ActiScan

DMARC

BIMI and Brand Trust: What It Actually Takes to Roll Out

September 15, 2026

Rodney Hall, COO— AI-assisted and reviewed prior to publication.

A closed brass padlock beside a wax seal pressed into paper, symbolizing verified trust before a logo displays.

A verified logo sitting next to a message in Gmail or Yahoo looks like a marketing feature. It is not. It is the visible output of an authentication chain that has to be correct at every link, and for most domains that chain is broken in at least one place before anyone even applies for a certificate. Brand Indicators for Message Identification, or BIMI, rewards domains that have already done the harder work of email authentication. It does not do that work for them.

So what does a BIMI rollout actually require? A domain needs DMARC published at enforcement, meaning a policy of quarantine or reject rather than the monitoring-only p=none, applied to 100 percent of mail on both the organizational domain and any sending subdomains. On top of that sits a specification-compliant SVG logo, a DNS TXT record pointing to it, and in most cases a Verified Mark Certificate or Common Mark Certificate that proves who owns the logo.

What Is BIMI, and What Does It Actually Gate On?

BIMI lets a domain publish the location of a brand logo in DNS so a receiving mail system can display it next to authenticated messages. The mechanism itself is simple. The gating conditions around it are not.

The original BIMI specification work, carried out as an IETF Internet-Draft rather than a ratified RFC, states plainly that domain owners need DMARC enforcement on both the organizational domain and any subdomains that send mail, and that the pct tag in the DMARC record must be absent or set to 100 percent, since anything less signals partial enforcement rather than full coverage. That last detail catches more domains than it should. A DMARC record left over from a phased rollout, with pct set below 100 from when a team was still testing, will pass every authentication check on individual messages and still suppress the logo, because BIMI evaluates the policy that is published, not the outcome of any one message.

Google's own troubleshooting documentation confirms the same threshold from the receiving side, stating that the percent option must be set to 100, since BIMI does not support DMARC policies with a pct value other than 100. This is one of the few requirements that shows up identically in the standards draft and in a major mailbox provider's own support pages, which is a reasonable signal that it is not going away.

Why DMARC Enforcement Is the Real Gate

DMARC enforcement, not the BIMI record itself, is what actually stands between a domain and a displayed logo. A domain can have a perfectly formatted SVG, a valid certificate, and a syntactically correct BIMI TXT record, and none of it matters if the DMARC policy is still sitting at p=none.

That ordering is deliberate. Mailbox providers are not going to render a trusted-looking logo next to a message from a domain that has not proven it can identify its own legitimate senders. DMARC itself, now published by the IETF as RFC 9989 after more than a decade under the original RFC 7489, defines exactly how a domain owner enables a receiver to validate that a message's use of the domain matches the policy the domain has published. BIMI simply refuses to hand out its visual reward to a domain that has not cleared that bar.

For MSPs, this means BIMI conversations with clients are really DMARC conversations wearing a marketing hat. A client who wants their logo in Gmail is, whether they realize it or not, asking to finish a DMARC enforcement project. Any team walking a client through this is better served starting with the getting-started guide for authentication rollout rather than jumping straight to logo files and certificates.

VMC or CMC: Which Certificate Path Actually Fits?

The certificate decision comes down to whether the domain owner holds a registered trademark on the logo. A Verified Mark Certificate requires one and unlocks the Gmail blue checkmark. A Common Mark Certificate, which Google Workspace began supporting for Gmail in 2024, was built specifically for organizations that lack a registered trademark but can still prove sustained, consistent use of the logo.

Google's own announcement of CMC support frames it as a way to protect brand identity for a wider set of senders, since BIMI requires domains and logos to be verified by a third party regardless of which certificate type is used. That single change opened BIMI to a large population of SMBs and MSP clients who were previously blocked purely on trademark status, not on authentication maturity.

The table below summarizes how the two certificate paths and the no-certificate option compare across the requirement dimensions that matter most for planning a rollout.

RequirementVMCCMCNo certificate (self-asserted)
Registered trademark neededYesNoNo
Gmail logo displayYesYesNo
Gmail blue checkmarkYesNoNo
Typical mailbox supportGmail, Apple MailGmailYahoo, some regional providers
DMARC enforcement required firstYesYesYes

Every row in that table shares one column: DMARC enforcement is a prerequisite regardless of which certificate path a domain takes, or whether it skips certificates entirely and relies on providers willing to render a self-asserted logo.

