BIMI stands for Brand Indicators for Message Identification. It is a DNS and certificate system that lets a verified logo show up next to your messages in a supporting inbox. It builds entirely on top of the authentication most cold email sending domains already have, through our SPF, DKIM and DMARC setup guide.
This page covers the BIMI DNS record itself, the DMARC enforcement it requires, and the two certificate types. It also covers what they cost today, which inboxes actually render the logo, and a plain answer to whether a cold email sending domain should bother with it at all.
What is BIMI for cold email and cold outreach domains?
BIMI is a standard that lets a mail receiver display a brand's logo next to an authenticated message, using a DNS record that points to the logo file and, usually, a certificate proving the right to use it. It does not change whether a cold email is delivered; it only changes what the recipient sees once it has already passed authentication.
For a cold outreach sender, BIMI sits on top of existing work rather than replacing any of it. A domain still needs SPF, DKIM and DMARC in place before BIMI does anything, which is why it is a late-stage decision, not a starting point for cold email infrastructure.
What does a BIMI DNS record look like for cold email?
A BIMI record is a TXT record published at default._bimi.yourdomain.com that names a logo file and, optionally, a certificate file. Google Workspace's own BIMI setup guide gives this example record using the v=, l= and a= tags:
Host: default._bimi.yourdomain.com
Type: TXT
Value: v=BIMI1; l=https://images.example.com/brand/bimi-logo.svg; a=https://images.example.com/brand/certificate.pem
| Tag | Meaning |
|---|---|
v | Record version, always BIMI1 |
l | URL to the logo, an SVG file using the Tiny PS profile |
a | URL to the certificate file in PEM format; empty if using a logo with no certificate |
Gmail currently requires the a= certificate to show the logo at all, per Google's own setup guide above. A record with l= but an empty a= tag is valid under the BIMI spec but will not render a logo in Gmail specifically.
Does cold email sending require DMARC at quarantine or reject for BIMI?
Yes. BIMI will not work unless the domain's DMARC policy is set to p=quarantine or p=reject, and the policy has to apply to 100% of mail, set with pct=100. Google's guide states plainly that BIMI does not support a DMARC policy of p=none, and the same enforcement requirement applies at Yahoo and Apple.
This matters more for cold outreach than for a marketing or transactional domain. Enforcing DMARC on a domain that is actively sending cold mail means any message that fails SPF or DKIM alignment gets quarantined or rejected outright, not just logged. Our cold email DMARC policy guide covers how to move a domain through none, to quarantine, to reject without breaking legitimate mail along the way.
What is the difference between a VMC and a CMC for cold email BIMI?
A Verified Mark Certificate, or VMC, requires a registered trademark or government seal. A Common Mark Certificate, or CMC, accepts a logo that has not been registered as a trademark. Both certify a domain's right to use a specific logo with BIMI, but they check different things and cost differently.
| VMC | CMC | |
|---|---|---|
| Requires | Registered trademark or government seal | No registered trademark required |
| Gmail logo treatment | Blue "authenticated" checkmark | Logo shown, no checkmark |
| DigiCert price (checked on digicert.com, October 2026) | $1,752.00/year list price per certificate; monthly-equivalent billing is not offered | Not listed as a separate DigiCert product; DigiCert sells only the VMC/mark certificate line |
| Sectigo price (checked on sectigo.com, October 2026) | Starts at $1,350/year on a multi-year subscription | As low as $990/year |
| Entrust price (checked on entrust.com, October 2026) | Entrust's own pricing page does not list a current price; third-party resellers have quoted figures near $1,300/year, but that is not Entrust's own number | Not listed |
None of these issuers bill monthly; VMC and CMC certificates are sold as annual or multi-year subscriptions. Getting a VMC also requires the logo to already be a registered trademark, a process that can itself take months before a certificate application can even start, per DigiCert's own FAQ on its mark certificates page.
Which inboxes actually show a BIMI logo for cold email senders?
Gmail, Yahoo and Apple Mail are the three inboxes worth knowing about, and each has its own requirement beyond the basic DNS record. Checking each provider's own documentation matters because BIMI support is not universal and keeps changing.
