BIMI: how to set it up, and why you probably shouldn't bother yet
What it actually takes to get your logo into the inbox with BIMI, and an honest look at why, right now, it's mostly vanity rather than a deliverability win.
Someone in marketing saw a competitor's logo sitting next to their name in Gmail, and now it's your problem. They want the badge. That little round logo that says "this brand is verified."
BIMI is how you get it. It's also, for most organisations, a project that buys you a logo and not much else. Here's the honest version of both halves.
What is BIMI, really?
BIMI stands for Brand Indicators for Message Identification. It's a DNS record that points mailbox providers at your logo. When a provider supports it and trusts you, your logo shows up next to your messages.
That's the whole feature. A picture in the inbox.
Worth knowing before anyone signs a purchase order: BIMI is not a finished standard. It's an IETF Internet-Draft. The current one is draft-brand-indicators-for-message-identification-14, dated 1 May 2026 and set to expire on 2 November 2026 unless it's revised again, and it still carries the boilerplate that an Internet-Draft is "work in progress"1. Mailbox providers shipped it anyway, which is why it works at all. There is still no RFC number to point at.
The important word is trust. BIMI does not make your mail any more authentic than it already was. It rides on trust you built with DMARC and puts a picture on it. The logo is the reward for authentication you've already done, not a thing that improves it.
default._bimi.example.com. IN TXT "v=BIMI1; l=https://example.com/logo.svg; a=https://example.com/vmc.pem"
Two parts. l= is your logo. a= is the certificate that proves you own it, and the specification treats it as optional: leave it out and it is assumed empty1. Hold onto that second one. It's where the money goes.
What does it actually take to set up?
There's a ladder, and you can't skip a rung.
The first rung is enforced DMARC. Your domain must publish a policy of p=quarantine or p=reject. Not p=none. The specification adds two conditions that sentence hides. quarantine only counts at an effective percentage of 100, and if you publish a subdomain policy it must not be none2. Google says the same thing in its own words, pct set to 1003. A domain sitting at p=quarantine; pct=25 while it ramps up is not eligible, and nothing tells you so. You publish the record, wait, and no logo ever arrives. This rung is the real gate, and for a lot of domains it's months of work on its own. You have to fix SPF and DKIM for every legitimate sender before you can safely enforce. If you're not at enforcement yet, BIMI isn't your next step. DMARC is.
The second rung is a logo in the right format. Not your PNG. BIMI wants SVG Tiny PS, a stripped-down SVG profile carrying baseProfile="tiny-ps" and version="1.2"4. The BIMI Group splits the rest into two lists. Required: a <title> element, which "must be included" though its content is not strictly specified, and no external references, no scripts, no animation, and no x= or y= attributes on the <svg> root5. Recommended rather than required, for compatibility: a square aspect ratio, a solid rather than transparent background, and a file that "should not exceed 32 kilobytes"5. The x/y one is the trap, and the BIMI Group names it on the same page: Illustrator's own SVG Tiny 1.2 export writes those attributes in, so you have to strip them by hand. Most brand SVGs fail on the first try. Budget an afternoon.
The third rung is a certificate, and whether it's optional depends entirely on which inbox you care about. Gmail won't show your logo on the strength of the DNS record alone: Google's own setup page says Gmail and other email clients "support BIMI only with PEM files"3, and the PEM is the certificate. Gmail takes a Verified Mark Certificate (VMC), which needs a registered trademark, or a Common Mark Certificate (CMC), which doesn't, though a CMC gets you the avatar without the verified checkmark Gmail shows for a VMC6.
Apple's support page is vaguer. It calls the messages it decorates "digitally certified", says senders have to "demonstrate control over their brand logos", and adds that BIMI "also works with VMCs (Verified Mark Certificates) and other forms of BIMI Evidence Documents"7. Apple's developer page is blunter. A logo appears in Apple Mail only once the recipient's mail provider has "Verified a BIMI Evidence Document (for example, a VMC trusted by the mail provider)", is on the BIMI Group's list of providers supporting BIMI, has been verified by Apple, and adds the headers vouching for those checks12. So a certificate is not optional here either. The provider has to verify one. But look at who the conditions land on. Not one of the four is yours to pass; every one sits on your reader's provider. Neither page names an accepted document type beyond the VMC, so whether a CMC alone gets you in is a question Apple does not answer in public. Don't assume the cheaper certificate buys you both inboxes. Yahoo is the outlier. It does not currently require a VMC at all8.
That last rung is where BIMI stops being a DNS exercise and becomes a procurement one.
So why is it mostly vanity?
Three reasons, in order of how much they'll annoy you.
The VMC tax is real, and it recurs. DigiCert's own list prices on 6 September 2026 were $1,752.00 a year for a Verified Mark Certificate and $1,416.00 a year for a Common Mark Certificate, both on 12-month auto-renewing subscriptions9. Resellers quote lower and issuers move their pricing, so get a current quote rather than trusting this line. The VMC route also needs a registered trademark, which is its own cost and its own wait: Google puts the trademark process at six to twelve months3. You are paying, every year, for a logo to appear in some inboxes. It is the most expensive image hosting on earth.
