You may have noticed some senders show a circular brand logo in Gmail while yours shows a grey initial. That is BIMI — Brand Indicators for Message Identification. Getting it is less about the logo and more about the email authentication underneath it.
The prerequisite nobody skips past
BIMI only displays if your domain enforces DMARC at quarantine or reject. Not “none”. That means SPF and DKIM must be correct and aligned first, and you must have moved through monitoring to enforcement without breaking your legitimate mail.
This is the real work, and it is worth doing regardless of logos — DMARC enforcement is what stops criminals sending invoices as you.
The path, in order
- Publish SPF listing every service that sends on your behalf
- Enable DKIM signing on each of those services
- Publish DMARC at p=none and collect reports
- Fix what the reports reveal — there is always something forgotten
- Move to p=quarantine, then p=reject
- Only then, add BIMI
The logo requirements
The logo must be SVG Tiny P/S — not a normal SVG export. Square, centred, solid background. Most design teams need one attempt to get the format right.
The VMC question
Some mailbox providers, including Gmail, require a Verified Mark Certificate — which requires a registered trademark for your logo. This is the step that stops most organisations, and it is a genuine cost. If you do not hold a trademark, BIMI display is limited.
Is it worth it?
The logo itself is a modest gain. The DMARC enforcement you have to do first is a significant one — it removes an entire category of fraud committed in your name. Treat BIMI as the reward for doing the authentication properly, not as the goal.
We handle DMARC from first report to full enforcement, without breaking your mail flow. Ask for a free authentication check on your domain.