Blog · Bimi
How to Get BIMI Working: The Prerequisites Most Teams Skip
What Is BIMI and Why It Is Worth the Effort
BIMI puts your logo next to your sender name in supported inboxes. Gmail, Apple Mail, Yahoo, and Fastmail currently show it. For brands that send transactional and marketing email at scale, it is a real visibility advantage.
The problem is that BIMI is almost universally described as "add a DNS record and you are done." That description is wrong just often enough to waste teams months of effort and a VMC they cannot yet use.
The BIMI Prerequisite Chain (In Order)
BIMI requires a specific sequence of authentication and configuration steps. Providers enforce each one before showing your logo. Skip a step or do it out of order, and your record publishes with no visible result.
Step 1: DKIM signing must be present and aligned
Your sending infrastructure must sign outgoing mail with DKIM using a key where the signing domain matches your From domain exactly. If your ESP (Email Service Provider) signs with their own domain instead of yours, this step fails silently. Most ESP-caused BIMI failures happen here. Your ESP dashboard may show DKIM as "configured" while still signing with the wrong domain.
Step 2: DMARC policy must be at p=quarantine minimum
p=none does not qualify. Providers require p=quarantine or p=reject before they will show your BIMI logo. This is the most commonly skipped prerequisite. Teams read about BIMI, check their DMARC, see p=none, and assume they are close enough. They are not.
This is also where DMARCFlow earns its place on this list. If you are tracking your DMARC policy in a monitoring tool, you will see immediately when your policy is still at p=none. Most teams pursuing BIMI discover their policy has been at p=none for months because nobody was watching the aggregate reports. DMARCFlow monitors that signal so you know when you have actually crossed the threshold, not just when you think you have.
Step 3: Your brand must have a registered trademark (for VMC)
Verified Mark Certificates require proof of a registered trademark matching the logo you want to display. The trademark must be registered with a recognized national or regional office such as the USPTO. Unregistered marks, common-law trademarks, and pending applications typically do not qualify.
Step 4: Obtain and install your certificate
Once your trademark status is confirmed, you apply for either a VMC or a CMC from an approved certificate authority. Issuance timelines vary. A VMC from DigiCert or Entrust can take anywhere from a few days to several weeks depending on trademark verification complexity. Your IT team then installs the certificate on your mail servers or passes it to your ESP for inclusion in BIMI-signed messages.
Step 5: Publish your BIMI DNS record
The BIMI record sits at default._bimi.yourdomain.com and points to your logo file (hosted on HTTPS) and optionally references a selector record if you use multiple VMCs for different sending contexts. Logo files must be PNG or SVG, under 32KB, and served over HTTPS with a valid certificate.
VMC vs CMC - Which Certificate Type to Choose
Two certificate types can power BIMI. The choice matters because it affects cost, timeline, mailbox provider support, and what evidence you need to provide.
VMC (Verified Mark Certificate)
- Issued by: DigiCert, Entrust, GlobalSign
- Evidence required: registered trademark matching your logo
- Cost range: approximately $500-$1,500 per year, per domain
- Timeline: typically 5-20 business days for new applications
- Mailbox support: Gmail, Apple Mail, Yahoo, Fastmail
VMC is the established option. It has the broadest mailbox provider support and the most mature CA ecosystem. If your trademark is registered and clean, the application process is straightforward.
CMC (Certified Mark Certificate)
- Issued by: a smaller set of certificate authorities including some newer entrants
- Evidence required: may accept broader proof of mark use, not limited to registered trademarks in some cases
- Cost range: typically lower than VMC, though the market is still developing
- Timeline: varies by CA
- Mailbox support: growing but more limited than VMC at present
CMC was designed to lower the barrier to entry for brands that use logos in commerce but have not yet registered them as trademarks. If your trademark application is pending, or if your logo differs from your registered company name, a CMC may be worth exploring. The tradeoff is narrower mailbox provider acceptance today.
Decision guide
If you have a registered trademark and need the broadest possible inbox support, VMC is the safer choice. If your trademark is pending or your brand logo does not match a registered mark, explore CMC carefully and verify your target mailbox providers accept it before paying.
One practical note: certificate authorities have different verification processes and timelines. DigiCert and Entrust are the dominant VMC issuers for email. Both publish detailed requirements on their websites. Read them before starting the application, not after.
How to Audit Your Domain for BIMI Readiness
Before spending money on a certificate, run this checklist against your sending domain.
DKIM check: Send a test message to a DMARC analyzer or your own inbox and inspect the DKIM signature. The d= domain must match your From address domain exactly. If your ESP is signing with their own domain, that is a problem that must be fixed before BIMI can work.
DMARC policy check: Look up your DMARC record. The p= tag must be set to quarantine or reject. If it is none, BIMI will not activate regardless of your DNS configuration.
Alignment check: Even with DKIM present, the signing domain must align with your From domain under DMARC alignment rules. Misaligned DKIM is a common silent failure mode.
Trademark check: Do you have a registered trademark for your logo? If not, VMC is not available yet. Consider whether your trademark application is far enough along to justify waiting versus pursuing a CMC.
Logo file readiness: If you have not already prepared your logo in PNG (32KB max) or SVG format served over HTTPS, add that to your pre-flight list.
Common Reasons BIMI Fails Silently
Teams publish their BIMI record, wait a few days, and see nothing. Usually one of the following is responsible.
DKIM not aligned. The most common cause. ESPs often sign with their own domain by default. This passes SPF and DKIM checks but fails DMARC alignment, which is a prerequisite for BIMI. The ESP dashboard usually says DKIM is configured. It is, just not for your domain.
DMARC at p=none. Second most common. Teams enable DMARC monitoring but never move to enforcement. BIMI requires p=quarantine or p=reject. The policy looks active so it feels done.
Logo file not accessible. The logo URL in the BIMI record must be publicly accessible over HTTPS without authentication. Local network URLs, intranets, and URLs behind login screens will not work.
Certificate expired or revoked. Certificates must remain valid. Expired VMCs cause BIMI to stop working without notice.
Selector record missing. If you use multiple sending domains or multiple VMCs, you need a selector record. Most teams with a single domain and a single VMC do not need one, but misconfigured selectors are a source of silent failures.
FAQ
Does p=none qualify for BIMI?
No. BIMI requires p=quarantine or p=reject. p=none is monitoring mode and mailbox providers do not display BIMI logos for domains in monitoring mode.
How long does a VMC take to issue?
For domains with a registered USPTO trademark, issuance typically takes 5-15 business days. Complex cases with international trademarks or disputes can take longer. CMC issuance varies more widely depending on the CA and evidence requirements.
Can I use BIMI without a trademark certificate?
Not with current mailbox provider requirements for VMC or CMC. Some CAs are exploring unregistered-mark options within the CMC framework, but support from Gmail and Apple Mail for those alternatives is not yet confirmed.
Does BIMI work with subdomains?
BIMI is published at the organizational domain level. Subdomain senders typically need their own BIMI record on their specific subdomain or must rely on the organizational domain's BIMI record, depending on the provider's implementation.
My ESP handles BIMI for me. What do I need to check?
Ask your ESP: (1) Is DKIM signed with our From domain, not yours? (2) What is our current DMARC policy? (3) Who holds the VMC and how is it installed? (4) Can we see BIMI aggregate reports? If the ESP cannot answer these four questions clearly, dig deeper before assuming BIMI is working.