---
title: "BIMI: How to Set It Up (and Why It Needs DMARC) | AutoSPF"
description: "What BIMI is, how it displays your logo in the inbox, the VMC certificate, and why it requires a DMARC policy at enforcement. A practical setup guide."
image: "https://autospf.com/images/og-default.png"
canonical: "https://autospf.com/email-authentication/bimi/"
---

# BIMI: Your Logo in the Inbox

A typical user receives multiple emails a day, some of which are essential updates or personal messages, while others are marketing emails from various brands. In this crowded inbox, what are the odds that your email will stand out and strike a chord with the recipient? Let’s say it’s quite slim unless you add something unique to capture the reader’s attention.

This guide is part of our guide to [email authentication](/email-authentication/). Related: [MTA-STS](/email-authentication/mta-sts/) and [DKIM vs DMARC](/email-authentication/dkim-vs-dmarc/).

A typical user receives multiple emails a day, some of which are essential updates or personal messages, while others are marketing emails from various brands. In this crowded inbox, what are the odds that your email will stand out and strike a chord with the recipient? Let’s say it’s quite slim unless you add something unique to capture the reader’s attention. 

_BIMI (Brand Indicators for Message Identification) displays a brand’s verified logo next to authenticated emails in supporting clients (Gmail, Apple Mail, Yahoo). BIMI requires a DMARC policy of `quarantine` or `reject` \- `p=none` is not sufficient. A Verified Mark Certificate (VMC) from DigiCert or Entrust is required for Gmail logo display._

If you want to add a credibility factor and jazz to your marketing emails, showing your brand’s logo next to your emails can be a game-changer. It’s not just another [marketing tactic](https://www.designrush.com/news/proven-email-marketing-tactics-re-engage-non-converting-website-users) but also about building trust and reinforcing your [brand identity](https://www.investopedia.com/terms/b/brand-identity.asp). _When the logo appears right next to your email, it gives a sense of familiarity, which means that your audience recognizes your brand at a glance_.

This is where [Brand Indicators for Message Identification](https://en.wikipedia.org/wiki/Brand%5FIndicators%5Ffor%5FMessage%5FIdentification) (BIMI) comes in. BIMI enables you to display your authenticated, verified logo next to any authenticated emails, adding a certain level of professionalism and credibility.

Let us dig deeper into what BIMI is and how you can set it up. 

## What is BIMI?

BIMI is a tool that allows you to display your brand’s logo alongside your emails in recipients’ inboxes. In reality, it’s a lot more than a design update; it makes emails feel more authentic and trustworthy when they reach the user’s inbox. After all, when people see your verified logo alongside your email, its chances of being trusted become significantly higher, especially during times like these when every other email you come across is a [phishing attempt](https://thehackernews.com/2024/03/new-strelastealer-phishing-attacks-hit.html) or spam. 

What makes this protocol so unique and relied upon is the fact that it works hand-in-hand with other [email security](/) protocols, including SPF, DKIM, and DMARC. All these protocols ensure that your emails are legitimate and haven’t been tampered with, so when your logo shows up, it tells the users that it is backed by a layer of security and, obviously, the email is safe to engage with. 

_One can say that BIMI builds a cohesive brand in inboxes and makes your emails stand out for all the right reasons, without gimmicks_. If you want to build trust while improving thevisibility of your messages, BIMI is the best tool in your arsenal.

## Why is BIMI so important?

If you already have [SPF](/blog/what-is-spf-email-a-guide-to-sender-validation-technology/), DKIM, and DMARC implemented, you might wonder if it is really necessary to implement BIMI as well. Truth be told, it is not mandatory, but it has become almost non-negotiable to reinforce credibility and trust in the [ever-evolving threat landscape](https://cybermagazine.com/articles/the-rapidly-evolving-threat-landscape-of-2024). 

Here are some of the reasons why you should implement BIMI for your domain:

![ever-evolving threat landscape](https://media.mailhop.org/autospf/images/2024/12/spf-flattening-2.jpg) 

### To elevate your brand presence 

With BIMI, you can turn your emails into an extension of your brand identity by displaying your logo along with them. Your logo takes center stage among the generic-looking emails that flood the recipient’s inbox. 

### To build trust 

Sure, implementing SPF, [DKIM](/tools/dkim-lookup/), and DMARC adds a layer of security that your recipients deserve, but the problem with these protocols is that your audience never sees them in action on the front end. BIMI gives them a clear signal of authenticity, encouraging them to open your emails with more confidence.

