BIMI (Brand Indicators for Message Identification)
Implementing BIMI — DMARC enforcement prerequisites, the BIMI DNS record, SVG Tiny PS logo requirements, VMC/CMC certificates, and mailbox-provider support.
Operational4 min read
Who it is for ESP operators, Senders
Applies to senders on any platform
ContentsOn this page — 7 sections
If you want your brand's logo to appear next to your messages in recipients' inboxes, BIMI is how you ask for it. You publish the logo in DNS, and participating mailbox providers display it next to authenticated messages. Each mailbox provider decides independently whether to display the logo, and how.
BIMI is not an authentication protocol itself. It is a reward for full authentication: a domain qualifies only once DMARC is at enforcement. This is why BIMI is often the business reason that pays for a DMARC enforcement rollout.
Prerequisites: DMARC at enforcement
Before a BIMI record is honored, you need:
- SPF, DKIM and DMARC deployed with proper alignment on the sending domain.
- A DMARC policy at enforcement on the Organizational Domain and its subdomains:
p=quarantine; sp=quarantineor stronger, orp=reject; sp=reject.
- Not permitted:
p=none,sp=none, or anypctvalue below 100.
Mail must actually pass DMARC. The logo is displayed only on authenticated messages, and providers also make display depend on the reputation of the sending domain.
The BIMI DNS record
A TXT record published at the default selector under the _bimi label:
default._bimi.example.com. IN TXT "v=BIMI1; l=https://example.com/logo.svg; a=https://example.com/vmc.pem"
| Tag | Meaning | Notes |
|---|---|---|
v |
Version | BIMI1. Must be first |
l |
HTTPS URL of the SVG Tiny PS logo file | Required for the logo to be displayed |
a |
HTTPS URL of the evidence document (a VMC or CMC certificate, in PEM format) | Optional in the specification, but required in practice by providers that demand certificates (e.g., Gmail) |
A record with l= but no a= is a self-asserted BIMI record. Support for self-asserted records varies among mailbox providers (see the table below). Selectors other than default are possible, declared through a BIMI-Selector header on the message, to show a different logo for each mail stream.
SVG logo requirements (SVG Tiny PS)
The logo must conform to the SVG Portable/Secure (SVG Tiny PS) profile, which is based on W3C SVG Tiny 1.2:
| Requirement | Value |
|---|---|
version attribute on <svg> |
1.2 |
baseProfile attribute on <svg> |
tiny-ps |
<title> element |
Required. It should reflect the company name |
<desc> element |
Recommended (accessibility) |
| External links or references | Forbidden (other than declared XML namespaces) |
| Scripts, animation, interactive elements | Forbidden |
x= and y= attributes on the <svg> root |
Forbidden |
| File size | ≤ 32 KB |
| Aspect ratio | Square |
| Background | A solid color is recommended, because transparent backgrounds display inconsistently across mail clients |
| Composition | Center the logo. Mail clients crop it to a circle or a rounded square |
SVG files exported by standard design tools do not comply as they are. Adobe Illustrator can export SVG Tiny 1.2, but you usually need to edit the file by hand to set baseProfile="tiny-ps" and remove stray x and y attributes. The BIMI Group publishes reference files and conversion tools.
Certificates: VMC and CMC
Mark Verifying Authorities issue mark certificates to confirm the link between a logo and a domain. Two Certification Authorities qualified for BIMI issue them: DigiCert and Entrust. The certificate contains the SVG logo, and the record's a= tag points to it as a PEM file. Certificates carry a subject:markType field (OID 1.3.6.1.4.1.53087.1.13) that identifies the validation method used.
| Verified Mark Certificate (VMC) | Common Mark Certificate (CMC) | |
|---|---|---|
| Logo basis | A registered trademark (the supported jurisdictions are listed in the BIMI Group VMC Guidelines) or a mark recognized by a government | A mark with prior use (no trademark needed) or a modified registered mark (a variant of a trademark you own, e.g., seasonal versions) |
| Evidence required | Trademark registration, and validation of the organization | The logo displayed publicly for at least 12 months on a website you control, with historical proof (e.g., archive.org) as well as its current live display |
| Gmail display | Logo plus a blue verified checkmark | Logo only, with no checkmark |
| Common prerequisites | DMARC at enforcement (p=quarantine or p=reject, no sp=none, no pct<100), an SVG Tiny PS logo, and a published BIMI record |
Same |
Certificates are "highly recommended" rather than mandatory everywhere. Gmail requires a VMC or CMC and ignores self-asserted records, while Yahoo, Fastmail and LaPoste display self-asserted logos.
Provider support (BIMI Group adoption list, May 2025)
| Status | Providers |
|---|---|
| Supports BIMI | Apple, Google (Gmail), Yahoo Inc., Fastmail, Zoho Mail, Comcast, Cloudmark (Proofpoint), La Poste, WEB.DE, GMX, KDDI, NTT docomo, Onet Poczta, Zone, Zoner |
| Considering or planning | Yahoo Japan, Seznam.cz, mail.com, BT, AT Mail, Nifty, Qualitia |
| Does not support | Microsoft (Outlook.com and Microsoft 365 use their own mechanisms for brand logos instead) |
Display criteria beyond the published requirements (domain reputation, sending history, volume) vary by provider, and each provider applies them at its own discretion. A valid record and certificate make a domain eligible to have its logo shown, but do not guarantee that it will be.
Implementation checklist
- Bring all mail streams to aligned SPF and DKIM, and move DMARC to enforcement:
p=quarantineorp=reject, covering subdomains and applied to all messages (see DMARC Deployment in Depth). - Produce an SVG Tiny PS logo that meets the requirements in the table above, and validate it with the BIMI Group's tools.
- Obtain a VMC (for a trademarked logo) or a CMC (for 12-month prior use) from DigiCert or Entrust. This is required for Gmail. Skip it only if the providers you target accept self-asserted records.
- Host the SVG file (and the PEM file, if you have a certificate) at stable HTTPS URLs.
- Publish the
default._bimiTXT record. - Check the result with a BIMI record checker, and by sending mail to test accounts at providers that support BIMI. Expect providers to apply their own reputation checks before they display the logo.
Related articles
- DMARC
- DMARC Deployment in Depth, on reaching the enforcement policy that BIMI requires
Check your own record
The free check reads what your domain publishes in DNS.
In this topic
All 13 in Authentication →