
What Is a BIMI Record, and How Does It Show Your Logo in Inboxes?
Scroll through a Gmail or Apple Mail inbox and you'll notice that some senders show a crisp brand logo in the avatar circle, while most show a generic initial. That logo isn't uploaded through a Gmail setting or pulled from a social profile. It comes from a DNS record called BIMI, and the inbox only shows it when the sender's email authentication is strong enough to prove the message really came from them.
This article explains what a BIMI record is, what you need in place before it will work, how to prepare a compliant logo file, the role of Verified Mark Certificates, and how to publish and test the record. BIMI is the last step of an authentication stack that starts with SPF, DKIM, and DMARC — so if those aren't in place yet, that's where to start.
What Is a BIMI Record?
BIMI (Brand Indicators for Message Identification) is a standard that lets a domain owner publish the location of their brand logo in DNS. Mailbox providers that support BIMI fetch that logo and display it alongside messages that pass authentication.
The BIMI record itself is a TXT record published at a special name under your domain:
default._bimi.example.com. 3600 IN TXT "v=BIMI1; l=https://example.com/brand/bimi-logo.svg; a=https://example.com/brand/bimi-vmc.pem"
It contains:
v=BIMI1— the version, which must come first.l=— an HTTPS URL to your logo, in a specific SVG format.a=— an HTTPS URL to a mark certificate (a VMC or CMC) that proves you have the right to use the logo. Optional in the spec, but required by Gmail and Apple Mail.
The default part of the name is the selector. Most domains only ever use default. Senders can use other selectors for different brands, signalled by a BIMI-Selector header in the message, but that's rarely needed.
BIMI is developed by the AuthIndicators Working Group (the BIMI Group) and has been progressing through the IETF as a draft specification. It isn't a published RFC yet, but it's widely deployed.
Why BIMI Exists
BIMI's purpose isn't decoration — it's an incentive. Mailbox providers want senders to adopt strict email authentication, because that's what stops domain spoofing. BIMI rewards domains that do it with a visible brand signal that recipients notice.
The benefits for you:
- Recognition. Your logo stands out in a crowded inbox and helps recipients identify your mail at a glance.
- Trust signals. In Gmail, senders with a Verified Mark Certificate also get a verified checkmark next to their name.
- Anti-phishing. Because BIMI only works with DMARC enforcement, an attacker spoofing your domain can't get your logo displayed — their mail fails authentication.
What BIMI doesn't do: it doesn't directly boost deliverability or bypass spam filtering. The authentication requirements behind it, however, do help.
How BIMI Works
When a supporting mailbox provider receives a message, the process looks roughly like this:
- Authentication checks run first. The receiver evaluates SPF, DKIM, and DMARC for the
From:domain. - The receiver checks the DMARC policy. The domain must have DMARC at an enforcing policy. If the message fails DMARC, or the policy is
p=none, BIMI stops here. - The receiver queries the BIMI record at
default._bimi.<from-domain>, falling back to the organizational domain if the exact domain has none. - The receiver fetches the logo and certificate from the URLs in the record, validates the SVG, and checks that the certificate covers your domain and contains the same logo.
- The logo is displayed — often cached by the provider, so changes can take time to appear.
Every one of those steps can fail independently, which is why BIMI setups often seem to "do nothing" at first.
Prerequisites: What Must Be in Place First
1. DMARC at enforcement
This is the requirement that stops most domains. Your DMARC record must use p=quarantine or p=reject. With quarantine, the policy must apply to all mail — no pct value below 100. Subdomain policy (sp) must not be none either.
A DMARC record that qualifies:
_dmarc.example.com. 3600 IN TXT "v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com"
A record that does not qualify:
_dmarc.example.com. 3600 IN TXT "v=DMARC1; p=quarantine; pct=50; rua=mailto:dmarc-reports@example.com"
Getting to enforcement safely takes time, and it's covered step by step in the DMARC setup guide.
2. Aligned DKIM and SPF on all mail
All the mail you want the logo on must pass DMARC, which means aligned DKIM or SPF. Third-party senders — marketing platforms, CRMs, helpdesks — need to sign with your domain.
3. A compliant SVG logo
BIMI requires a specific SVG profile called SVG Tiny Portable/Secure (SVG Tiny PS). Regular SVG exports from design tools usually won't pass.