### To enhance engagement 

It goes without saying that emails that look trustworthy and professional are more likely to be opened and interacted with. _To achieve this, you need BIMI in addition to your existing authentication protocols_. It complements your existing security by improving the user experience and engagement.

### To show your commitment to security 

Implementing BIMI tells your audience that your organization is not just a company that follows security [best practices](/blog/spf-best-practices-cisos-guide-to-email-security/) \- it goes the extra mile to make communication safer and more transparent for them.

### To stay above the competition 

In a crowded inbox where ever email is fighting to garner attention, the one with a logo will surely stand out. If you do not have your logo next to the email, chances are that your email will be perceived as less professional or even suspicious.

As more and more brands send out emails with their logos attached to them, it is no longer about keeping pace; it is about staying ahead. 

## What are the prerequisites for implementing BIMI?

You need to properly set up BIMI to be able to display your [brand’s logo](https://www.theverge.com/2021/7/12/22573813/google-authenticated-brand-logos-gmail-rolling-out-bimi-dmarc) along with your outgoing emails, and for this, it is important to meet certain requirements. Without these, you will be unable to implement BIMI and establish the trust and credibility that you strive for.

Let’s look at some of the requirements that you cannot skip when adopting BIMI:

### Properly implemented DMARC

The first thing you need to enforce BIMI is to properly configure DMARC for your sending domain. Unless you don’t verify the authenticity of your emails with a [DMARC policy](https://knowledgebase.constantcontact.com/email-digital-marketing/articles/KnowledgeBase/7644-What-is-DMARC?lang=en%5FUS) (at p= quarantine or p=reject), BIMI won’t work. [DMARC](/fraudmarc-alternatives/) ensures that the receiving servers know that incoming email is truly coming from your domain, a trusted source. For that to hold, your SPF record must stay within [the 10 DNS lookup limit](/spf-too-many-dns-lookups/), or a PermError will quietly undermine DMARC and, with it, BIMI.

_To implement DMARC, it is important that you have either SPF or DKIM (ideally both) set up_. Once you have these authentication protocols up and running for your email-sending domain, you’re one step closer to adopting BIMI. Run an [SPF checker](/tools/spf-checker/) to confirm your record is valid before you move on.

### A logo that meets BIMI standards 

Yes, you need your brand’s logo to set up BIMI, but it cannot be in any random format or size. For your logo to be shown in your emails, it should be in [SVG Tiny 1.2 format](https://www.entrust.com/knowledgebase/ssl/how-to-convert-your-svg-logo-to-tiny-ps-format-for-use-in-verified-mark-certificates) so that it is clearly visible and scalable. _The next thing is that your logo should be square-shaped with a simple design with a transparent background_. Another thing you must keep in mind while selecting your logo BIMI is that it must be hosted on an [HTTPS server](https://hyperskill.org/learn/step/25834), and do not forget to include its URL in your BIMI DNS record.

### A trademarked logo without any extra text 

To set up BIMI, your logo should be trademarked but if your company’s logo has any kind of extra text or tagline, you might be in a fix. So make sure your logo does not include any of these. 

Well, if you do not have a trademarked logo, you can still use it to set up BIMI. Thanks to the [Common Mark Certificates](https://www.thesslstore.com/blog/common-mark-certificates-make-it-easier-to-display-your-logo-in-gmail/) (CMC) that Google introduced in October 2024, which make things a lot easier.

### A Verified Mark Certificate (VMC) from an approved authority 

If you want your logo to appear alongside your emails with BIMI, you will need a [Verified Mark Certificate](https://www.digicert.com/faq/email-trust/what-is-a-verified-mark-certificate) (VMC), which is essentially proof that you own your logo and have permission to use it. You can apply for your VMC and get it from approved authorities such as DigiCert or Entrust, among others. It helps establish that your brand is legitimate and your emails are safe.

## What are the steps you should follow to implement BIMI?

Now that we know what all you need to set up BIMI, let’s take you through the entire process of implementing the protocol so that you can display your logo next to your emails without a hitch.

