What is BIMI?
BIMI (Brand Indicators for Message Identification) is an email standard that displays your logo next to your emails in supporting inboxes. Instead of a generic icon or initials, customers see your actual brand logo—instantly recognizing your message as legitimate.
Think of it as a verified badge for email. When customers see your logo, they know the email really came from you.
Prerequisites for BIMI
BIMI only works when your email authentication is solid:
DMARC at Enforcement
Your DMARC policy must be set to quarantine or reject (not none). This proves you’ve implemented email authentication seriously.
Passing SPF and DKIM
Emails must pass authentication checks. BIMI won’t display if your email authentication is failing.
SVG Logo File
Your logo must be in a specific SVG format (Tiny PS), hosted at a publicly accessible URL.
Benefits for Shopify Merchants
Instant Recognition
Customers immediately identify your emails among dozens in their inbox. This increases open rates and engagement.
Trust Signal
A verified logo builds confidence. Customers know phishing emails won’t display your logo, so its presence indicates legitimacy.
Brand Consistency
Your visual identity extends into the inbox, reinforcing brand recognition across every customer touchpoint.
Competitive Advantage
Most brands haven’t implemented BIMI yet. Early adoption makes your emails stand out.
Setting Up BIMI
Step 1: Ensure DMARC Enforcement
Your DMARC record should have p=quarantine or p=reject. If you’re still at p=none, work through the DMARC implementation process first.
Step 2: Prepare Your Logo
Create an SVG file meeting BIMI requirements:
- Square dimensions (1:1 ratio)
- SVG Tiny 1.2 or Portable/Secure format
- Centered, no text below logo
- Solid background (no transparency)
Step 3: Host Your Logo
Upload the SVG to a publicly accessible HTTPS URL on your domain, like:
https://yourstore.com/brand/logo.svg
Step 4: Create BIMI DNS Record
Add a TXT record:
- Host:
default._bimi - Value:
v=BIMI1; l=https://yourstore.com/brand/logo.svg
Step 5: Verify Implementation
Use BIMI validator tools to check your setup. Monitor supported inboxes (Gmail, Apple Mail) to confirm logo display.
VMC Certificates: The Extra Layer
For maximum trust, consider a Verified Mark Certificate (VMC):
What is VMC?
A digital certificate from a certification authority that verifies you own the trademark associated with your logo.
Benefits
- Required by Gmail for BIMI logo display
- Provides legal verification of brand ownership
- Adds stronger anti-spoofing protection
Costs
VMC certificates typically cost $1,000-1,500 per year and require a registered trademark.
For many Shopify merchants, starting without VMC is reasonable—you’ll get BIMI benefits in Apple Mail and other providers while evaluating whether VMC investment makes sense.
How Recon Helps
Recon supports your BIMI implementation by:
- Verifying DMARC is at enforcement level (BIMI prerequisite)
- Checking your BIMI DNS record is correctly configured
- Monitoring email authentication to ensure BIMI continues working
- Alerting you to issues that could prevent logo display
FAQ
Q: Which email providers support BIMI?
A: Apple Mail shows BIMI logos without VMC. Gmail requires VMC for logo display. Yahoo, AOL, and others support BIMI with varying requirements. Coverage continues to expand.
Q: Do I need a registered trademark for BIMI?
A: For basic BIMI (without VMC), no. For Gmail’s BIMI support (which requires VMC), you need a registered trademark to obtain the certificate.
Q: How long does BIMI take to start working?
A: After DNS propagation (24-48 hours), BIMI begins working. However, email providers may cache the logo, so initial appearance can vary. Give it a few days to fully propagate.
Want us to monitor this for you?
Run a free brand security audit with Recon and see your vulnerabilities in minutes.
Run Free AuditRelated Articles
DMARC: Email Authentication Explained
Understand DMARC and how it prevents email spoofing to protect your Shopify brand from phishing attacks.
DKIM: Digital Signatures for Your Shopify Store Emails
Understand how DKIM adds digital signatures to prove your Shopify emails are authentic and haven't been tampered with.
Email Spoofing: When Criminals Impersonate Your Shopify Store
Discover how scammers send fake emails from your domain and the steps to stop email spoofing attacks.