BIMI Explained: Getting Your Logo Into the Inbox
BIMI puts your verified logo next to your emails in the inbox — but it only works on top of a DMARC policy already at enforcement. Here's what's actually required.
BIMI (Brand Indicators for Message Identification) is the standard that lets your verified logo appear next to your emails in supporting inboxes — Gmail, Yahoo, and a growing list of mail clients. It's a trust signal, not a deliverability fix, and it has one hard prerequisite that trips up most people who try to set it up: DMARC has to already be at enforcement.
What BIMI actually requires
| Requirement | Detail |
|---|---|
| DMARC policy | Must be at p=quarantine or p=reject — p=none does not qualify |
| SVG logo | Square, Tiny PS profile, specific format constraints |
| BIMI DNS record | TXT record at default._bimi.yourdomain.com pointing to the logo URL |
| VMC certificate | Verified Mark Certificate — required by Gmail, optional for some other providers |
Why the DMARC prerequisite matters more than the logo
This is the step that stops most domains cold. Reaching p=quarantine or p=reject means every legitimate sending source on the domain — marketing tools, transactional email, cold outreach platforms — has to already pass SPF or DKIM alignment cleanly. For a domain still running mixed or unaudited sending sources, that's weeks of DMARC reporting and cleanup before BIMI is even a possibility, not a same-day DNS change.
See our DMARC rollout guide for the staged path from p=none to enforcement — BIMI is the reward at the end of that process, not a shortcut around it.
The VMC certificate question
Gmail requires a Verified Mark Certificate to display the logo — essentially a notarized proof that your organization legitimately owns the trademark on the logo you're publishing. VMCs cost several hundred dollars a year and require a registered trademark in most cases, which is the single biggest practical barrier for smaller companies. Yahoo and some other providers display BIMI logos without a VMC, so the certificate isn't universally required — but Gmail's user base makes it the one that matters most for B2B senders.
Is it worth it for a cold outreach domain?
This is where the answer gets specific. BIMI is built for brand trust on a domain recipients already recognize — a company's primary sending domain, not a secondary domain used specifically for cold outreach. Cold email best practice generally recommends sending from a dedicated subdomain or separate domain, precisely so outreach volume doesn't touch the primary brand domain's reputation. A logo next to a cold email from an unfamiliar sending domain doesn't carry the same trust signal it would from a known brand domain — the recipient doesn't recognize the logo's context either way.
BIMI makes the most sense for: the primary domain used for customer-facing transactional and marketing email, once DMARC is already enforced there for other reasons. It's a lower priority for a dedicated cold outreach domain, where the DMARC enforcement work is better spent purely on deliverability rather than as a prerequisite for a visual trust badge recipients may not even register as meaningful.
Bottom line
BIMI is a real, growing standard — but it's downstream of DMARC enforcement, which is itself a multi-week rollout most domains haven't completed. Get DMARC to enforcement for the reasons that matter (spoofing protection, Gmail/Yahoo bulk sender compliance) first; treat the logo as a bonus on your primary brand domain, not a priority for a dedicated cold outreach domain.
Your next campaign is six minutes away
Connect your business and let Alien AI handle the writing, structuring, and optimizing.
Generate my Business DNA — free