ActiScan
← Email Authentication Fundamentals

Module 6 of 6

BIMI — Brand Logos in the Inbox

BIMI (Brand Indicators for Message Identification) is the standard that lets your actual logo show up next to your messages in a supporting inbox – Gmail and Yahoo are the two largest mailbox providers that display it today.

The requirement everyone gets backwards

BIMI is not something you turn on independently – it's a reward layered on top of DMARC enforcement, not a substitute for it. To even qualify, a domain generally needs:

  • DMARC published at p=quarantine or p=reject (not p=none) – BIMI is explicitly not available to domains that are only monitoring, not enforcing.
  • A logo published as an SVG Tiny PS file – a restricted, security-conscious profile of SVG, not any SVG you already have on hand. It disallows scripts, external references, and most of what makes ordinary SVG powerful, precisely because it renders inside untrusted mail clients.
  • For most major providers: a Verified Mark Certificate (VMC) – a certificate issued by a small number of authorized certificate authorities that cryptographically ties the logo to your organization's registered trademark.

Why the ordering matters

Think about what BIMI is actually promising a recipient: "this logo really represents whoever is sending this, because their domain enforces authentication strictly enough that spoofing it is hard." If BIMI worked on top of p=none, that promise would be empty – anyone could spoof the domain and nothing would stop the message from arriving, logo and all. Requiring enforcement first is what makes the badge mean something.

Run ActiScan's BIMI readiness check against your own domain – it checks DMARC enforcement and validates the actual SVG file against the real SVG Tiny PS profile, not just whether a BIMI DNS record happens to exist.

Try it yourself: BIMI Readiness Check