![email-sending](https://media.mailhop.org/autospf/images/2024/12/spf-record-syntax-1512.jpg) 

### How Do You Implement and Enforce DMARC?

First things first, you need to implement DMARC for your email-sending domain. While you’re at it, make sure that your DMARC policy is set to a stricter level, like p=quarantine or p=reject, instead of p=none. Without this enforcement, BIMI will not work because it relies on DMARC to validate the [legitimacy of your emails](https://www.usatoday.com/story/tech/2021/08/23/gmail-spam-filter-email-inbox-google/8242847002/).

### Get your logo ready 

_The next thing you need for BIMI is your logo. But as we discussed earlier, it should be in a specific format and size (SVG Tiny 1.2), and only then will you be able to upload it_. Your logo should also be square with a simple design and a transparent background. These details matter as email clients display your logo in small sizes, and if your logo is too busy, it will not be properly visible to the recipients. 

### Host your logo 

Once you have your logo ready, it’s time to host it on a [web-accessible location](https://www.forbes.com/councils/forbesbusinesscouncil/2023/03/20/understanding-the-importance-of-web-accessibility/) (HTTPS). This is where the email providers will pick your logo from and display it in recipients’ inboxes. The location you choose should be reliable and the URL is stable. 

### Create a BIMI DNS record 

Next up, create a BIMI record in TXT format. It should look something like:

_default.\_bimi.example.com IN TXT “v=BIMI1; l=<https://example.com/path-to-logo.svg>_

_v=BIMI1: is the BIMI version._

_l=: is the URL of your hosted logo._

### Publish your BIMI record

After you have created the BIMI [TXT record](https://dnsmadeeasy.com/post/what-is-a-txt-record), you’ve to add it to your domain’s [DNS settings](https://www.ntchosting.com/encyclopedia/dns/settings/). This will ensure that all participating email servers have access to the BIMI information. 

### Get a VMC

As we discussed earlier, a VMC (Verified Mark Certificate) is important for BIMI, so if you do not already have a certificate from an approved authority, make sure to get one. Once you do, you can add the VMC to your [BIMI record](https://manage.accuwebhosting.com/knowledgebase/4490/What-is-a-BIMI-Record.html) using the a= tag.

### How Do You Verify and Monitor?

You’re almost done with your BIMI set up. To ensure that the BIMI record is configured properly and the logo is visible next to your emails, it’s best to test it. For this you can use a [BIMI lookup tool](https://www.mailmodo.com/tools/bimi-checker/) and keep an eye on [DMARC reports](/kitterman-alternatives/) to identify any authentication failures. Understanding [why check SPF regularly](/10-reasons-for-regular-spf-record-checks-in-cybersecurity/) matters here too, since drift in your record can break BIMI long after setup.

Rated 5/5 on G2 · Trusted since 2018 

##  Trusted by 50,000+ domains 

### "AutoSPF Flattens SPF Records Seamlessly & Keeps Changes Logged - I am quite pleased with the product"

> It does what it promises to do, and does it very well. I appreciate that it keeps a log of changes made, which prevents many mistakes. A client's SPF record would have way too many lookups, but AutoSPF makes that problem go away. The length of the SPF record is typically not the issue; it's the amount of lookups in the record that are. AutoSPF "flattens" the record, automatically expanding the defined lookups to IP addresses or ranges. And it auto-updates the record when the un-flattened lookups change. 

 PJ 

Peter J.

 President · Small-Business (50 or fewer emp.) 

### "Helped us go beyond capacity"

> AutoSPF did exactly as described, it helped us get past our 10 lookup limit. Afterwards, we hit another limit regarding overall capacity and when contacted, they quickly provided us with a new solution to eliminate capacity issues entirely going forward, so now we can add as many SPF records as needed. They also provided us with a personalized support video explaining their new method in its entirety using our instance as the example. 

 VU 

Verified User

 Financial Services · Mid-Market (51-1000 emp.) 

### "Great service and great support"

> AutoSPF was easy to initially set up on our own and a great cost effective entry into spf flattening. Needed our first support assistance today and got great response including a video demonstrating the issue I was trying to solve, a quick fix, and more detailed followup. 

 GF 

Greg F.

 Mid-Market (51-1000 emp.) 

