BIMI is published as a DNS TXT record pointing to an SVG logo (and, for most major mailbox providers, a Verified Mark Certificate, or VMC, proving trademark ownership). It only renders for mail that already passes DMARC with a policy stronger than none.
BIMI is a trust and recognition signal, not an authentication mechanism on its own; it depends entirely on SPF/DKIM/DMARC already being correctly configured and enforced. Domains that haven't moved past p=none should fix DMARC enforcement before investing in BIMI.
Support varies by mailbox provider, and VMC issuance requires a registered trademark, so BIMI is usually the last authentication project a domain takes on rather than the first.