4. A mark certificate (for Gmail and Apple Mail)
Gmail and Apple Mail require the a= tag to point to a valid mark certificate. Some other providers, such as Yahoo, may display a BIMI logo without one, but you'll reach far fewer inboxes.
Preparing the SVG Tiny PS Logo
The SVG Tiny PS profile strips out everything that could be used for tracking or scripting. Key requirements:
- The root element must declare
version="1.2"andbaseProfile="tiny-ps". - It must contain a
titleelement (usually your brand name). - No scripts, animations, external references, embedded raster images, or interactive elements.
- No
xoryattributes on the rootsvgelement. - The image should be square, with a solid background — many inboxes crop logos into a circle, so keep important elements centered.
- Keep the file small; the BIMI Group recommends staying under 32 KB.
A minimal compliant structure looks like this:
<?xml version="1.0" encoding="UTF-8"?>
<svg xmlns="http://www.w3.org/2000/svg" version="1.2" baseProfile="tiny-ps" viewBox="0 0 512 512">
<title>Example Inc</title>
<rect width="512" height="512" fill="#1a73e8"/>
<circle cx="256" cy="256" r="140" fill="#ffffff"/>
</svg>
This declares the Tiny PS profile, includes a title, and uses a square viewBox with a full-bleed background. Your real logo would replace the rectangle and circle with its own paths.
You can sanity-check a file before uploading it. This Python script flags the most common problems:
import sys
import xml.etree.ElementTree as ET
SVG_NS = "{http://www.w3.org/2000/svg}"
tree = ET.parse(sys.argv[1])
root = tree.getroot()
problems = []
if root.get("baseProfile") != "tiny-ps":
problems.append('root must have baseProfile="tiny-ps"')
if root.get("version") != "1.2":
problems.append('root must have version="1.2"')
if root.find(f"{SVG_NS}title") is None:
problems.append("missing title element")
if root.get("x") is not None or root.get("y") is not None:
problems.append("root svg must not have x or y attributes")
for el in root.iter():
tag = el.tag.replace(SVG_NS, "")
if tag in ("script", "image", "animate", "foreignObject"):
problems.append(f"disallowed element: {tag}")
print("\n".join(problems) if problems else "No common BIMI SVG problems found")
Run it with python3 check_bimi_svg.py bimi-logo.svg. It's not a full validator, but it catches the issues that cause most rejections. For a definitive check, use the BIMI Group's online inspector.
Host the file on an HTTPS URL you control, served with the image/svg+xml content type.
Verified Mark Certificates and Common Mark Certificates
A mark certificate is an X.509 certificate, issued by an authorized certificate authority, that binds your logo to your domain. It's what lets Gmail and Apple Mail trust that you're entitled to display a particular logo.
There are two kinds:
| Verified Mark Certificate (VMC) | Common Mark Certificate (CMC) | |
|---|---|---|
| Logo requirement | Registered trademark with a recognized trademark office | No trademark needed, but the logo must have been publicly used for at least a year |
| Gmail checkmark | Yes, shows a verified checkmark | Logo only, no checkmark |
| Apple Mail | Supported | Check current support; Apple has historically required a VMC |
| Validation | Organization identity checks plus trademark verification | Organization identity checks plus evidence of prior logo use |
Mark certificates are issued by a small number of authorized CAs, such as DigiCert and GlobalSign, and they cost significantly more than a standard TLS certificate. The CA embeds your SVG logo inside the certificate, so the logo in your l= URL must match exactly.
Once issued, you receive a PEM file containing the certificate chain. Host it on HTTPS, just like the logo, and reference it in the a= tag.
Publishing the BIMI Record
With the logo and certificate hosted, create a TXT record:
- Name:
default._bimi - Type: TXT
- Value:
v=BIMI1; l=https://example.com/brand/bimi-logo.svg; a=https://example.com/brand/bimi-vmc.pem
If you're adding it in a dashboard that appends your domain automatically, enter only default._bimi in the name field. For general guidance on where these settings live, see how to access DNS settings.
To explicitly declare that a subdomain shouldn't display a logo, you can publish an empty record:
default._bimi.notifications.example.com. 3600 IN TXT "v=BIMI1; l=; a=;"
Empty l= and a= values tell receivers that this domain has opted out of BIMI.