Where BIMI Rollouts Actually Break

The most common source of failure is not a missing certificate. It is small, silent errors in records and files that never surface as an error message to the domain owner. A 2025 analysis of the top one million domains by URIports, which built its own RFC-aligned BIMI validator, found that the share of BIMI-enabled domains with at least one error that blocks logo display grew from 41.8 percent in 2024 to 53.6 percent in 2025, even as overall adoption of BIMI records grew by 28 percent over the same period. Errors did not shrink as adoption grew. They grew faster.

The same research identified where those errors concentrate:

  • Non-compliant SVG files, the single most common failure, holding at roughly 27 to 28 percent of errors across both years, largely because standard design tools do not export the required SVG Tiny PS format natively.
  • DMARC configuration issues, including lingering p=none policies and subdomain policies that were never brought to enforcement.
  • Invalid or expired certificate references at the Authority Evidence Location, a category that grew as more domains attempted the VMC or CMC path.

None of these failures produce a bounce, a rejected message, or an alert in an inbox. A mailbox provider checks the chain once per render decision, and if any link fails, it simply does not show the logo. There is no notification loop back to the domain owner, which is exactly why a scanning and monitoring layer on top of DNS and DMARC state matters more here than in most other authentication work.

What This Means for MSPs Managing Multiple Client Domains

An MSP evaluating BIMI for a book of client domains is really running a DMARC enforcement audit across all of them, since the gating requirement is identical for every domain regardless of vertical or size. Red Sift's global DMARC adoption research, drawn from over 73 million domains, found that only about 2.5 percent of domains analyzed had reached p=reject, the strictest enforcement tier, while the large majority had no visible DMARC record at all. That gap is the real BIMI backlog. Most client domains are nowhere near ready for a logo conversation until enforcement is sorted out first.

A practical rollout sequence for an MSP looks like this in practice:

  • Confirm SPF and DKIM are passing and aligned for every sending source, including third-party marketing and transactional platforms.
  • Move DMARC from p=none to p=quarantine at pct=100, watch aggregate reports for a stabilization period, then move to p=reject.
  • Apply the same sp= enforcement to subdomains that send mail, since a strong organizational policy with a weak subdomain policy still blocks BIMI.
  • Choose VMC or CMC based on trademark status, prepare the SVG in Tiny PS format, and publish the BIMI TXT record only after enforcement is confirmed stable.
  • Monitor the published record and certificate expiry on an ongoing basis, since VMCs and CMCs both carry roughly a 397-day validity window and lapse silently.

Domains already tracking authentication posture through a scanning platform have a real head start here, since the DMARC enforcement state that gates BIMI is the same state that gates deliverability more broadly. Reviewing that posture across a client base is easier with the domain visibility built into the pricing tiers ActiScan offers for MSPs managing more than a handful of domains.

Is BIMI Worth the Rollout Effort?

For a domain that has already reached DMARC enforcement, BIMI is a low-incremental-cost way to convert that authentication work into a visible trust signal, and the certificate landscape has gotten more accessible since CMC arrived. For a domain still at p=none, BIMI is not the next project. Finishing enforcement is.

The honest framing for a client conversation is that BIMI cannot substitute for the underlying authentication work, and no vendor claim to the contrary should be trusted. What it can do is make finished authentication work visible to end users in a way that raw SPF and DKIM records never will. That visibility has real value for brands that get phished frequently, since a verified logo gives recipients a concrete visual cue that a spoofed lookalike message will not have.

Any MSP weighing whether to add BIMI to a service offering should treat it as a milestone inside a DMARC program, not a separate product. Domains that are ready can move through the certificate and DNS steps in a matter of weeks. Domains that are not ready need the enforcement work first, and pretending otherwise just produces the same silent, unexplained failure that shows up in the error statistics year after year. Teams starting that assessment from scratch can walk through domain checks directly from the signup flow before committing a client to either path.

Further Reading

← Back to all posts
BIMI Rollout Guide: DMARC, VMC, and CMC Requirements — ActiScan Blog