How Many Brands Actually Use BIMI? A Check of 1,359 Domains
BIMI is used by a minority of big brands, and fewer still have it fully working. In a check of 1,359 major domains on 2 October 2026, 16.9% of S&P 500 companies published a BIMI record, and 13.5% had everything Gmail requires in place: an unexpired mark certificate, DMARC at quarantine or reject, and a logo that loaded.
Among SaaS companies the share was lower still, at 11.5% publishing and 3.0% complete. Most SaaS BIMI records skip the certificate entirely.
What BIMI needs
BIMI (Brand Indicators for Message Identification) shows your logo next to your mail in supporting inboxes. It is a TXT record at default._bimi.<domain>, like:
v=BIMI1; l=https://example.com/logo.svg; a=https://example.com/vmc.pem
l=points at the logo, in SVG.a=points at a mark certificate that proves you own the logo.
Requirements differ by mailbox provider, and both are published:
| Requirement | Gmail | Yahoo |
|---|---|---|
| DMARC policy | quarantine or reject, pct=100 | quarantine or reject |
| Certificate | VMC or CMC required | VMC not required, used if present |
| Other | Bulk mail only, sufficient reputation and engagement |
Sources: Google's Set up BIMI page and Yahoo's Sender Hub BIMI page, both read on 2 October 2026. Google also notes that Gmail shows a checkmark only for senders verified with a VMC.
How we measured
Three samples, 1,359 unique domains: DNS, plus a fetch of every logo and certificate.
| Sample | Source | Domains |
|---|---|---|
| S&P 500 | Wikipedia's "List of S&P 500 companies", website domains from Wikidata | 496 |
| SaaS | 200 largest SaaS-tagged companies by listed team size, Y Combinator public directory (yc-oss.github.io mirror) | 200 |
| Top sites | Tranco top 1,000 (list ID Y83YG), only domains with a working MX | 700 |
For each domain we queried default._bimi.<domain> with dnspython against public resolvers and kept records beginning v=BIMI1. For each record we fetched the l= logo and the a= certificate over HTTPS, parsed the certificate with OpenSSL, and read its expiry date, issuer and mark type. Mark type tells VMCs ("Registered Mark", "Government Mark") apart from CMCs ("Prior Use Mark", "Modified Registered Mark"). We matched each domain to its DMARC policy from the same DNS run. Time: about 03:50 UTC, 2 October 2026.
A domain counts as complete if it has a certificate that loaded and had not expired, DMARC at quarantine or reject with pct=100, and a logo that loaded. That is the Gmail bar. We did not validate the SVG against the BIMI SVG profile or check the certificate chain beyond reading it, so "complete" here is necessary but not sufficient.
The results
Around one in six large brands publishes BIMI; fewer than one in seven has it complete.
| S&P 500 (n=496) | SaaS (n=200) | Tranco top 1,000 with MX (n=700) | |
|---|---|---|---|
| Publishes BIMI | 84 (16.9%) | 23 (11.5%) | 168 (24.0%) |
With certificate (a=) |
74 | 9 | 125 |
| Without certificate (self-asserted) | 10 | 14 | 43 |
| Certificate expired | 5 | 2 | 15 |
| Certificate could not be fetched | 2 | 1 | 5 |
| Logo could not be fetched | 3 | 1 | 7 |
| DMARC p=none or missing | 1 | 1 | 4 |
| Complete (Gmail bar) | 67 (13.5%) | 6 (3.0%) | 105 (15.0%) |
Three findings stand out.
1. SaaS companies mostly skip the certificate
14 of the 23 SaaS BIMI records have no certificate at all. Without one, Gmail will not show the logo. Yahoo's sender guidance says it may, provided the other conditions are met, so a self-asserted record is not useless. But for most B2B recipients, who are on Google Workspace or Microsoft 365, it achieves little.
Mark certificates cost money and VMCs need a registered trademark, which is a plausible reason smaller companies skip them, though our data cannot show motive.
2. Certificates lapse and nobody updates the record
22 of the 256 unique BIMI domains point at an expired certificate. Expiry dates ranged from April 2024 to late September 2026, so some had been invalid for well over a year.
An expired certificate fails silently in the same way a broken MTA-STS host does. The DNS record still exists, the logo file still loads, and nothing tells the domain owner that Gmail has stopped showing the logo. If you run BIMI, put the certificate's renewal date in the same calendar as your TLS certificates.
3. DMARC is not the bottleneck
Almost every BIMI publisher already enforces DMARC. Across the 256 unique BIMI domains, only 4 were on p=none and 2 had no DMARC record. No BIMI publisher used a pct below 100.
That makes sense: BIMI is something teams set up after DMARC enforcement, not before. If you are still on p=none, BIMI is several steps away. Our DMARC adoption study shows 27.5% of SaaS companies are in that position.
