Email & Domain Security

BIMI for MSPs: What It Is and Whether It's Worth Setting Up for Clients

BIMI puts a verified brand logo next to a client's mail in supporting inboxes — but only once DMARC is already enforced, not before. It is worth understanding precisely because clients ask for the badge without knowing what it depends on, and setting expectations correctly up front avoids a conversation later about why it "isn't working."

What BIMI is

Brand Indicators for Message Identification lets a domain publish a verified logo that supporting mail providers display next to authenticated messages from that domain — a visible, recognizable brand mark sitting where an anonymous sender icon or blank avatar would otherwise appear. The goal is recognition and trust signaling, not spam filtering or malware scanning.

It is published the same way as the authentication records it depends on: a DNS TXT record at a specific BIMI selector, pointing at a hosted logo file and, depending on the receiving provider, a certificate that verifies ownership of that logo.

The hard dependency: DMARC at enforcement, not p=none

BIMI only works once a domain's DMARC policy is at p=quarantine or p=reject. The reasoning is straightforward: a logo displayed next to mail tells the recipient "trust this," and providers will not make that promise unless spoofed mail from the domain is already being blocked rather than merely reported on. A domain still at p=none has no path to showing a BIMI logo, no matter how correctly the rest of the BIMI record is configured.

This is the detail that trips up clients who ask for BIMI as a quick branding win: it is not a parallel track that can be set up ahead of DMARC work to save time. It is the last step after DMARC enforcement is already stable, not a shortcut around it.

The Verified Mark Certificate question

Beyond the DNS record and logo, some of the largest mail providers require a Verified Mark Certificate before they will display a BIMI logo at all — a certificate that legally attests to logo ownership, issued against a registered trademark. This adds real cost and process: trademark registration, if the client does not already have one, plus the certificate issuance itself.

Other receiving providers display BIMI logos without requiring this certificate. The practical implication is that BIMI's payoff depends on which mail providers a client's actual recipients use — check that before setting expectations about how visible the logo will end up being, rather than assuming universal display once the record is published.

The logo file is the easy part

BIMI requires a square SVG image meeting a specific profile of the SVG format — not just any export from a design tool, which often includes markup the specification does not allow. Once a compliant file exists, hosting it and publishing the DNS record is comparatively simple. Most of the actual work in a BIMI rollout is the DMARC enforcement it depends on, not the logo itself.

Deciding which clients are ready

  • DMARC is already enforced at quarantine or reject, and has been stable — not recently changed to hit a deadline.
  • The client has, or is willing to pursue, a registered trademark if their priority mail providers require a Verified Mark Certificate.
  • The client understands BIMI is a visibility benefit on top of authentication already in place, not a replacement for it.

A client without enforced DMARC is not a BIMI candidate yet — the honest answer is to finish the authentication work first, and revisit BIMI once that foundation is actually in place.

Where BIMI fits in ongoing monitoring

Once BIMI is live, it depends on the same DMARC enforcement staying in place — if a policy gets weakened back to p=none to troubleshoot an unrelated delivery issue, the logo can stop displaying without anyone connecting the two changes. Checking BIMI status alongside SPF, DKIM, and DMARC as one authentication picture, rather than as an unrelated one-time setup, catches that kind of regression.

SecurityScore.me checks BIMI presence alongside graded DMARC, SPF, and DKIM as part of external domain monitoring. See domain and website monitoring for the full email-authentication picture, and the MSP security platform overview for how authentication status stays visible across a portfolio rather than as a one-time setup task.

Frequently asked questions

Learn more

Track BIMI and DMARC status together, across every client domain