[Read our reviews on G2 ](https://www.g2.com/products/autospf/reviews)

```json
{"@context":"https://schema.org","@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138897474","https://www.linkedin.com/company/autospf","https://x.com/autospf01","https://www.facebook.com/autospf","https://github.com/duocircle","https://www.g2.com/products/autospf/reviews"],"aggregateRating":{"@type":"AggregateRating","ratingValue":"5.0","reviewCount":"21","bestRating":"5","worstRating":"1","url":"https://www.g2.com/products/autospf/reviews"},"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://autospf.com/contact-us/"},"knowsAbout":["SPF Record Flattening","Sender Policy Framework","Email Authentication","DNS Management","DMARC","DKIM","Email Deliverability","SPF Lookup Limits"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"AutoSPF","url":"https://autospf.com","description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","publisher":{"@type":"Organization","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
{"@context":"https://schema.org","@type":"FAQPage","mainEntity":[{"@type":"Question","name":"How Do You Implement and Enforce DMARC?","acceptedAnswer":{"@type":"Answer","text":"First things first, you need to implement DMARC for your email-sending domain. While you’re at it, make sure that your DMARC policy is set to a stricter level, like  p=quarantine or p=reject, instead of p=none. Without this enforcement, BIMI will not work because it relies on DMARC to validate the [legitimacy of your emails](https://www.usatoday.com/story/tech/2021/08/23/gmail-spam-filter-email-inbox-google/8242847002/)."}},{"@type":"Question","name":"How Do You Verify and Monitor?","acceptedAnswer":{"@type":"Answer","text":"You’re almost done with your BIMI set up. To ensure that the BIMI record is configured properly and the logo is visible next to your emails, it’s best to test it. For this you can use a [BIMI lookup tool](https://www.mailmodo.com/tools/bimi-checker/) and keep an eye on [DMARC reports](/kitterman-alternatives/) to identify any authentication failures. Understanding [why check SPF regularly](/10-reasons-for-regular-spf-record-checks-in-cybersecurity/) matters here too, since drift in your record can break BIMI long after setup."}}]}
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://autospf.com/"},{"@type":"ListItem","position":2,"name":"Email Authentication","item":"https://autospf.com/email-authentication/"},{"@type":"ListItem","position":3,"name":"BIMI","item":"https://autospf.com/email-authentication/bimi/"}]}
```

```json
{"@context":"https://schema.org","@type":"Product","name":"AutoSPF","url":"https://autospf.com","aggregateRating":{"@type":"AggregateRating","ratingValue":5,"reviewCount":21,"bestRating":5,"worstRating":1},"review":[{"@type":"Review","reviewRating":{"@type":"Rating","ratingValue":5,"bestRating":5},"author":{"@type":"Person","name":"Peter J.","jobTitle":"President"},"datePublished":"2026-03-10","reviewBody":"It does what it promises to do, and does it very well. I appreciate that it keeps a log of changes made, which prevents many mistakes. A client's SPF record would have way too many lookups, but AutoSPF makes that problem go away. The length of the SPF record is typically not the issue; it's the amount of lookups in the record that are. AutoSPF \"flattens\" the record, automatically expanding the defined lookups to IP addresses or ranges. And it auto-updates the record when the un-flattened lookups change.","name":"AutoSPF Flattens SPF Records Seamlessly & Keeps Changes Logged - I am quite pleased with the product","publisher":{"@type":"Organization","name":"G2","url":"https://www.g2.com"}},{"@type":"Review","reviewRating":{"@type":"Rating","ratingValue":5,"bestRating":5},"author":{"@type":"Person","name":"Verified User","jobTitle":"Financial Services"},"datePublished":"2025-07-31","reviewBody":"AutoSPF did exactly as described, it helped us get past our 10 lookup limit. Afterwards, we hit another limit regarding overall capacity and when contacted, they quickly provided us with a new solution to eliminate capacity issues entirely going forward, so now we can add as many SPF records as needed. They also provided us with a personalized support video explaining their new method in its entirety using our instance as the example.","name":"Helped us go beyond capacity","publisher":{"@type":"Organization","name":"G2","url":"https://www.g2.com"}},{"@type":"Review","reviewRating":{"@type":"Rating","ratingValue":5,"bestRating":5},"author":{"@type":"Person","name":"Greg F."},"datePublished":"2023-07-26","reviewBody":"AutoSPF was easy to initially set up on our own and a great cost effective entry into spf flattening. Needed our first support assistance today and got great response including a video demonstrating the issue I was trying to solve, a quick fix, and more detailed followup.","name":"Great service and great support","publisher":{"@type":"Organization","name":"G2","url":"https://www.g2.com"}}]}
```
