Andrew Luxem
FREE

BIMI

BIMI puts your logo next to your name in the inbox. That is not what it is for. It is the receipt for DMARC done right, and this playbook tells you whether the certificate is worth the money before you spend it.

The vendor pitch for BIMI is a logo and an open-rate lift, usually quoted without a methodology. Here is the honest version. Any lift attributed to BIMI comes almost entirely from its prerequisite: to display a logo at all, your domain must run DMARC at enforcement, and getting to enforcement is what improves placement and shuts down exact-domain spoofing. The logo is the carrot. The enforcement is the substance.

The prerequisite is absolute. Your organizational domain needs p=reject, or p=quarantine applied at full strength, and a subdomain policy that is not none. Then BIMI itself is one DNS record at a default selector: a version tag, a pointer to your logo file, and, where a certificate is required, a pointer to the certificate chain.

Where it renders decides whether it is worth doing, and the map is uneven. Gmail requires a certificate and reserves its blue verified checkmark for the more expensive kind. Apple Mail requires a certificate too, and evaluates through the recipient's mail backend, so a corporate Exchange backend means no logo no matter what you spent. Yahoo honors self-asserted records with no certificate at all, but only for bulk senders with established reputation. Microsoft does not support BIMI, full stop. Read your audience before you read a certificate price sheet: a B2C list living in Gmail, Apple, and Yahoo is the strong case, and a Microsoft-heavy B2B audience is a return of roughly zero.

The certificates are a two-tier system. A Verified Mark Certificate requires a registered trademark and organizational validation, runs high three to low four figures a year, and is the only path to Gmail's checkmark. The Common Mark Certificate, introduced in 2024, takes a prior-use path instead: show your logo has been in commercial use for a year or more, skip the trademark, pay somewhat less, get the logo everywhere certificates work, and forgo the checkmark. Three authorities issue them today. The logo itself must be a strict SVG profile, and the certificate is bound to that exact file: change the logo, even a color refresh, and you are buying a new certificate. Budget that into every rebrand conversation.

I have shipped this end to end repeatedly, at national retail scale, on both certificate paths and with two of the three authorized issuers, DigiCert and GlobalSign: procurement and payment, the documentation each requires, legal counsel for the trademark evidence, certificate and logo hosting, through to verified rendering in Gmail. What that taught me is that BIMI is an organizational project wearing a technical costume. The DNS record takes ten minutes. The evidence package and the validation process are the long pole, and the silent failure modes after launch are almost never in your zone file.

The CFO paragraph, since someone will ask for it: you are buying three things. Forced completion of DMARC enforcement, which closes your spoofing exposure. Brand impressions on every delivered message, at inbox scale, in the one place competitors cannot buy placement. And, on the VMC path, a trust mark next to your name. If enforcement is already done and your audience is consumer at volume, the annual certificate is a marginal cost per impression. If either condition fails, spend the money finishing enforcement instead; you get the security outcome without the certificate.

Buy BIMI for the second thing and treat the first as the receipt.

SIGNALS IT IS WORKING
External recipients at Gmail, Yahoo, and Apple Mail see the logo, not just internal test traffic.
DMARC has stayed at enforcement since launch.
The certificate renewal and logo hash have a named owner and a date.
REPLACES
Buying a certificate on a vendor's open-rate promise and discovering a quarter later that the logo never rendered outside your own building.