BIMI (Brand Indicators for Message Identification) is an email standard that lets a business show its own logo next to its messages in supporting inboxes, once it has proved through email authentication that the mail really comes from its domain. The logo appears in the round avatar space where an initial or a blank icon would otherwise sit.
How BIMI works
BIMI sits on top of the email authentication you should already have. Your domain needs SPF and DKIM working and aligned with your From address, and a DMARC policy at enforcement: quarantine or reject, not the monitoring-only p=none. Without that, mailbox providers ignore the BIMI record entirely.
You then publish a TXT record in your domain’s DNS, usually at default._bimi.yourdomain.co.uk. It points to two things: your logo as an SVG file in a restricted format called SVG Tiny Portable/Secure, hosted over HTTPS, and, for most of the large inboxes, a mark certificate.
A verified mark certificate (VMC) is issued by a small group of certificate authorities after they confirm that the logo is your registered trademark and that you control the domain. A registration with the UK Intellectual Property Office is accepted. A newer common mark certificate (CMC) can cover a logo that is not registered, provided you can show it has been in public use on your website for a set period, typically a year. At the time of writing (October 2026), Gmail shows logos backed by either type, adding a blue tick only for a VMC; Apple Mail needs a VMC; and Yahoo may show a logo without any certificate for senders with a strong reputation. Check each provider’s current rules before paying for anything.
Why it matters for a UK business
The logo itself is a modest visual cue: a recognisable mark in a crowded inbox, and a signal to careful readers that the message passed checks. It does not lift you out of the spam folder, and I have not seen published evidence I would rely on for a dependable rise in clicks.
The real value is in what you must fix to qualify. Reaching DMARC enforcement means finding every service that sends as your domain, from the accounting package to the booking system, and authenticating each one. That work protects your customers from phishing that borrows your name and supports your deliverability. For a UK brand that criminals regularly imitate, such as a retailer or a firm that takes payments, that protection is worth far more than the logo.
Common mistakes
- Publishing a BIMI record while DMARC is still at p=none, then wondering why no logo appears.
- Uploading an ordinary SVG exported from design software. It must be converted to the Tiny Portable/Secure profile, square, with no scripts or external references.
- Buying a verified mark certificate before checking the trademark. The registered mark must match the logo you want to show.
- Forgetting subdomains. If marketing email goes out from a subdomain, that subdomain must also be covered by an enforced DMARC policy.
- Expecting the logo everywhere. Support varies by mailbox provider and app, so check which of the inboxes your subscribers actually use display BIMI logos before promising one to anyone.
How to act on it
Treat BIMI as the final step of an authentication project, not the first. Check your SPF, DKIM and DMARC records with a free checker or your email platform’s domain settings. Move DMARC from monitoring to quarantine and then reject, reading the aggregate reports as you go so nothing legitimate breaks.
Next, confirm the trademark position. If your logo is registered with the UKIPO in the form you use, a VMC is open to you; if not, decide whether a CMC is enough or whether to register the mark first. Prepare the SVG, host it on your own domain over HTTPS, publish the record and test it with a BIMI checker. If email is one of several channels you are weighing up, my digital marketing strategy work can help you decide where this sits among your priorities.