Certificates in the wild
DigiCert issued almost all the certificates we could read.
| Issuer (organisation) | S&P 500 | SaaS | Tranco |
|---|---|---|---|
| DigiCert | 69 | 8 | 108 |
| GlobalSign | 1 | 0 | 7 |
| Entrust | 1 | 0 | 3 |
| Sectigo | 1 | 0 | 1 |
| SSL Corporation | 0 | 0 | 1 |
And by mark type:
| Mark type | Certificate type | S&P 500 | SaaS | Tranco |
|---|---|---|---|---|
| Registered Mark | VMC | 71 | 6 | 117 |
| Government Mark | VMC | 0 | 0 | 1 |
| Prior Use Mark | CMC | 1 | 1 | 2 |
| Modified Registered Mark | CMC | 0 | 1 | 0 |
CMCs are still rare: 5 of the certificates we could read, across 256 unique BIMI domains. Large brands have registered trademarks and use VMCs, which also earn the Gmail checkmark.
Well-known domains with a VMC in place included apple.com, amazon.com, paypal.com, bankofamerica.com, jpmorganchase.com, linkedin.com and ebay.com. gmail.com, yahoo.com, microsoft.com and outlook.com published no BIMI record of their own.
Is BIMI worth it for you?
For a consumer brand that already enforces DMARC, it is a reasonable next step. For cold email, no.
- BIMI displays only where the receiving provider supports it, and Gmail requires a paid certificate.
- Yahoo, by its own description, shows logos only for bulk mail with sufficient reputation, not for one-to-one mail.
- None of it helps an unknown sender reach the inbox in the first place. Authentication and list quality do that.
If you are sending B2B outreach, the order of work is: verify the list, get SPF, DKIM and DMARC right, then consider BIMI. Our BIMI setup guide covers the steps in detail.
Check any domain
dig +short TXT default._bimi.example.com
dig +short TXT _dmarc.example.com
If the BIMI record has an a= URL, download it and check the expiry:
curl -s https://example.com/vmc.pem | openssl x509 -noout -enddate -issuer
The DMARC checker confirms the policy side, and the deliverability check covers SPF, DKIM and DMARC in one pass.
Limitations
- Default selector only. BIMI allows other selectors. We checked only
default, which is what nearly all publishers use. - Leaf certificate only. We read the first certificate in each PEM file, which is normally the leaf. We did not validate the full chain or check revocation.
- SVG not validated. We confirmed the logo loaded, not that it meets the SVG Tiny PS profile BIMI requires.
- Website domain, not mail domain. Some companies send marketing mail from a different domain or a subdomain with its own BIMI record.
- Big domains only, one snapshot. Results are for large, well-known domains on 2 October 2026.
The short version
- 16.9% of S&P 500 companies, 11.5% of SaaS companies and 24.0% of top-site mail domains publish BIMI.
- Only 13.5%, 3.0% and 15.0% respectively meet Gmail's bar.
- Most SaaS BIMI records have no certificate, so Gmail ignores them.
- 22 of 256 BIMI domains point at an expired certificate.
- DMARC enforcement is almost universal among BIMI publishers, so it is a prerequisite, not the blocker.
Raw data: download the full dataset as CSV. It is free to reuse with a link back to this page.
Common questions
How many companies use BIMI?
In our October 2026 check, 84 of 496 S&P 500 companies (16.9%) published a BIMI record, against 23 of 200 SaaS companies (11.5%) and 168 of 700 mail-receiving domains in the Tranco top 1,000 (24.0%). Fewer had everything Gmail needs: a current certificate, an enforcing DMARC policy and a reachable logo.
Do you need a VMC for BIMI?
For Gmail, you need either a Verified Mark Certificate (VMC) or a Common Mark Certificate (CMC), according to Google's BIMI setup page. Yahoo's sender site says it does not currently require a VMC for logos to appear in Yahoo apps, but it does require a DMARC policy of quarantine or reject, bulk sending volume and sufficient reputation.
What DMARC policy does BIMI need?
Quarantine or reject. Google's BIMI page states p=none is not supported and that pct must be 100. In our data almost every BIMI publisher met this: only 4 of the 256 unique domains with BIMI records were on p=none, and 2 had no DMARC record at all.
Do BIMI certificates expire?
Yes. VMCs and CMCs are time-limited certificates, and when one lapses the BIMI record keeps pointing at it. We found 22 of the 256 unique BIMI domains referencing a certificate whose expiry date had already passed when we checked on 2 October 2026, some by more than a year.
Verify unlimited addresses for $29.99/month
Real SMTP mailbox checks. No credits, no per-email fees.
Get Started