Who is supporting BIMI?

The mailbox providers’ list supporting BIMI is growing steadily. An up-to-date list can be found here for both supporting providers as well as providers considering BIMI.

As of April 2023, the list includes Gmail, Yahoo, La Poste, Fastmail, Onet.pl and Zone, Proofpoint as an anti-spam appliance and Apple Mail (from iOS 16 onwards).

The most prominent names on that list are obviously Yahoo, Gmail and one recent adopter: Apple with iOS 16. Apple takes a special role in the mix as they are not a mailbox provider, but they did add BIMI support to their native mail app. Mail being compliant with BIMI will be displayed as “digitally certified email” which boosts the trust in the brand.

Implementation

Implementing BIMI does come in several steps:

  1. DMARC (Domain based Message Authentication, Reporting and Conformance) implementation on enforcement level for both the sending domain and its organizational domain - Learn more

  2. Creation of your brand logo in the SVG TinyPS format - Learn more

  3. Signing up for a Verified Mark Certificate (only needed for some providers) - Learn more

  4. Publish a BIMI DNS record with the logo and the certificate - Learn more

  5. Having a good reputation - Learn more

NOTE
Note that all steps need to be checked off.

DMARC

DMARC is a standard which allows the brand to decide what a mailbox provider should do with an email which fails authentication. The so-called policies range from “none” over “quarantine” (Spam folder placement) to “reject” (outright block the mail). Only the latter two policies are called “enforcement” and qualify for BIMI. Mail sent by Adobe is passing authentication, as SPF (Sender Policy Framework) and DKIM (Domain Keys Identified Mail) are set up per default. Adobe is setting up DMARC on your sending domain on request.

In addition to DMARC on the sending domain, DMARC also needs to be employed on enforcement level for the organizational domain (if the sending domain is news.example.com, example.com is the organizational domain).

The logo creation needs to follow the requirements to 100%. Please always refer to the BIMI Group’s guidelines.

The logo needs to be stored in a secure location (HTTPS), in case a content delivery network (CDN) is used any protection which prevents Mailbox Providers from getting the logo (e.g. Bot Protection) needs to be disabled.

Besides the technical requirements, there are some practical recommendations like having a square logo, having a solid color as background and others. These recommendations are for best visualization. Some providers have their own requirements which are additional to the ones by the BIMI working group. Gmail for example requires the logo to be at least 96 x 96 pixels.
Please note that non-compliance can lead to the logo not being displayed.