Checking Your BIMI Setup
First, confirm the record is live:
dig TXT default._bimi.example.com +short
Then confirm the DMARC policy qualifies:
dig TXT _dmarc.example.com +short
Check that the logo and certificate URLs are reachable and served with sensible content types:
curl -sI https://example.com/brand/bimi-logo.svg | grep -i content-type
curl -sI https://example.com/brand/bimi-vmc.pem | grep -i content-type
The logo should return image/svg+xml. If either URL returns a 404, a redirect to a login page, or an HTML error page, receivers won't display the logo.
Finally, send a message to a Gmail address and look at the original source. In Gmail, a successful BIMI evaluation is reflected in the authentication results, and the logo appears in the inbox once Gmail has processed and cached it — which can take anywhere from hours to a few days.
Common Mistakes and Best Practices
- DMARC isn't really at enforcement.
p=none,pctbelow 100 with quarantine, orsp=nonewill all prevent BIMI from working. - Non-compliant SVG. Exporting directly from a design tool almost always produces a regular SVG. Convert it to SVG Tiny PS and validate it.
- Logo mismatch. The SVG at
l=must match the logo embedded in your VMC or CMC. Updating the logo means getting a new certificate. - Expired certificate. Mark certificates are typically valid for one year. Set a renewal reminder — when it lapses, the logo disappears.
- Expecting instant results. Mailbox providers cache BIMI data and may apply their own reputation thresholds. Low-volume or new sending domains may not see the logo even with a perfect setup.
- Broken URLs after a site redesign. Moving the logo or certificate files breaks BIMI silently. Keep them at a stable path outside your normal site structure.
- Forgetting other sending subdomains. If you send from
mail.example.com, receivers check that name first and then fall back to the organizational domain. Make sure DMARC alignment covers it.
BIMI Record FAQ
BIMI stands for Brand Indicators for Message Identification. It's a standard that lets mailbox providers display a sender's logo next to authenticated messages.
For Gmail and Apple Mail, yes, you need a mark certificate. Gmail accepts either a Verified Mark Certificate or a Common Mark Certificate. Some other providers may show a logo without a certificate, but your reach will be limited.
The most common reasons are a DMARC policy that isn't at enforcement, a logo that isn't valid SVG Tiny PS, a missing or mismatched certificate, or provider caching. Mailbox providers may also require a sending reputation threshold before displaying logos.
Not directly. BIMI is a display feature. However, the strong authentication BIMI requires, especially DMARC at enforcement, does contribute to better deliverability.
It's a TXT record at default._bimi.yourdomain, where default is the selector. The value starts with v=BIMI1; and includes the logo URL and certificate URL.
No. BIMI only accepts SVG files in the SVG Tiny Portable/Secure profile. Raster images, including those embedded inside an SVG, aren't allowed.
A VMC requires a registered trademark and earns a verified checkmark in Gmail. A CMC doesn't require a trademark, only proof the logo has been in use for at least a year, and shows the logo without the checkmark.
Yes, as long as the policy applies to all mail. A quarantine policy with pct set below 100 doesn't qualify, and neither does p=none.
Conclusion
A BIMI record is only a few dozen characters of DNS, but it sits at the top of a stack of requirements: aligned SPF and DKIM, DMARC at enforcement, a logo in a strict SVG profile, and, for the biggest inboxes, a mark certificate. That's by design. BIMI rewards domains that have done the work of preventing spoofing, and the logo it displays is a signal that the message really came from you.
If your DMARC policy is already at quarantine or reject, BIMI is mostly a matter of preparing the logo, deciding whether a VMC or CMC fits your brand, and publishing one TXT record. If you're not there yet, treat BIMI as a goal at the end of your DMARC rollout — the security benefits of getting there are worth more than the logo itself.
Here are some useful references for going deeper on BIMI:
- BIMI Group: Brand Indicators for Message Identification — the official home of the BIMI standard, with implementation guides and a record inspector.
- RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC) — the DMARC specification BIMI depends on.
- W3C: Scalable Vector Graphics (SVG) Tiny 1.2 Specification — the SVG profile on which SVG Tiny PS is based.
- Google Workspace Admin Help: Email sender guidelines — Gmail's authentication requirements that underpin BIMI.


