LeadHaste

BIMI: What the Logo in the Inbox Actually Requires

Christian Sørensen
Christian Sørensen·Sep 26, 2026·8 min read

Summarize with AI

BIMI displays your logo beside your sender name in mailbox providers that support it, and the logo is the reward for finishing DMARC enforcement on the domain in question. That ordering decides who should be reading this. If the domain already carries enforcement on itself and its subdomains, BIMI costs a certificate and a design round. If it does not, BIMI is a quarter of authentication work wearing a visual incentive.

The Gate Is DMARC Enforcement, Not the Logo File

The BIMI Group implementation guide puts the authentication requirement before anything visual. DMARC policy "MUST be at enforcement on the organizational domain and subdomains," which the guide spells out as either "Quarantine (p=quarantine; sp=quarantine)" or "Reject policy (p=reject; sp=reject)."

Two details in that sentence decide eligibility before the artwork does.

The first is sp. Enforcement on the organizational domain is not sufficient by itself; the subdomain policy has to match. A domain that reached p=reject on the main domain can still carry sp unset or parked at none to protect a billing system or a support desk sending from a subdomain. That exception is a reasonable operating choice, and it disqualifies the domain for BIMI until the subdomain traffic is cleaned up.

The second is the percentage tag. The guide states plainly that "'None' policies or 'pct' less than 100 percent are not accepted." A staged rollout sitting at pct=50 while the team watches reports is not at enforcement for this purpose, even though the policy value reads reject.

Both conditions are DMARC gaps that a BIMI evaluation surfaces, which is what makes the evaluation worth running even if the logo never ships.

The Certificate Is Called Optional and Behaves as Required

The BIMI record itself is short. The implementation guide gives the shape as default._bimi.[domain] IN TXT "v=BIMI1; l=[SVG URL]; a=[PEM URL]", where l points at the logo and a points at the certificate.

On the certificate, the guide marks the step "Highly recommended, but Optional," and adds that "Self-Asserted BIMI records have limited support across the various Mailbox Providers." It declines to name which providers require what, noting only that "each participating mailbox provider has their own criteria."

Google answers that question for its own inbox. The Workspace documentation on adding a BIMI TXT record states that "to display BIMI logos in Gmail, you must use a TXT record that refers to a Privacy Enhanced Mail (PEM) file." The PEM file is the certificate. A self-asserted record with only the l tag does not produce a logo in Gmail.

Our view: price the certificate as a required line item. Resolve how much of your recipient base sits on Google Workspace, because for that share a record without the a tag produces no logo at all, and the budget conversation should start from that number instead of from the specification's word "optional."

Cold Outbound Domains Are the Wrong Place for It

Outbound programmes run on sending domains separated from the main brand domain, which is what protects the company's primary mail from a campaign that goes badly. That separation is exactly what makes BIMI pointless on those domains.

A logo works by recognition. The prospect opening a first-touch message has never encountered the sending domain, has no stored association with the mark, and gains nothing from seeing artwork they cannot place. Meanwhile, each sending domain is its own organizational domain, so the enforcement requirement, the hosted SVG and the certificate all repeat per domain. An outbound setup running dozens of sending domains multiplies a cost against an audience that cannot recognise the result.

The brand domain is a different argument. Mail going to customers, applicants, partners and renewal contacts reaches people who do know the mark, and those are the recipients for whom a visual sender cue changes anything. If BIMI is worth buying, it is worth buying there.

The Logo File Is a Real Piece of Work

The guide requires "an SVG Tiny PS version of your official logo," built to the Scalable Vector Graphics (SVG) Tiny PS specification. That is a restricted profile of SVG rather than the export your design team already has on file.

The practical consequence is that the asset comes back to design with constraints that sound arbitrary from outside the standard, and it has to be hosted somewhere stable and publicly reachable, because the l tag is a URL that receivers fetch. A logo served from a location that changes during a website migration breaks the record quietly, with no bounce and no report to tell you.

Budget the design round and name an owner for the hosted file. A BIMI record whose logo URL has gone stale is worse than no record, because everyone believes the work is done.

The Sequence We Would Follow

We treat BIMI as the last item in an authentication programme, never the reason to start one.

Reach p=reject on the organizational domain and confirm no legitimate mail is failing in your DMARC aggregate reports. Then extend the same policy to subdomains with sp=reject, which usually means finding the forgotten system sending from a subdomain and authenticating it properly. Remove any pct tag once the reports are quiet. Our guide to fixing a DMARC policy that is not enabled covers the states that keep a domain short of enforcement, and reading a DMARC report covers the evidence that tells you the rollout is safe.

Only after that does the logo question make sense, because by then the answer costs a certificate and a design round instead of a quarter of authentication work.

What To Do This Week

  1. Read the p, sp and pct values from your live _dmarc record. Write them down, since they define whether BIMI is available at all.
  2. If sp is absent or below enforcement, inventory what sends from your subdomains. That inventory is the actual project.
  3. Get a quote for a certificate from a certification authority before committing, because Gmail display depends on it.
  4. Ask your design team whether an SVG Tiny PS export exists. If not, add the round to the timeline instead of discovering it later.
  5. Leave BIMI off cold outbound sending domains and revisit only for the domain your customers already recognise.

If you want your sending domains, authentication records and outbound setup reviewed together before you spend on any of this, book a free ICP and campaign-fit discovery call →.

Frequently Asked Questions

A strong positive reply rate for B2B cold email is 1.5–3%. Top-performing campaigns with tight targeting and personalized copy can hit 4–5%. If you're below 1%, it usually signals a deliverability or messaging problem, not a volume problem.

The safe range is 30–50 emails per inbox per day for warmed inboxes. That's why outbound systems use multiple inboxes (we use 80) to reach 40,000+ monthly sends while keeping each inbox well within safe limits. Sending more than 50/day from a single inbox risks spam folder placement.

Yes. The CAN-SPAM Act permits unsolicited commercial email as long as you include a physical address, an unsubscribe mechanism, accurate headers, and non-deceptive subject lines. Unlike GDPR in Europe, the US does not require prior opt-in consent for B2B cold outreach.

Domain warm-up typically takes 2–3 weeks. During this period, sending volume gradually increases while the email warm-up tool generates positive engagement signals (opens, replies) to build sender reputation. Skipping or rushing warm-up is the most common cause of deliverability problems.

Cold email is targeted, relevant outreach to a specific person based on their role, industry, or company, with a clear business reason. Spam is untargeted mass messaging with no personalization or relevance. The distinction matters legally (CAN-SPAM compliance) and practically (deliverability depends on relevance signals).

bimiemail authenticationdmarcbrand domain
Christian Sørensen

Christian Sørensen

Co-Founder & CEO, LeadHaste

Co-founded LeadHaste and runs the multichannel side of the system, from LinkedIn outreach to the agents that qualify replies before a human ever sees them.

Newsletter

The weekly for people who buy outbound.

Five things that changed in outbound this week, why they matter, and what to do about each. Read by founders, sales leaders and growth leads at B2B companies.

Read past issues →

Ready to build outbound that compounds?

We'll build the entire system for your business, and the infrastructure it runs on stays yours.

Book my free review →