News
BIMI vs DMARC for Brand Logos in the Inbox
April 22, 2022
BIMI vs DMARC for brand logos in the inbox is a display feature versus the authentication policy it sits on. DMARC (with SPF and DKIM) tells receivers what to do when From alignment fails. BIMI (Brand Indicators for Message Identification) is a DNS TXT on default._bimi that points at an SVG mark — and, for many providers, a verified mark certificate — so supporting inboxes can show your logo. Without DMARC at enforcement, BIMI is a wish. It does not replace MTA-STS, website HSTS, or a WAF. RoastMyOpsec is a consented GET to a URL. It does not query BIMI TXT, does not fetch SVG marks, and does not score missing BIMI as an F.
The practical difference
DMARC is the spoofing control. BIMI is branding on mail that already passed. MTA-STS is SMTP TLS to your MX. The marketing homepage TLS check does not see any of this. See SPF vs DKIM vs DMARC and MTA-STS vs DMARC.
A BIMI SVG that embeds scripts or unexpected hosts is the wrong file type for this job. Keep the mark boring, tiny, and on a host you control.
How to choose a policy
Every sending domain: SPF, DKIM, DMARC with a rua you read, then p=quarantine or reject when flows are clean. BIMI: only after enforcement, with an SVG that matches the trademark you can prove. Skip BIMI on a domain that barely sends mail. Do not publish a BIMI record that points at a dangling CNAME.
| Control | What it does | Depends on | Takeaway |
|---|---|---|---|
| DMARC | From alignment disposition | SPF / DKIM | Do this first |
| BIMI | Logo in some inboxes | DMARC enforcement + mark | Optional branding; not a roast F |
| MTA-STS | SMTP TLS to MX | Healthy policy host | Transport, not a logo |
| Website HTTPS | Browser to origin | Cert + HSTS | Different layer |
When BIMI still wins
BIMI wins as a brand cue after DMARC is real. DMARC still wins as the security control. Missing BIMI on a brochure domain is healthy. Pair with DNS hygiene if the BIMI hostname is leftover SaaS.
What the roast can prove
Nothing about BIMI or DMARC. Confirm records in your mail console. Pair with security.txt if you also want a researcher inbox on the web origin.
Common mistakes
The first mistake is a BIMI record before DMARC p=quarantine or reject.
The second mistake is hosting the SVG on a bucket that also lists .env.
The third mistake is treating a missing BIMI logo as an OPSEC finding.
Free audit the URL you own
RoastMyOpsec is a defensive public-surface roast: headers, cookies, sensitive paths, and more — no exploit payloads. Start with the free audit, then open the vault if the blurred findings look expensive.
Free audit nowFAQ
- Does BIMI replace DMARC?
- No. BIMI is a logo on mail that already authenticates. DMARC is the policy.
- Should every marketing domain publish BIMI?
- Only if you send mail, enforce DMARC, and care about inbox logos. Missing BIMI is not a roast F.
- Does RoastMyOpsec check BIMI?
- No. It does not query DNS TXT or fetch BIMI SVG files.