Definition ยท DNS & Email Spoofing

What is BIMI?

BIMI (Brand Indicators for Message Identification) is an email specification that lets organisations display their logo next to their messages in supporting email clients, including Gmail, Yahoo Mail, and Apple Mail. The logo only appears for mail that passes strong authentication, so BIMI acts as both a branding feature and a visible reward for getting email security right.

How BIMI works

A BIMI record is a DNS TXT record published at default._bimi.example.com:

v=BIMI1; l=https://example.com/logo.svg; a=https://example.com/vmc.pem

The l tag points to the brand logo as an SVG (in the restricted SVG Tiny Portable/Secure profile), and the optional a tag points to a Verified Mark Certificate.

Requirements

  • DMARC at enforcement โ€” the domain must publish a policy of quarantine or reject; p=none is not sufficient
  • Passing authentication โ€” each message must pass DMARC, which in turn depends on SPF or DKIM with alignment
  • A Verified Mark Certificate (VMC) โ€” some providers, notably Gmail, only display logos backed by a VMC, a certificate that attests the sender owns the trademark on the logo

Why BIMI matters

BIMI has no direct security effect of its own, but it is one of the strongest commercial incentives for DMARC adoption: the logo is only available to domains that have completed the journey to an enforcing DMARC policy, which is the state that actually prevents spoofing.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.