Only for a VMC. You can publish a BIMI record without one, and some providers will display the logo — but the providers with the widest consumer reach generally want the certificate, and that requires a registered mark.
Hosted BIMI
BIMI is the visible payoff for authentication work customers never see. It is also the strictest standard of the set, and it fails silently.
BIMI has a hard prerequisite that catches most people out: your DMARC policy must be at quarantine or reject. A domain sitting at p=none will never display a logo no matter how correct the BIMI record is, and nothing tells you why.
Then there is the file. The logo has to be SVG Tiny Portable/Secure — a deliberately restricted profile, square, with a solid background and no scripting or external references. Exporting an SVG from a design tool almost never produces a compliant file, and the failure mode is the same as every other BIMI problem: nothing appears, and no error is sent to anyone.
The platform checks the whole dependency chain before you publish: policy state, alignment, record syntax, file profile, and hosting. If the logo will not display, you learn which requirement is unmet instead of guessing.
The record and the asset are hosted for you, so there is no separate job to stand up a compliant endpoint — and when the DMARC policy moves to enforcement, BIMI is already staged and correct.
Required format
Minimum policy
For wider support
The honest answer is that it depends on where your customers read mail.
A Verified Mark Certificate proves the logo is a trademark you own. Some mailbox providers require one before they will display anything; others will show a logo without it. The certificate carries a real annual cost and requires a registered trademark, which takes months if you do not already hold one.
For a consumer brand sending high volumes to Gmail and Apple Mail, the reach usually justifies it. For an organisation whose mail goes mostly to business recipients on Microsoft 365, the calculation is different and it is reasonable to publish BIMI without a VMC first.
We will tell you which applies to your sending profile rather than treating the certificate as mandatory. The authentication work underneath is valuable either way — the logo is the visible part, not the point.
Something not covered here? Talk to our team.
Only for a VMC. You can publish a BIMI record without one, and some providers will display the logo — but the providers with the widest consumer reach generally want the certificate, and that requires a registered mark.
In order of likelihood: the DMARC policy is not at enforcement, the SVG does not meet the Tiny PS profile, or the record points somewhere unreachable. The checker reports which of the three applies rather than just failing.
Rarely without modification. Tiny PS forbids common features that design tools emit by default, and the mark must be square with a solid background — which often means a cropped variant of your primary logo rather than the logo itself.
Not directly. It does not change how filters score your mail. What it changes is recipient recognition at the moment of scanning an inbox, which is a different and narrower benefit than deliverability.