Email Security

BIMI: Display Your Shopify Logo in Customer Inboxes

Learn how BIMI puts your brand logo next to your emails, building trust and protecting against email impersonation.

bimi email branding logo verification email security
Last updated

What is BIMI?

BIMI (Brand Indicators for Message Identification) is an email standard that displays your logo next to your emails in supporting inboxes. Instead of a generic icon or initials, customers see your actual brand logo—instantly recognizing your message as legitimate.

Think of it as a verified badge for email. When customers see your logo, they know the email really came from you.

Prerequisites for BIMI

BIMI only works when your email authentication is solid:

DMARC at Enforcement

Your DMARC policy must be set to quarantine or reject (not none). This proves you’ve implemented email authentication seriously.

Passing SPF and DKIM

Emails must pass authentication checks. BIMI won’t display if your email authentication is failing.

SVG Logo File

Your logo must be in a specific SVG format (Tiny PS), hosted at a publicly accessible URL.

Benefits for Shopify Merchants

Instant Recognition

Customers immediately identify your emails among dozens in their inbox. This increases open rates and engagement.

Trust Signal

A verified logo builds confidence. Customers know phishing emails won’t display your logo, so its presence indicates legitimacy.

Brand Consistency

Your visual identity extends into the inbox, reinforcing brand recognition across every customer touchpoint.

Competitive Advantage

Most brands haven’t implemented BIMI yet. Early adoption makes your emails stand out.

Setting Up BIMI

Step 1: Ensure DMARC Enforcement

Your DMARC record should have p=quarantine or p=reject. If you’re still at p=none, work through the DMARC implementation process first.

Create an SVG file meeting BIMI requirements:

  • Square dimensions (1:1 ratio)
  • SVG Tiny 1.2 or Portable/Secure format
  • Centered, no text below logo
  • Solid background (no transparency)

Upload the SVG to a publicly accessible HTTPS URL on your domain, like: https://yourstore.com/brand/logo.svg

Step 4: Create BIMI DNS Record

Add a TXT record:

  • Host: default._bimi
  • Value: v=BIMI1; l=https://yourstore.com/brand/logo.svg

Step 5: Verify Implementation

Use BIMI validator tools to check your setup. Monitor supported inboxes (Gmail, Apple Mail) to confirm logo display.

VMC Certificates: The Extra Layer

For maximum trust, consider a Verified Mark Certificate (VMC):

What is VMC?

A digital certificate from a certification authority that verifies you own the trademark associated with your logo.

Benefits

  • Required by Gmail for BIMI logo display
  • Provides legal verification of brand ownership
  • Adds stronger anti-spoofing protection

Costs

VMC certificates typically cost $1,000-1,500 per year and require a registered trademark.

For many Shopify merchants, starting without VMC is reasonable—you’ll get BIMI benefits in Apple Mail and other providers while evaluating whether VMC investment makes sense.

How Recon Helps

Recon supports your BIMI implementation by:

  • Verifying DMARC is at enforcement level (BIMI prerequisite)
  • Checking your BIMI DNS record is correctly configured
  • Monitoring email authentication to ensure BIMI continues working
  • Alerting you to issues that could prevent logo display

FAQ

Q: Which email providers support BIMI?

A: Apple Mail shows BIMI logos without VMC. Gmail requires VMC for logo display. Yahoo, AOL, and others support BIMI with varying requirements. Coverage continues to expand.

Q: Do I need a registered trademark for BIMI?

A: For basic BIMI (without VMC), no. For Gmail’s BIMI support (which requires VMC), you need a registered trademark to obtain the certificate.

Q: How long does BIMI take to start working?

A: After DNS propagation (24-48 hours), BIMI begins working. However, email providers may cache the logo, so initial appearance can vary. Give it a few days to fully propagate.

Want us to monitor this for you?

Run a free brand security audit with Recon and see your vulnerabilities in minutes.

Run Free Audit