Plenty of European businesses have bought a BIMI certificate this year expecting their logo to start appearing next to their emails within weeks. Most are still waiting, and the certificate was never the reason why.
The certificate is the easy part
BIMI, Brand Indicators for Message Identification, lets a verified brand logo appear beside authenticated email in supporting inboxes such as Gmail and Yahoo. Research published today by email deliverability testing company MailGenius, based on a Certificate Transparency snapshot of more than 20,000 BIMI certificates across 109 countries, shows adoption growing fast, with certificate issuance up 54 percent between 2024 and 2025. But according to the report, most projects stall not at the certificate but at the requirement underneath it: DMARC at enforcement, meaning a policy of quarantine or reject rather than the far more common policy of none.
Why enforcement is the hard part
Getting to DMARC enforcement means identifying every system that sends email on a company’s behalf, from the marketing platform to the CRM to the invoicing tool to whatever a sales team signed up for without telling IT, and proving each one authenticates correctly under SPF and DKIM. Miss one, and either legitimate mail starts failing at enforcement, or the domain never reaches enforcement in the first place because nobody trusts the policy enough to flip the switch. As MailGenius owner Troy Ericson put it, that inventory work “costs nothing to buy and several weeks to finish,” and it belongs to no single team, which is usually why it stalls.
Why this matters beyond the logo
DMARC enforcement is no longer just a nice-to-have for brand recognition. Google, Microsoft and Yahoo have already made it mandatory for bulk senders, and 2026 is the year that scrutiny is extending to smaller senders too. Countries that have made DMARC enforcement mandatory have seen phishing success rates fall dramatically, because a properly enforced policy stops spoofed mail from a company’s own domain before it reaches anyone’s inbox. Getting to enforcement pays for itself in avoided phishing and business email compromise long before a logo ever shows up.
What to check before starting a BIMI project
If your organisation has a BIMI certificate that is not displaying, or a DMARC record still sitting at “none” or “quarantine” months after go-live, the fix is the sender inventory, not the certificate.
If you want a European team to map every system sending email on your domain, get you to genuine DMARC enforcement, and only then worry about the logo, contact Excello Digital. We help businesses get their email authentication right the first time, instead of discovering the gaps after a spoofed email reaches a customer.
