// Audit 2, email brand trust
Your logo belongs in the inbox.
Most domains already qualify and never find out.
BIMI puts your brand mark next to your mail in Yahoo, AOL, Apple Mail and Gmail. It never throws an error. When a gate fails it simply does not render, and nothing anywhere tells you why. Every one of those gates is checkable from outside, so we check them and hand you the exact fix.
- BIMI T0BlockedDMARC is not enforcing, so BIMI cannot start at all.
- BIMI T1UnclaimedYou already qualify. The logo slot is sitting there unclaimed.
- BIMI T2BrokenThe record is published and something downstream is failing silently.
- BIMI T3LiveRenders in Yahoo, AOL and Apple Mail. Gmail is still holding back.
- BIMI T4CertifiedLive everywhere, Gmail included.
A rung requires every rung beneath it. A flawless logo file behind a DMARC record that does not enforce is still BIMI T0, because nothing downstream of that gate can render.
pct=90 passes every DMARC checker on the internet and still kills BIMI forever. sp=none disqualifies a domain even at p=reject, so the most locked-down apex you can write is BIMI-dead. Neither reports an error anywhere. Both are one line to fix.
The DMARC gates
BIMI reads your DMARC record before it looks at anything else. Two of these fail silently.
The BIMI record
One TXT record at default._bimi. This is the step most eligible domains never take.
The logo file
SVG Tiny P/S. An ordinary export from any design tool satisfies almost none of it.
The certificate
Only Gmail requires one. Plenty of domains should rationally stop before this.