A BIMI record is a single DNS TXT record, published at default._bimi.yourdomain.com, that tells inbox providers where to find your brand logo and, when required, the certificate that proves you own it. Get it right and your logo appears next to your messages in Gmail, Apple Mail, Yahoo, and others, and VMC senders also earn the blue verified checkmark in Gmail. But BIMI is the last step, not the first: it only works once your email authentication is already strong. This guide walks through the exact prerequisites, the record syntax, the logo format, when you need a VMC or CMC certificate, and how to validate the whole chain.
What BIMI actually does
BIMI stands for Brand Indicators for Message Identification. It does not authenticate your mail by itself. Instead, it rides on top of DMARC: a receiving provider first checks that a message passes DMARC in alignment, and only then looks up your BIMI record to decide which logo to show. If authentication fails, the logo never appears. That dependency is the single most common reason a BIMI record "does not light up."
Prerequisites you must satisfy first
Before you publish anything at default._bimi, confirm every item below is true. Providers enforce these strictly.
| Requirement | Detail |
|---|---|
| SPF or DKIM passing | Mail must authenticate and align with your From domain. |
| DMARC at enforcement | Policy must be p=quarantine or p=reject. A p=none policy will not qualify. |
| No weak subdomain policy | Avoid sp=none; a subdomain override back to none disqualifies the org. |
| Enforcement coverage | Gmail expects the policy to apply to all or nearly all mail (not pct below 100). |
| SVG Tiny PS logo | A square logo in SVG Portable/Secure format, served over HTTPS. |
| Certificate (for most inboxes) | A VMC or CMC is required for Gmail and Apple Mail to render the mark. |
The logo: SVG Tiny Portable/Secure
BIMI does not accept a PNG or a regular SVG. The required format is SVG Tiny PS (a restricted profile of SVG Tiny 1.2 with scripting and external references stripped out for security). The artwork must be square (a 1:1 aspect ratio), should sit centered on a solid background, and must be hosted at a stable HTTPS URL. Keep the file small, ideally under 32 KB. Most design teams export from a vector source and then run it through a BIMI conversion tool to produce a compliant SVG Tiny PS file.
VMC versus CMC: proving the logo is yours
Publishing a logo is not enough for the major inboxes. Gmail and Apple Mail will only render the mark when your BIMI record also links to a certificate that proves your right to the logo. There are two kinds:
- VMC (Verified Mark Certificate): for logos backed by a registered trademark. The certificate authority verifies your trademark with a recognized intellectual-property office. VMC senders also receive the blue verified checkmark in Gmail.
- CMC (Common Mark Certificate): introduced by the AuthIndicators Working Group in late 2024 for organizations without a registered trademark. The CA verifies that the logo has been publicly displayed on a domain you control for at least 12 months, using web-archive evidence. Gmail supports CMC, but a CMC does not grant the blue checkmark.
Both certificate types are issued by a Mark Verifying Authority (MVA). The three MVAs most organizations use are DigiCert, Entrust, and Sectigo. Trademark-based VMCs are recognized against offices such as the USPTO, EUIPO, UK IPO, and IP Australia, among more than a dozen jurisdictions. Expect a VMC to list in the low four figures per year; CMCs are generally cheaper but still a paid product.
Publishing the BIMI record
The record is a TXT record at the special default._bimi host. The v tag declares the version, l points to the SVG logo, and a points to the PEM certificate chain.
; Logo plus certificate (what Gmail and Apple Mail need)
default._bimi.example.com. IN TXT "v=BIMI1; l=https://example.com/bimi/logo.svg; a=https://example.com/bimi/vmc.pem"
; Logo only (self-asserted; most major inboxes will not render it)
default._bimi.example.com. IN TXT "v=BIMI1; l=https://example.com/bimi/logo.svg;"
The selector is default in almost every case. You can use alternate selectors (for example a product brand) by setting a BIMI-Selector header on outgoing mail, but start with default.
Validating the setup
Check the DNS record and certificate chain before you announce anything. Use dig to confirm the record resolves and the tags are intact.
$ dig +short TXT default._bimi.example.com
"v=BIMI1; l=https://example.com/bimi/logo.svg; a=https://example.com/bimi/vmc.pem"
# Confirm DMARC is at enforcement
$ dig +short TXT _dmarc.example.com
"v=DMARC1; p=reject; rua=mailto:dmarc@example.com"
# Confirm the logo URL serves the SVG over HTTPS
$ curl -sI https://example.com/bimi/logo.svg | grep -i content-type
content-type: image/svg+xml
Then send a test message to a Gmail account you control and, in the web client, open the raw message to confirm the BIMI indicator lookup succeeded. Many senders also use a hosted BIMI inspector to verify the SVG profile, the certificate chain, and DMARC alignment in one pass.
Common reasons the logo does not appear
- DMARC not at enforcement. A
p=nonepolicy, orsp=noneon a subdomain, blocks BIMI entirely. - No certificate. A logo-only record will be ignored by Gmail and Apple Mail; they require a VMC or CMC.
- Wrong SVG profile. A standard SVG, a non-square image, or a file with scripting or external references fails the SVG Tiny PS check.
- Reputation and volume. Some providers only show marks for domains with an established sending history, so a brand-new domain may authenticate perfectly and still wait.
- Mail not aligned. If the From domain does not align with the SPF or DKIM domain, DMARC can pass loosely for delivery but still fail the stricter alignment BIMI depends on.
- Caching. After fixing a record, the old answer can linger until the TTL expires, so changes are not instant.
A sensible rollout order
Work through the chain in this sequence so you never chase a symptom caused by an earlier gap: confirm SPF and DKIM pass and align, move DMARC to p=quarantine and then p=reject, produce a compliant SVG Tiny PS logo, obtain a VMC (trademark) or CMC (12-month public use), publish the default._bimi TXT record with both l and a tags, then validate and send test mail.
Ready to check your work? Run your default._bimi and _dmarc records through the Valla DNS propagation checker to confirm they have published everywhere before you send, and browse the other email-authentication guides in our /learn/ hub to tighten SPF, DKIM, and DMARC first. The logo is the reward for getting the foundation right.