BIMI puts your logo next to your emails in the inbox. It’s the most visible trust signal available to a sender.
It’s also the one with the strictest entry requirements. You can’t switch it on. Your DMARC policy has to be at enforcement first. Your logo has to be a specific SVG dialect. And Gmail wants a certificate proving the logo is yours.
Here’s what BIMI is, what the record looks like, and which certificate you actually need. Plus, what to check when the logo doesn’t show up.
- What Is BIMI?
- Where the Logo Actually Appears
- What You Need Before You Start
- VMC or CMC: Which Certificate Do You Need?
- How to Set Up BIMI
- The BIMI Record, Tag by Tag
- How to Check Your BIMI Record
- Why Your BIMI Logo Isn’t Showing
- Does BIMI Actually Improve Deliverability?
- Is BIMI Worth It for You?
- Getting the Authentication Right First
- Frequently Asked Questions
What Is BIMI?
BIMI stands for Brand Indicators for Message Identification. It’s a standard that lets a mailbox provider display your logo beside your messages. DNS tells the provider where your logo lives, and a certificate proves you’re entitled to use it.
BIMI doesn’t authenticate email by itself. It sits on top of SPF, DKIM and DMARC. It only takes effect once those work and DMARC is enforcing.
Where the Logo Actually Appears
Support is uneven, and this is worth knowing before you spend money on a certificate.
| Mailbox provider | BIMI logo | Notes |
|---|---|---|
| Gmail | Yes | Requires a VMC or CMC. Also shows a checkmark for verified senders. |
| Yahoo Mail | Yes | One of the earliest adopters. |
| Apple Mail | Yes | Displays in Mail on recent iOS and macOS versions. |
| Fastmail | Yes | Supports the standard. |
| Outlook.com | No | Microsoft has not implemented BIMI. |
Outlook is the one that catches people out. If much of your list is on Outlook, Hotmail or Live, BIMI won’t reach them at all.
What You Need Before You Start
You’ll need four things to get started. Often, skipping ahead is one reason a BIMI setup does nothing.
1. SPF and DKIM passing. Both need to be in place and aligned with your sending domain.
2. DMARC at enforcement. This is the hard gate, and most organizations never get there. Your policy must be p=quarantine or p=reject. A p=none record will not work, no matter how correct everything else is.
3. A logo in SVG Tiny PS. Not an ordinary SVG. This is a restricted profile of the format, formally the SVG Tiny Portable/Secure specification.
4. A VMC or CMC, if you want the logo to show in Gmail. More on that next, because the answer is genuinely confusing.
VMC or CMC: Which Certificate Do You Need?
Here’s the part that confuses a lot of users.
The BIMI specification treats the certificate as optional. The a= tag isn’t required, and the BIMI Group describes VMCs and CMCs as “highly recommended, but optional.”
Gmail treats it as mandatory. Google’s own documentation requires a VMC or a CMC from an approved issuer before it will display a logo.
Both statements are true. The spec permits a self-asserted logo. But those have very limited support among mailbox providers. In practice, a certificate is the price of entry.
Verified Mark Certificate (VMC)
A VMC proves you own a registered trademark for the logo. If your mark is registered in a supported jurisdiction, this is the certificate to get.
Common Mark Certificate (CMC)
A CMC is the alternative for logos that aren’t trademarked. It verifies prior use rather than registration. It also allows variations a trademark filing wouldn’t cover, like seasonal color changes or a stacked wordmark.
For most small and mid-size senders without a registered trademark, a CMC is the realistic option. Gmail accepts both.
Where to Get One
Certificates are issued by a short list of approved Mark Verifying Authorities, including DigiCert and Entrust. The BIMI Group maintains the current issuer list. It’s the only list that matters, because a certificate from anywhere else won’t be trusted.
Budget for a real annual cost and a verification process that takes days rather than minutes. Pricing isn’t published consistently, so get a quote before you plan a launch date around it.
How to Set Up BIMI
Step 1: Get DMARC to Enforcement
Start at p=none and read your DMARC reports until you’re confident every legitimate sending source passes. Then move to p=quarantine, then p=reject if you want it.
Do not jump straight to enforcement just to qualify for BIMI. Enforcing before your sources are aligned means your own mail starts failing.
Step 2: Prepare the Logo
Export a square SVG and convert it to SVG Tiny PS. Requirements to check:
- Square aspect ratio
- Minimum 96 by 96 pixels, with dimensions expressed in absolute pixels, not percentages
- No scripts, no external references, no animation
- Legible when small, and readable against both light and dark backgrounds
Host it at a stable HTTPS URL that you don’t plan to move.
Step 3: Get a VMC or CMC
Apply through an approved issuer. You’ll need to prove organizational identity, plus trademark registration for a VMC. Expect this step to set your timeline.
Step 4: Publish the BIMI Record
Add a TXT record in your DNS. If you’re not sure where to do that, our domain and DNS documentation has step-by-step guides for GoDaddy, Cloudflare, Namecheap, Route 53, cPanel, and most other registrars.
The record looks like this:
default._bimi.yourdomain.com IN TXT "v=BIMI1; l=https://yourdomain.com/logo.svg; a=https://yourdomain.com/vmc.pem"
Then send yourself a test message to a Gmail address and check that the logo renders.
