BIMI works with DMARC by requiring your domain to have a DMARC policy set to enforcement before email clients will display your brand logo next to messages. Specifically, your DMARC policy must be set to either quarantine or reject — a policy of none is not sufficient. BIMI essentially rewards domains that have already done the hard work of locking down their authentication. The sections below walk through each layer of that relationship, from DNS records to real-world failure scenarios.
What does BIMI require from your DMARC setup?
BIMI requires your domain to have a DMARC policy at the enforcement level, meaning the policy tag must be set to p=quarantine or p=reject. A monitoring-only policy of p=none does not qualify. Beyond the policy level, your domain must also be passing DMARC alignment, meaning your sending infrastructure must be properly configured so that either SPF or DKIM aligns with the From domain on your messages.
Think of DMARC enforcement as the gatekeeper. Email clients that support BIMI use it as a trust signal before they will even consider rendering your logo. If your DMARC record exists but your policy is still at none, you are essentially telling mailbox providers that you are still monitoring your email streams rather than actively protecting them. BIMI is designed for senders who have moved past that stage.
There is also a practical readiness consideration. Before moving your DMARC policy to enforcement, you should have confidence that all of your legitimate sending sources are authenticated. Jumping to reject prematurely can cause legitimate mail to be blocked. The recommended path is to move gradually from none to quarantine while monitoring your DMARC aggregate reports, then advance to reject once you are confident all legitimate traffic is covered.
What is a Verified Mark Certificate and do you need one?
A Verified Mark Certificate, or VMC, is a digital certificate issued by a certified authority that cryptographically ties your brand logo to your domain. It acts as proof that you own the trademark associated with the logo you want displayed in the inbox. Whether you need one depends on which email clients you are targeting and how they have chosen to implement BIMI.
When a VMC is required
Gmail and Apple Mail, two of the highest-volume BIMI-supporting clients, require a VMC before they will display your logo. Without one, even a perfectly configured BIMI DNS record will not trigger logo display in these environments. The VMC requirement exists because these providers want to prevent brand impersonation, ensuring that only the legitimate trademark owner can display a given logo.
When a VMC is optional
Some smaller or emerging BIMI implementations allow logo display without a VMC, relying solely on DMARC enforcement as the trust signal. However, since the largest mailbox providers require it, treating the VMC as a mandatory component is the practical approach for most senders who want meaningful reach. Your logo must also be in SVG Tiny PS format and hosted at a publicly accessible HTTPS URL.
How does the BIMI DNS record connect to DMARC enforcement?
The BIMI DNS record does not directly reference your DMARC record, but mailbox providers check both independently before rendering your logo. Your BIMI record is a TXT entry published at a specific subdomain of your sending domain, typically default._bimi.yourdomain.com, and it contains the URL of your logo file and, optionally, your VMC. Mailbox providers look up this record only after confirming that your domain passes DMARC at an enforcement level.
The connection is sequential rather than structural. When an email arrives, the receiving mail system evaluates SPF and DKIM, then checks DMARC alignment and policy. If the message passes DMARC under a quarantine or reject policy, the mail client may then look up the BIMI record to retrieve your logo. If DMARC fails or the policy is too permissive, the BIMI lookup never happens regardless of how well your DNS record is configured.
This design means that fixing your BIMI record will never compensate for a weak DMARC setup. The two are interdependent from a workflow perspective even though they live in separate DNS records with no direct technical linkage between them.
Which email clients support BIMI with DMARC today?
As of 2026, Gmail, Apple Mail, Yahoo Mail, and Fastmail are among the email clients with active BIMI support. Gmail was one of the earliest major adopters and remains the most significant in terms of subscriber volume for most senders. Each provider has implemented BIMI slightly differently, particularly around VMC requirements and the level of DMARC policy they enforce.
Outlook and Microsoft 365 have their own brand logo display system called BIMI-adjacent indicators, but they do not follow the open BIMI standard in the same way. This means that even a fully compliant BIMI setup will not trigger logo display in Outlook environments without separate configuration through Microsoft’s own program.
Coverage is growing but uneven. Before investing significant effort in BIMI implementation, it is worth auditing your subscriber list to understand which email clients your audience actually uses. If a large portion of your list opens mail in environments that do not yet support BIMI, the immediate return on that investment will be limited, even though the DMARC enforcement work you do along the way benefits your deliverability regardless.
Why does BIMI fail even when DMARC is configured correctly?
BIMI can fail despite correct DMARC configuration for several reasons unrelated to your policy settings. The most common causes include an incorrectly formatted SVG logo file, an expired or improperly issued VMC, a BIMI DNS record with syntax errors, or a logo hosted at an HTTP rather than HTTPS URL. Each of these will silently prevent logo display without affecting your DMARC pass rate.
Logo format is a frequent stumbling block. The BIMI specification requires SVG Tiny PS format, which is a specific subset of SVG. Standard SVG files exported from design tools often include elements that are not compliant with this profile. Many senders discover this only after their BIMI record is live and the logo still does not appear.
VMC validity is another common failure point. VMCs have expiration dates, and if a certificate lapses, mailbox providers will stop rendering the logo until it is renewed. It is worth treating VMC renewal as a recurring calendar item rather than a one-time task.
Finally, some failures come down to DNS propagation timing or TTL settings. If you recently updated your BIMI record or moved your logo to a new URL, allow sufficient time for changes to propagate before concluding that something is broken. Testing with a BIMI inspection tool after any change is a reliable way to confirm that your record is being read correctly before troubleshooting further.
How Email Industries helps with BIMI and DMARC authentication
Getting BIMI to work correctly requires more than publishing a DNS record. It means having a fully enforced DMARC policy, properly authenticated sending infrastructure, a compliant logo file, and a valid VMC all working together. We help organizations work through every layer of that stack, from auditing existing authentication gaps to guiding DMARC policy progression and validating BIMI implementation end to end. Our work in this area includes:
- DMARC record audits and policy advancement from none to enforcement
- SPF and DKIM alignment reviews across all sending sources
- BIMI DNS record setup and SVG logo format validation
- VMC procurement guidance and renewal tracking
- Ongoing monitoring to catch authentication failures before they affect inbox placement
Whether you are just starting your DMARC journey or troubleshooting a BIMI setup that should be working but is not, our email authentication services are built to move you forward. If you want expert eyes on your current setup, explore our deliverability assurance packages or reach out to us directly to talk through where things stand.
Related Articles
- What are the BIMI requirements email senders must meet?
- What is an SPF record and what is it used for?
- What happens if your SPF record is misconfigured?
- How do you maintain inbox placement during an email platform migration?
- Why do emails go to spam after migrating to a new platform?
- How does email platform migration affect your IP reputation?
- How do you choose the right email platform to migrate to?
- How are full service email agencies adapting to AI and automation?
- When should you pause your IP warming schedule?
- What is the difference between IP warmup and domain warmup?
- What is domain warmup in email marketing?
- How long does it take to see results from an email marketing services agency?
- How do agencies develop annual email marketing plans?
- How do email marketing agencies create campaign strategies?
- What tools do professional email agencies use?


