What is BIMI?
BIMI (Brand Indicators for Message Identification) is a standard that lets mailbox providers display your brand's logo next to email from your domain. It only works for domains that enforce DMARC with p=quarantine or p=reject, and Gmail additionally requires a Verified Mark Certificate (VMC) or Common Mark Certificate (CMC).
By Stephen Williams · Updated
How BIMI works
- You publish a BIMI TXT record pointing to your logo (and certificate) on your domain.
- A receiving mailbox provider authenticates an incoming message and checks that it passes DMARC.
- If your domain's DMARC policy is at enforcement, the provider fetches your BIMI record, validates the logo and certificate against its own criteria, and may show the logo in the inbox.
Because the logo is only shown for mail that passes DMARC at enforcement, BIMI gives brands a visible reward for finishing their DMARC rollout.
BIMI requirements
- DMARC at enforcement:
p=quarantineorp=rejecton the organizational domain and subdomains, with nopctbelow 100 and nosp=none. Check yours with the DMARC checker, and follow the DMARC policy rollout guide if you're still at p=none. - A logo in SVG Tiny Portable/Secure (SVG Tiny PS) format, a restricted SVG profile (
baseProfile="tiny-ps", version 1.2) without scripts or external references. - A mark certificate (VMC or CMC) for providers that require one, such as Gmail.
- A BIMI DNS record at
default._bimi.yourdomain.com.
The BIMI record
v=BIMI1; l=https://example.com/brand/bimi-logo.svg; a=https://example.com/brand/certificate.pem| Tag | Meaning |
|---|---|
v=BIMI1 | Version; must come first. |
l= | HTTPS URL of the SVG Tiny PS logo. May be left empty when the certificate embeds the logo. |
a= | HTTPS URL of the VMC or CMC in PEM format. Optional for providers that don't require a certificate. |
Google notes that Gmail supports BIMI with PEM files, which embed both the SVG logo and the certificate, so a Gmail-focused record can use v=BIMI1; l=; a=https://example.com/brand/certificate.pem.
VMC vs CMC
| Verified Mark Certificate (VMC) | Common Mark Certificate (CMC) | |
|---|---|---|
| Proves | Ownership of a registered trademark logo | Use of a logo that isn't a registered trademark |
| Trademark required | Yes, with an office recognized by VMC issuers | No |
| Gmail checkmark | Yes, Gmail shows a checkmark for VMC-verified senders | No checkmark |
| Issued by | Authorized mark certificate issuers | Authorized mark certificate issuers |
Getting ready for BIMI
- Get SPF and DKIM passing with alignment for every sender, then publish DMARC; use the DMARC record generator to create the record.
- Move to
p=quarantineorp=rejectwith full coverage, including subdomains. - Produce an SVG Tiny PS version of your logo and host it over HTTPS.
- Obtain a VMC or CMC if you want the logo in Gmail.
- Publish the BIMI record and send a test message to a supporting mailbox.
Sources
Frequently asked questions
Does BIMI work with a DMARC policy of p=none?
No. BIMI requires DMARC at enforcement: p=quarantine or p=reject, applied to all mail (no pct below 100), on the organizational domain and its subdomains. A p=none policy means no logo.
Do I need a VMC to use BIMI?
It depends on the mailbox provider. Gmail requires a Verified Mark Certificate (VMC) or a Common Mark Certificate (CMC) from an authorized certificate authority, and shows a checkmark for senders verified with a VMC. Other providers set their own criteria.
Where is the BIMI record published?
As a TXT record at default._bimi.yourdomain.com, with the value v=BIMI1; followed by l= (the HTTPS URL of your SVG logo) and a= (the HTTPS URL of your certificate PEM file).
Does BIMI improve security or deliverability?
BIMI itself doesn't authenticate anything; the protection comes from the DMARC enforcement it requires. Its benefit is brand recognition in the inbox for mail that has already been authenticated.