Posted in

BIMI Explained

BIMI is an email standard that can allow your organization’s verified brand logo to appear beside authenticated emails in supporting inboxes.

BIMI stands for Brand Indicators for Message Identification. Instead of simply telling an email provider who sent a message, it adds a visual identity to authenticated email by giving participating mailbox providers a published brand logo they can display.

How does BIMI work?

It relies heavily on email authentication.

Before implementing it, a domain should have SPF, DKIM and DMARC correctly configured and aligned. DMARC must be operating at enforcement, using p=quarantine or p=reject, with the policy applied to 100% of messages.

Next comes the logo. Your organization prepares its logo using the required SVG format and publishes a DNS TXT record.

A simplified record lives under a name such as:

default._bimi.example.com

The record tells supporting email providers where the approved logo can be found.

What about VMC and CMC certificates?

You may also need a Verified Mark Certificate (VMC) or Common Mark Certificate (CMC). These provide additional verification around the logo being displayed. Requirements vary between mailbox providers, and publishing a BIMI record does not guarantee that every inbox will show your logo.

Is BIMI a security feature?

Not exactly.

BIMI itself isn’t intended to replace email security. Its value comes partly from requiring strong authentication mechanisms such as DMARC before a brand becomes eligible.

Think of it as the visible layer at the end of a properly authenticated email setup.

If SPF, DKIM, and DMARC are the security team checking your identity at the door, BIMI is the name badge you get once you’ve made it inside.