- Gmail shows a logo only when the domain has a VMC and DMARC is enforced, per Google's own BIMI setup guide. A CMC-only record does not get Gmail's blue checkmark. Based on the same documentation, it may not render a logo in Gmail at all without a VMC.
- Yahoo Mail supports BIMI. Per Yahoo's own BIMI help page, it requires meeting Yahoo's authentication and security requirements to be "verified." Third-party guidance, not Yahoo's own page, describes Yahoo as not strictly requiring a VMC the way Gmail does.
- Apple Mail supports BIMI from iOS 16, iPadOS 16 and macOS Ventura 13 onward, across Apple's own Mail app and iCloud.com, per Apple's own support page on BIMI. Apple's developer documentation describes displaying a "digitally certified" label in message details rather than Gmail's checkmark treatment.
Outlook.com and Microsoft 365 webmail do not currently support BIMI logo display at all, which matters for a cold outreach program since a meaningful share of business recipients read mail in Outlook. A logo that shows in Gmail will simply not appear for an Outlook recipient, certificate or not.
Is BIMI worth it for a cold email sending domain?
Usually not. BIMI is built for a domain you want recipients to recognize and trust over years of sending. Most cold email sending domains are built to be expendable, replaced when a campaign burns one out rather than nursed back to health. Spending on a certificate for a domain you might retire in months works against the economics of the thing.
The DMARC enforcement requirement is the sharper issue. Moving a cold sending domain to p=reject is a deliberate choice with real consequences. Any message that slips on SPF or DKIM alignment, including from a legitimate relay or forwarder, gets rejected outright rather than just logged. That is a defensible choice for a domain you control tightly, but it raises the stakes of any authentication misstep on a domain sending unsolicited mail, which is exactly the kind of mail most likely to be scrutinized.
There are cases where it makes sense: an agency's own branded sending domain used consistently over a long period, where the brand is the point and the domain is not disposable. For the typical cold outreach setup, dedicated sending domains with solid SPF, DKIM and DMARC already cover the deliverability work that actually matters. Check your current setup with our free BIMI checker before deciding either way.
How does Pipefire handle DNS authentication for cold email sending domains?
Pipefire writes SPF, DKIM and DMARC for every sending domain it sets up, with DMARC policies managed to protect deliverability on domains built for cold outreach specifically. BIMI itself sits outside what any cold email platform configures day to day, since it depends on a trademark, a certificate purchase and a DMARC enforcement decision that is yours to make for a domain you intend to keep.
If you want the authentication layer that supports cold outreach handled without the DNS work, see our sending domain setup. For BIMI specifically, the certificate purchase and enforcement decision stay with you, since it is tied to your brand and trademark rather than the mechanics of sending.
What is BIMI cold email FAQ
Do I need BIMI to send cold email?
No. BIMI has no effect on whether a cold email is delivered or filtered; SPF, DKIM and DMARC handle authentication, and BIMI only changes what a recipient sees in a supporting inbox once a message has already passed.
What is the difference between BIMI and DMARC for cold email?
DMARC is an authentication policy that tells receivers what to do with mail that fails SPF or DKIM checks. BIMI depends on DMARC being enforced at quarantine or reject but does not itself authenticate anything; it only controls logo display once DMARC has already passed.
Can I use BIMI for cold email without a VMC or CMC certificate?
The BIMI record format allows an empty a= tag with just a logo URL, but Gmail specifically requires a VMC to show the logo, per Google's own setup documentation. A record with no certificate at all is valid under the spec but will not render in the inboxes that matter most for a business sender.
How much does a BIMI certificate cost for cold email sending domains?
VMC certificates run from roughly $1,350 a year at Sectigo to $1,752 a year at DigiCert's list price, checked on each vendor's own site in October 2026; CMC certificates are cheaper, from $990 a year at Sectigo. Neither Sectigo nor DigiCert bills these monthly.
Will BIMI help my cold email open rates?
There is no independent data showing a logo changes open behavior for cold outreach specifically, and Pipefire does not track open rates on the emails it sends since it runs plain text with no tracking pixel. Treat any open rate lift claim as a vendor's own illustration unless it comes from a source outside the company selling the certificate.