Client support is patchy. Gmail, Apple Mail and Yahoo all display BIMI logos, but the word "supported" covers three different projects. Yahoo wants no certificate and adds conditions the others don't publish: the mailing has to be bulk, and the sending address needs "sufficient reputation and engagement"8. Apple only renders it from iOS 16, iPadOS 16 and macOS Ventura 13 onwards7. Microsoft does not render the logo at all. Its own current documentation lists the providers that support BIMI as "Google, Fastmail, Yahoo, etc." and does not include itself, and a Microsoft moderator answered the question directly on Microsoft Q&A: "As a receiver: Microsoft does not currently support BIMI rendering in Exchange Online or Outlook"10. If your audience sits on Microsoft 365, they see nothing you paid for.
And it does nothing for deliverability. This is the one people don't want to hear. BIMI sits downstream of authentication. The draft's own abstract scopes it to coordination between domain owners and mail user agents "to display brand-specific Indicators next to properly authenticated messages", and leaves receivers "free to define their own policies"; search the whole document for delivery, filtering or spam and nothing claims an effect on any of them1. Read Yahoo's conditions again and the arrow runs the other way from the sales pitch. Reputation and engagement decide whether you get the logo8. The logo appears because you already pass DMARC at enforcement, and it's that enforcement, not the picture, that protects your domain and your inbox placement. You get the entire deliverability benefit at rung one. The logo on rung three is decoration.
If a vendor pitches BIMI as a way to "improve inbox placement", they're selling you the cake by describing the icing. The placement came from DMARC. You already had it.
Microsoft's own BIMI page does this in public, and the bullet contradicts its own heading. It lists "Improved email deliverability" as a benefit of BIMI, then explains that the improvement comes from setting up SPF, DKIM and DMARC correctly11. The mechanism it names is DMARC, and the thing it is selling is the logo.
When is it actually worth it?
It's not never. There's a real case.
It works when you're a consumer-facing brand sending high volumes to Gmail, Apple and Yahoo audiences: retail, banking, big SaaS. Yahoo's bulk-mail condition is a fair proxy for who this was built for. What the certificate actually attests is narrow but real: Apple's framing is that a BIMI sender has met "a strong standard of email authentication" and demonstrated "control over their brand logos"7. Whether a recipient notices the logo, or recognises your brand faster because of it, is a marketing question none of the providers publish numbers on, and we have not measured it either.
It works when you already have a registered trademark and an enforced DMARC policy, because then the marginal cost is a certificate and an afternoon, not a year-long programme.
And it helps when you have a phishing problem and want every legitimate-sender signal you can get in front of consumers who've been targeted.
If that's you, BIMI is a reasonable line item. For a B2B firm sending mostly to other businesses on Microsoft 365, where the badge does not render at all today, it's much harder to justify the annual cheque.
Our take
BIMI is the reward at the top of a ladder that most of the value sits at the bottom of. Climb the ladder for the right reason. Get to DMARC enforcement because it stops people spoofing you, and treat the logo as a small, optional flourish at the end if your audience and budget line up.
Don't let the badge become the reason you do DMARC. Let stopping spoofing be the reason. The badge is what you might add afterwards, not the goal.
What to do
- Check where your DMARC policy actually is, and read the
pctvalue while you're there, not just thepvalue. If it'sp=none, orp=quarantineat anything under 100, that's the whole project right now. Run your domain through the DMARC checker and read the policy line. - Get to
p=quarantine; pct=100, thenp=reject, by fixing every legitimate sender first. This is the work that protects you. - Only then weigh BIMI. If you're a consumer brand with a trademark, get the SVG Tiny PS logo and a VMC. If you're not, publish the record without the cert if you like the idea, and accept the logo will only show in a few clients. Or skip it and spend the money elsewhere.
- Verify what you publish. Once a BIMI record is live, check it renders and validates with the BIMI checker before you tell anyone it's done.
The logo is nice. The authentication underneath it is the point.
What this article was checked against
Every claim above was verified against a primary source before publication, and re-checked on 6 September 2026. Certificate pricing and mailbox-provider behaviour both move, so re-read the vendor's own page rather than trusting the date on this one.