The BIMI Record, Tag by Tag
| Part | What it is | Required |
|---|---|---|
default._bimi | The selector. default covers all mail from the domain. A custom selector lets you serve different logos per stream. | Yes |
v=BIMI1 | Version. The only valid value today. | Yes |
l= | HTTPS URL of the SVG Tiny PS logo. | Yes |
a= | HTTPS URL of the VMC or CMC .pem file. Optional per the spec, needed in practice for Gmail. | Effectively yes |
An empty l= tag is legal and meaningful: it tells a mailbox provider to display nothing, which is a way to opt a domain out.
How to Check Your BIMI Record
Three ways, cheapest first.
Query the DNS yourself. From a terminal:
dig +short TXT default._bimi.yourdomain.com
You should see your v=BIMI1 record. “Nothing returned” means the record isn’t published or hasn’t propagated.
Check the pieces separately. Confirm your DMARC record is at p=quarantine or p=reject with pct=100, then open your logo URL in a browser and confirm it loads over HTTPS.
Use a BIMI validator. Several free checkers will fetch your record, validate the SVG profile and verify the certificate chain in one pass. That last part matters, because a certificate problem is invisible in a plain DNS lookup. We don’t offer a BIMI checker ourselves, so use one of the established ones.
Validate after any change to your logo file, your certificate or your DMARC policy. All three can silently break the display.
Why Your BIMI Logo Isn’t Showing
Almost always one of these:
- DMARC isn’t in enforcement mode. Still the number one cause. Check for
p=noneand for apctbelow 100. - The subdomain policy is missing. You set
p=rejectbut leftspunset or atnone. - The logo is ordinary SVG, not SVG Tiny PS. It looks fine in a browser, yet it still gets rejected.
- No certificate, and you’re testing in Gmail. Gmail needs a VMC or CMC.
- The certificate expired. These renew annually, and nothing warns you in the inbox.
- The message failed DMARC. BIMI only applies to mail that passes. One misconfigured sending source can mean no logo on that stream.
- You’re looking in Outlook. It doesn’t support BIMI.
Also allow for time. DNS propagation and provider caching mean a correct setup can take a day or two to appear.
Does BIMI Actually Improve Deliverability?
Not directly, and it’s worth being precise about this because plenty of articles imply otherwise.
BIMI is a display standard. Mailbox providers don’t filter mail more favorably because a BIMI record exists. Publishing one won’t move a message from spam to the inbox.
What it does do is real, just indirect:
- It forces DMARC enforcement. That requirement is the actual deliverability win. Getting to
p=rejectimproves your authentication posture whether or not you ever add a logo. - It raises recognition. A visible logo makes your mail easier to identify, and engagement is a signal providers do weigh.
- It makes impersonation harder. An attacker can’t reproduce your logo slot without passing DMARC for your domain.
So, the honest framing is to pursue BIMI for brand trust and anti-phishing. Treat the DMARC work it forces as a deliverability benefit.
Is BIMI Worth It for You?
The certificate cost and the DMARC prerequisite mean this isn’t automatically worth doing.
It’s worth it if:
- Your logo is recognized, so showing it earns you something
- You’re a phishing target, which covers most finance, retail and any product with a login. Recognition helps when spam filters are weighing your mail
- You’re already at
p=reject, so the hard part is behind you
Hold off if:
- You’re not at DMARC enforcement yet. Then that’s your project, not BIMI. It delivers most of the benefit on its own.
- Most of your recipients are on Outlook, Hotmail or Live, where the logo won’t render at all
- You have no registered trademark and no budget for a CMC
- Your sending volume is low enough that inbox recognition isn’t a meaningful lever
The single question worth asking: are you at p=reject with every sending source passing? If not, do that first. You’ll get the deliverability improvement immediately and BIMI becomes a small final step rather than a project.
Getting the Authentication Right First
Every part of BIMI depends on authentication that already works. If SPF, DKIM and DMARC aren’t passing across all your sending sources, fix that first. It’s worth doing whether or not you ever publish a logo.
SendLayer handles authentication during domain setup and logs every message. That lets you confirm which sources are passing before you move DMARC to enforcement.
Frequently Asked Questions
These are answers to common questions we see about BIMI and how it works.
What is a BIMI record?
A BIMI record is a DNS TXT record published at default._bimi.yourdomain.com. It tells mailbox providers where your logo is hosted. The a= tag points to the certificate proving you’re entitled to use it.
Do I need a VMC for BIMI?
The specification treats the certificate as optional. Gmail requires either a VMC or a CMC before it will display your logo. Since self-asserted logos have very limited support, a certificate is effectively required in practice.
What’s the difference between a VMC and a CMC?
A VMC verifies a registered trademark. A CMC verifies prior use of a logo that isn’t trademarked. It also allows variations a trademark filing wouldn’t cover. Gmail accepts both.
Does BIMI require DMARC?
Yes, and at enforcement. Your policy must be p=quarantine or p=reject with pct=100, and the subdomain policy must match. A p=none record disqualifies you.
Does BIMI improve email deliverability?
Not directly. It’s a display standard, not a filtering signal. The deliverability benefit comes from the DMARC enforcement BIMI requires. Being recognizable in the inbox also helps engagement.
That’s it! Now you know how BIMI works.
Next, do you want to get your authentication passing before you add a logo? Check out our guide to how SPF, DKIM and DMARC work for more information.
Ready to send your emails in the fastest and most reliable way? Get started today with the most user-friendly and powerful SMTP email delivery service. SendLayer Business includes 5,000 emails a month with premium support.
