What the hell is BIMI anyway?

TL;DR

  • BIMI shows your logo next to your emails in a handful of inboxes. It doesn’t fix deliverability on its own, and it only works once DMARC is already enforced.
  • If someone’s flagged “no BIMI record” as a red flag in an audit of your agency’s domain, treat that with scepticism. Google, Microsoft, Yahoo and Meta don’t have one on their own primary domains either.
  • Most UK recruitment agencies don’t need BIMI at all yet. Get SPF, DKIM and DMARC properly enforced first. That’s the part that actually stops your domain being spoofed against candidates and clients.
  • If you do go ahead: a self-asserted logo record (CMC) costs almost nothing. A Verified Mark Certificate (VMC), which gets you Gmail’s blue tick, requires a registered trademark and a real budget, and it’s rarely worth it for agencies under 200 staff.

If you’ve had a domain audit land in your inbox recently, there’s a decent chance “no BIMI record” was near the top of the list of things wrong with your setup. It’s a good line for a sales pitch. A logo next to your agency’s name in a candidate’s inbox sounds like exactly the sort of thing you should already have.

Before you add it to this quarter’s to-do list, it’s worth understanding what BIMI actually does, what it requires you to already have in place, and how many of the businesses who could be using it have actually bothered.

What BIMI actually does

BIMI (Brand Indicators for Message Identification) is a DNS TXT record that tells a handful of inbox providers where to find your logo, so it displays next to your name in a candidate’s or client’s inbox. Go the whole way in Gmail and buy a Verified Mark Certificate, and you also get a small blue tick.

Here’s the bit an audit report tends to skate past: you can’t have BIMI without doing the real work first. It only activates once your DMARC record is already enforcing at quarantine or reject, not sitting at p=none. BIMI sits entirely on top of authentication your agency should have set up anyway, to stop your domain being used to spoof candidates or impersonate your consultants to clients.

So if a domain has no BIMI record, the honest read isn’t “this agency’s email security is weak.” It’s “this agency hasn’t bought a logo certificate yet,” which is a considerably smaller problem, and one that assumes the bigger problem is already solved.

Where it actually came from

Most people think that Google thought it up. Actually, BIMI comes from the AuthIndicators Working Group, an industry body that published the first formal spec in February 2019. Google joined that group in July 2019 and committed to piloting it in Gmail, alongside Yahoo, Mailchimp, Twilio SendGrid, Proofpoint, Validity and Valimail. Entrust and DigiCert later built the certificate side, issuing the VMCs Gmail requires for the blue tick.

Google is the most prominent backer and, since 2021, one of the biggest supporters through Gmail.

The bit worth checking yourself

So, surely Google uses BIMI on it’s own domains? Well, no. We looked up the actual DNS records.

google.com has no BIMI record. Neither does gmail.com. Nor does microsoft.com (they don’t support it anyway), yahoo.com, verizon.com or meta.com. Apple does have one, fully certificated, and so do several of the vendors who build BIMI infrastructure for a living: Mailchimp, Twilio, SendGrid, Proofpoint, Validity, Valimail, Entrust and DigiCert, along with Amazon, Salesforce and LinkedIn.

That’s a genuinely mixed picture but incredibly intresting that the company that made a big deal of Gmail’s BIMI support and pushed the blue tick hasn’t applied it to its own domains.

We went further and checked BIMI records across just over 100 major UK-listed companies: banks, insurers, retailers, miners, housebuilders, utilities. Six had a working record: Shell, Aviva, National Grid, St James’s Place, Beazley and Sage. Roughly 6%, mostly insurers and utilities with heavy consumer-facing email volume, which tracks with what BIMI was actually built for. Everyone else has nothing.

If a domain audit is using a missing BIMI record as evidence that your agency’s email setup is neglected, it’s fair to point out that the same test fails for the company that runs Gmail.

Do you need a CMC or a VMC

If you’ve got SPF, DKIM and DMARC properly enforced already, adding BIMI is genuinely low-cost and there’s no real reason not to. The decision that matters is which certificate.

Now, BIMI isn’t for everyone but if you really do want it, start with a CMC. A Common Mark Certificate is self-asserted, costs nothing beyond the logo work, and gets your logo showing in the inboxes that support it. A Verified Mark Certificate, the one that gets you Gmail’s blue tick, requires a registered trademark for your logo and a paid certificate on top. It’s a real decision with a real cost, and it’s mainly worth it for consumer-facing brands sending high volumes where recognisability in the inbox has a direct commercial payoff. For most recruitment agencies, candidate trust is built by the sender name and a clean track record, not a blue tick.

What this means for recruiters

If a firm has approached your agency with a domain audit that leads on BIMI, that’s a sales tactic, not a security assessment. It’s designed to alarm someone non-technical into a quick decision. The actual questions worth asking are:

  • Is our DMARC policy set to quarantine or reject, or is it still sitting at p=none (which does nothing)?
  • Are SPF and DKIM aligned for every platform sending on our domain, including our ATS, our outreach platform, and any marketing tool, not just the one the audit happened to check?
  • Has our domain reputation actually been assessed, or has someone just run a DNS lookup and handed us a list of missing records?

BIMI is worth doing once those are answered. It’s not a substitute for answering them.

FAQ

Does BIMI improve email deliverability?
No. BIMI is a display feature, not an authentication mechanism. It doesn’t affect whether your emails reach the inbox. DMARC, SPF and DKIM are what determine deliverability and protect your domain from spoofing.

Can we set up BIMI without DMARC?
No. BIMI requires DMARC enforcing at quarantine or reject. If your DMARC policy is still at p=none, or you don’t have one at all, BIMI won’t activate regardless of what else you set up.

Do we need a Verified Mark Certificate to use BIMI?
No. A self-asserted CMC is enough to display your logo in inboxes that support BIMI, including Yahoo and Apple Mail. A VMC is only needed for the blue tick in Gmail, and it requires a registered trademark, which most agencies won’t have for their logo.

Should a recruitment agency prioritise BIMI over DMARC?
No. DMARC enforcement should always come first. It’s the part that actually stops someone spoofing your domain to send fraudulent emails to your candidates or clients. BIMI is a cosmetic layer on top of that protection, not a replacement for it.

Is it a red flag if our agency doesn’t have a BIMI record?
Not on its own. Most large, well-resourced organisations, including Google and Microsoft, don’t have one on their primary domain. What matters far more is whether your DMARC, SPF and DKIM are correctly configured and enforcing.

Next step

If someone’s handed your agency an audit with “no BIMI” flagged as a problem, the right first question isn’t “how do we get the tick.” It’s “what does our DMARC policy actually say,” because that’s the part that was never optional.

Book a free domain health check with Quinset →


CMC vs VMC: Comparison Guide

ComparisonVMCCMC
Application ProcessTime-consuming and expensiveEasier to obtain without the need for trademarking
EligibilityTrademarked logoMinimum one year of logo usage
BIMI Verification MarkIncludes blue verification checkmarkOnly logo display, no checkmark
Brand CredibilityHigher credibility with trademarked logoLess credibility without a trademark