- The
l=anda=tags, thata=is optional and assumed empty when absent ("If the a= tag is not present, it is assumed to have an empty value"), and thatdefaultis the default selector. Also the document's own status —draft-brand-indicators-for-message-identification-14, 1 May 2026, "Expires: 2 November 2026", carrying the standard Internet-Draft boilerplate that it is "work in progress" — and its abstract, which scopes BIMI to coordinating Indicator display and says MUAs "are free to define their own policies". The deliverability point is a negative claim, checked by grepping the full draft text fordeliver,filterand andspamon 6 September 2026: no hit asserts any effect on delivery or filtering. — draft-brand-indicators-for-message-identification-14 (IETF) ↩ - The DMARC gate: a policy of
quarantineat an effective percentage of 100, orreject, on both the Organizational Domain and the RFC5322.From domain, and a published subdomain policy that is notnone. — draft-brand-indicators-for-message-identification-14 (IETF) ↩ - Google's own requirements:
pset to quarantine or reject,pctset to 100, SVG Tiny PS withbaseProfiletiny-ps andversion1.2, a logo trademarked with a recognised intellectual property office for a VMC, a trademark process of six to twelve months, and the certificate requirement itself: "Gmail and other email clients support BIMI only with PEM files." (The oldsupport.google.com/a/answer/10911320URL 301-redirects here as of 6 September 2026.) — Set up BIMI (Google Workspace Admin Help) ↩ - SVG Tiny PS as the required profile, with the exact
baseProfileandversionattribute values. — Set up BIMI (Google Workspace Admin Help) ↩ - The split between what the BIMI Group requires and what it merely advises. Required: "A <title> element must be included that reflects the company name, though there are no strict requirements for the content of the element", and the document "must not include any of the following in order to be valid under the tiny-ps designation: Any external links or references…, Any scripts, animation, or other interactive elements, ‘x=’ or ‘y=’ attributes within the <svg> root element". Advisory, under the heading "When planning your image consider the following to ensure maximum compatibility": "The image should be a square aspect ratio", "The SVG document should be as small as possible and should not exceed 32 kilobytes", and "The background should be a solid color, as transparent backgrounds may not display as expected". The Illustrator trap is on the same page: "Unfortunately, Adobe Illustrator includes the errant ‘x=’ and ‘y=’ attributes in the <svg> root element which need to be removed." The profile draft agrees that the size limit is advice rather than a rule — "The file size of SVG Tiny PS documents SHOULD be as small as possible, and SHOULD NOT exceed 32 kilobytes" — and imposes no square-aspect requirement at all. — Creating BIMI SVG Logo Files (BIMI Group) · SVG Tiny Portable/Secure, draft-svg-tiny-ps-abrotman-07 (IETF) ↩
- Gmail accepts a Common Mark Certificate from senders without the registered trademark a VMC requires, and a CMC displays the brand avatar without the verified checkmark shown for a VMC. — Gmail allows more senders to protect their brand using BIMI Common Mark Certificates (Google Workspace Updates) ↩
- Apple's wording — "Email messages with brand logos have been digitally certified", senders must "demonstrate control over their brand logos", and "BIMI also works with VMCs (Verified Mark Certificates) and other forms of BIMI Evidence Documents" — and the supported versions: iOS 16, iPadOS 16, macOS Ventura 13 or later, and iCloud.com. — About BIMI support in Apple Mail (Apple Support) ↩
- Yahoo requires DMARC at quarantine or reject, states "we currently do not require VMCs to be set up for BIMI logos to appear in Yahoo applications", and adds two further conditions: bulk mail rather than personal email, and sufficient reputation and engagement for the sending address. — BIMI (Yahoo Sender Hub) ↩
- DigiCert's own list prices, read from the vendor's pricing page on 6 September 2026: Verified Mark Certificate $1,752.00 and Common Mark Certificate $1,416.00, each on a 12-month auto-renewing subscription. The two products are priced separately and the cheaper figure is the CMC — an earlier version of this article quoted $1,416 as the VMC price. That error is easy to repeat: the page ships with $1,416.00 hard-coded into the VMC column's price span and a script swaps in $1,752.00 on load, so a reader who views source, or reads the page before the script runs, sees the wrong number under the right product. The VMC figure sits in the page's own product data against SKU
vmc_basic. No multi-year or discounted price is offered — both products are sold only as 12-month auto-renewing subscriptions, markeddiscounted: false, with the note "Prices subject to change." A reseller quote is not either number. — Verified Mark Certificates (DigiCert) ↩ - Microsoft does not render BIMI logos for its own recipients. Its BIMI documentation lists the supporting providers as "Google, Fastmail, Yahoo, etc." without naming itself; the direct answer, "As a receiver: Microsoft does not currently support BIMI rendering in Exchange Online or Outlook", is from a Microsoft Q&A moderator badged "Microsoft External Staff", dated 29 September 2025 — a forum answer, not documentation, so treat it as Microsoft's stated position rather than a published commitment. The Learn page also carries an "Important" callout that "Emails sent from other Microsoft products, such as Exchange Online, do not yet support BIMI", but that is about sending, not about whether Outlook renders an incoming logo, so it is not cited for the claim above. — BIMI support (Microsoft Learn) · Does Exchange Online support BIMI verification? (Microsoft Q&A) ↩
- The vendor page that lists "Improved email deliverability" as a benefit of BIMI and then attributes it to SPF, DKIM and DMARC being set up correctly. Read the bullet, not the heading. — BIMI support (Microsoft Learn) ↩
- Apple’s developer page for mail providers, which sets out the four conditions for a logo to appear in Apple Mail. Verbatim: the mail provider must have “Been added to the bimigroup.org list of providers supporting BIMI, and been verified by Apple”, “Ensured message and domain compliance according to the BIMI draft specification”, “Verified a BIMI Evidence Document (for example, a VMC trusted by the mail provider)”, and “Added the required headers vouching for these checks”. Note these are conditions on the receiving provider, not on the sender. Read 6 September 2026. — Prepare your email server for BIMI support in Apple Mail (Apple Developer) ↩