# BIMI (Brand Indicators for Message Identification)

> Implementing BIMI — DMARC enforcement prerequisites, the BIMI DNS record, SVG Tiny PS logo requirements, VMC/CMC certificates, and mailbox-provider support.

Source: emailmarketing.net — https://emailmarketing.net/learn/authentication/bimi

If you want your brand's logo to appear next to your messages in recipients' inboxes, BIMI is how you ask for it. You publish the logo in DNS, and participating mailbox providers display it next to authenticated messages. Each mailbox provider decides independently whether to display the logo, and how.

BIMI is not an authentication protocol itself. It is a **reward for full authentication**: a domain qualifies only once [DMARC](https://emailmarketing.net/learn/authentication/dmarc) is at enforcement. This is why BIMI is often the business reason that pays for a [DMARC enforcement rollout](https://emailmarketing.net/learn/authentication/dmarc-deployment).

## Prerequisites: DMARC at enforcement

Before a BIMI record is honored, you need:

- SPF, DKIM and DMARC deployed with proper alignment on the sending domain.
- A DMARC policy at **enforcement on the Organizational Domain and its subdomains**:
  - `p=quarantine; sp=quarantine` or stronger, or
  - `p=reject; sp=reject`.
- **Not permitted**: `p=none`, `sp=none`, or any `pct` value below 100.

Mail must actually pass DMARC. The logo is displayed only on authenticated messages, and providers also make display depend on the reputation of the sending domain.

## The BIMI DNS record

A TXT record published at the `default` selector under the `_bimi` label:

```
default._bimi.example.com. IN TXT "v=BIMI1; l=https://example.com/logo.svg; a=https://example.com/vmc.pem"
```

| Tag | Meaning | Notes |
|---|---|---|
| `v` | Version | `BIMI1`. Must be first |
| `l` | HTTPS URL of the SVG Tiny PS logo file | Required for the logo to be displayed |
| `a` | HTTPS URL of the evidence document (a VMC or CMC certificate, in PEM format) | Optional in the specification, but required in practice by providers that demand certificates (e.g., Gmail) |

A record with `l=` but no `a=` is a **self-asserted** BIMI record. Support for self-asserted records varies among mailbox providers (see the table below). Selectors other than `default` are possible, declared through a `BIMI-Selector` header on the message, to show a different logo for each mail stream.

## SVG logo requirements (SVG Tiny PS)

The logo must conform to the **SVG Portable/Secure (SVG Tiny PS)** profile, which is based on W3C SVG Tiny 1.2:

| Requirement | Value |
|---|---|
| `version` attribute on `<svg>` | `1.2` |
| `baseProfile` attribute on `<svg>` | `tiny-ps` |
| `<title>` element | **Required**. It should reflect the company name |
| `<desc>` element | Recommended (accessibility) |
| External links or references | Forbidden (other than declared XML namespaces) |
| Scripts, animation, interactive elements | Forbidden |
| `x=` and `y=` attributes on the `<svg>` root | Forbidden |
| File size | ≤ 32 KB |
| Aspect ratio | Square |
| Background | A solid color is recommended, because transparent backgrounds display inconsistently across mail clients |
| Composition | Center the logo. Mail clients crop it to a circle or a rounded square |

SVG files exported by standard design tools do not comply as they are. Adobe Illustrator can export SVG Tiny 1.2, but you usually need to edit the file by hand to set `baseProfile="tiny-ps"` and remove stray `x` and `y` attributes. The BIMI Group publishes reference files and conversion tools.

## Certificates: VMC and CMC

**Mark Verifying Authorities** issue mark certificates to confirm the link between a logo and a domain. Two Certification Authorities qualified for BIMI issue them: **DigiCert** and **Entrust**. The certificate contains the SVG logo, and the record's `a=` tag points to it as a PEM file. Certificates carry a `subject:markType` field (OID `1.3.6.1.4.1.53087.1.13`) that identifies the validation method used.

| | Verified Mark Certificate (VMC) | Common Mark Certificate (CMC) |
|---|---|---|
| Logo basis | A **registered trademark** (the supported jurisdictions are listed in the BIMI Group VMC Guidelines) or a mark recognized by a government | A **mark with prior use** (no trademark needed) or a **modified registered mark** (a variant of a trademark you own, e.g., seasonal versions) |
| Evidence required | Trademark registration, and validation of the organization | The logo displayed publicly for **at least 12 months** on a website you control, with historical proof (e.g., archive.org) as well as its current live display |
| Gmail display | Logo **plus a blue verified checkmark** | Logo only, with no checkmark |
| Common prerequisites | DMARC at enforcement (`p=quarantine` or `p=reject`, no `sp=none`, no `pct<100`), an SVG Tiny PS logo, and a published BIMI record | Same |

Certificates are "highly recommended" rather than mandatory everywhere. Gmail requires a VMC or CMC and ignores self-asserted records, while Yahoo, Fastmail and LaPoste display self-asserted logos.

## Provider support (BIMI Group adoption list, May 2025)

| Status | Providers |
|---|---|
| Supports BIMI | Apple, Google (Gmail), Yahoo Inc., Fastmail, Zoho Mail, Comcast, Cloudmark (Proofpoint), La Poste, WEB.DE, GMX, KDDI, NTT docomo, Onet Poczta, Zone, Zoner |
| Considering or planning | Yahoo Japan, Seznam.cz, mail.com, BT, AT Mail, Nifty, Qualitia |
| Does not support | Microsoft (Outlook.com and Microsoft 365 use their own mechanisms for brand logos instead) |

Display criteria beyond the published requirements (domain reputation, sending history, volume) vary by provider, and each provider applies them at its own discretion. A valid record and certificate make a domain eligible to have its logo shown, but do not guarantee that it will be.

## Implementation checklist

1. Bring all mail streams to aligned SPF and DKIM, and move DMARC to enforcement: `p=quarantine` or `p=reject`, covering subdomains and applied to all messages (see [DMARC Deployment in Depth](https://emailmarketing.net/learn/authentication/dmarc-deployment)).
2. Produce an SVG Tiny PS logo that meets the requirements in the table above, and validate it with the BIMI Group's tools.
3. Obtain a VMC (for a trademarked logo) or a CMC (for 12-month prior use) from DigiCert or Entrust. This is required for Gmail. Skip it only if the providers you target accept self-asserted records.
4. Host the SVG file (and the PEM file, if you have a certificate) at stable HTTPS URLs.
5. Publish the `default._bimi` TXT record.
6. Check the result with a BIMI record checker, and by sending mail to test accounts at providers that support BIMI. Expect providers to apply their own reputation checks before they display the logo.

## Related articles

- [DMARC](https://emailmarketing.net/learn/authentication/dmarc)
- [DMARC Deployment in Depth](https://emailmarketing.net/learn/authentication/dmarc-deployment), on reaching the enforcement policy that BIMI requires
