Email & DNS
BIMI readiness: what has to be in place before a brand logo can appear
BIMI readiness is mostly about having mature authenticated mail and a controlled brand asset before adding another DNS record. BIMI does not replace SPF, DKIM, DMARC, sender reputation, or provider eligibility, and logo display remains a receiver decision.
Make DMARC enforcement healthy first
Inventory legitimate senders and make sure they pass aligned SPF or DKIM consistently. BIMI programs generally expect an enforcement-level DMARC policy; p=none is only monitoring.
Review aggregate reports long enough to avoid rejecting a forgotten legitimate source just to meet a logo requirement.
Prepare the brand asset to current requirements
BIMI uses a specific SVG profile and some mailbox providers may require a verified mark certificate or other brand-verification mechanism. Requirements can change, so check current receiver and BIMI working-group documentation before purchase.
Host the asset at a stable HTTPS URL you control.
Publish and validate the BIMI record
The default selector typically uses default._bimi. The TXT value references the logo URL and, where applicable, certificate location. Validate DNS syntax and fetch the referenced files externally.
Do not confuse successful DNS publication with guaranteed display in every mailbox.
Monitor authentication and reputation after launch
Keep DMARC reporting, complaint/reputation monitoring, and sender hygiene in place. A logo feature should be treated as the last layer on top of working email operations, not the mechanism that makes them trustworthy.
- Healthy enforced DMARC first.
- Use a compliant controlled SVG.
- Verify current certificate requirements.
- Expect receiver-specific display decisions.