BIMI: the logo in the inbox, and what it really requires
BIMI is the standard behind the brand logos next to messages in Gmail, Yahoo and Apple Mail. It is often pitched as a marketing feature — and the visibility is real — but its actual design is an incentive scheme: the logo is a reward receivers hand out for finished email authentication. Which means the question "how do we get our logo in the inbox" decomposes into work you should want anyway.
The prerequisite is enforcement, not a record
BIMI requires DMARC at enforcement: p=quarantine (at full strength, no pct carve-out) or p=reject — and receivers look at your subdomain policy too. This is the step that stalls most BIMI projects, because a logo request suddenly turns into an authentication cleanup. If your domain is still at p=none, the honest path starts at the path to reject, and the logo is what you pick up at the end of it. The rationale is sound: displaying your brand mark beside a message is a trust statement, and receivers only make it when your policy guarantees forged mail is not getting through.
The record and the logo file
The BIMI record itself is one TXT entry (default._bimi on your domain) pointing at your logo. The logo must be an SVG in a restricted profile — SVG Tiny with scripting and external references stripped — served over HTTPS. Square, simple, legible at 16 pixels: this is favicon thinking, not brochure thinking. Publishing record and file costs an hour; some receivers stop there and show the logo on that basis alone.
The certificate, and whether it is worth it
The largest receivers — Gmail and Apple among them — additionally require a Verified Mark Certificate: a certificate from an authorized issuer attesting that the logo is genuinely your mark, historically requiring a registered trademark and priced in the high hundreds of dollars per year (a newer Common Mark tier relaxes the trademark requirement somewhat). This is where the cost-benefit question genuinely lives, and the answer differs by sender: for a consumer brand sending at volume, inbox real estate plus the anti-phishing signal can be easily worth it; for a small B2B sender, publishing the record without a certificate — logo shown at some receivers, ignored at others — is a defensible stopping point.
The takeaway
Treat BIMI as a milestone marker: everything it requires — full enforcement, aligned authentication on every sender, records that stay correct — is exactly the state a well-run domain wants regardless of logos. Get there first, and BIMI becomes an afternoon; chase the logo first, and it becomes a project. Sojka's record checks include the BIMI record, and the readiness advisor tells you how far enforcement is.
Related: From p=none to p=reject without breaking your own mail · Why DMARC is worth having before anything goes wrong.
Check your domain free — it reads your public DNS and grades what is there.