What is BIMI?
Brand Indicators for Message Identification (BIMI) is an email specification that allows organisations to display their brand logo next to authenticated emails in supporting email clients. When properly implemented, your logo appears in Gmail, Apple Mail, and Yahoo Mail - increasing open rates and reducing phishing risk.
Prerequisites
Before implementing BIMI, you need:
- SPF - a published SPF record authenticating your sending IPs
- DKIM - signing your outgoing emails with a private key
- DMARC - a policy of
p=quarantineorp=reject(notp=none) - A Verified Mark Certificate (VMC) - issued by DigiCert or Entrust
Step 1: Verify Your SPF Record
dig TXT yourdomain.com | grep spf
Your record should include all authorised sending services. Example:
v=spf1 include:_spf.google.com include:sendgrid.net ~all
Step 2: Configure DKIM
DKIM signs your emails cryptographically. On Carbonio or Postfix:
opendkim-genkey -t -s default -d yourdomain.com
Publish the public key as a TXT record at default._domainkey.yourdomain.com.
Step 3: Set DMARC to Enforcement
_dmarc.yourdomain.com TXT "v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; pct=100"
Wait 2–4 weeks and review your DMARC reports before moving to p=reject.
Step 4: Obtain a VMC
A Verified Mark Certificate costs approximately $1,500/year from DigiCert. You need a registered trademark for your logo. The process takes 2–6 weeks.
Step 5: Publish the BIMI DNS Record
default._bimi.yourdomain.com TXT "v=BIMI1; l=https://yourdomain.com/brand/logo.svg; a=https://yourdomain.com/brand/certificate.pem"
Your SVG logo must be a square, solid-background SVG with no animations.
Verification
Use BIMI Inspector to validate your record. Allow 24–48 hours for propagation.
Need Help?
Our Email Infrastructure service covers the full BIMI implementation including VMC procurement, DNS configuration, and deliverability monitoring.