catch-all email alias shown as one glowing domain funnelling many envelopes into a single inbox","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/10\/catch-all-email-alias.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/10\/catch-all-email-alias.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/10\/catch-all-email-alias.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/10\/catch-all-email-alias.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/10\/catch-all-email-alias.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]}],"_links":{"self":[{"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/posts\/482","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/comments?post=482"}],"version-history":[{"count":1,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/posts\/482\/revisions"}],"predecessor-version":[{"id":483,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/posts\/482\/revisions\/483"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/media\/480"}],"wp:attachment":[{"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/media?parent=482"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/categories?post=482"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/tags?post=482"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}