BIMI. Get Your Logo in the Inbox
The DNS record that puts your brand logo next to your emails in Gmail and Yahoo, and the DMARC enforcement bar you must clear first.
p=quarantine or p=reject (not p=none), a logo in the strict SVG Tiny PS format, and for Gmail, a paid Verified Mark Certificate. Treat BIMI as the reward at the end of the authentication journey, not a quick win.What is BIMI?
BIMI (Brand Indicators for Message Identification) is a standard that lets mailbox providers display your brand logo as the avatar for your messages, in place of the grey initial-letter circle. You publish a TXT record at default._bimi.yourdomain.com pointing to an SVG of your logo; providers that support BIMI fetch it and, if your authentication checks out, show it in the inbox.
The catch, and the entire point of the standard: providers only display logos for mail that is strongly authenticated. BIMI is deliberately designed as a carrot to push domains toward DMARC enforcement. No enforcement, no logo, no exceptions.
Why it matters
- Inbox real estate and trust: a recognized logo measurably lifts open rates (vendors claim anywhere from a few percent up; your mileage will vary) and makes phishing lookalikes easier for recipients to spot.
- It forces good hygiene: you cannot get BIMI without DMARC at enforcement, which means you cannot get it without SPF and DKIM alignment sorted. Domains with BIMI are, by construction, hard to spoof.
- Verified blue checks: Gmail pairs the logo with a verification checkmark when a VMC is present, visible brand verification in the most-used inbox on earth.
Prerequisites, in order
- SPF and DKIM passing and aligned for all your mail streams. See the SPF guide and the DKIM guide.
- DMARC at enforcement:
p=quarantine(withpct=100) orp=reject, on the organizational domain. Our DMARC guide covers the safe ramp fromp=none. - A logo in SVG Tiny PS format: square, no scripts or external references, with a
<title>. There are free converters; budget an hour of fiddling. - (For Gmail) a VMC or CMC: a Verified Mark Certificate from DigiCert or Entrust, generally requiring a registered trademark for the logo (CMCs relax this to logos with established prior use). Roughly $1,000–1,500/year.
p=reject before your DMARC reports show all legitimate senders aligned will quarantine your own mail, a much worse outcome than a grey avatar. The logo can wait; lost invoices can't.How to check it
dig +short txt default._bimi.example.com
# Expect: "v=BIMI1; l=https://example.com/logo.svg; a=https://example.com/vmc.pem"Then verify the l= URL serves the SVG over HTTPS, and that your DMARC record shows p=quarantine or p=reject.
Setting it up, step by step
- Confirm DMARC enforcement has been stable for a few weeks with clean aggregate reports.
- Produce the SVG Tiny PS logo and host it at a stable HTTPS URL on a domain you control, e.g.
https://example.com/bimi/logo.svg. - (Optional but required for Gmail) obtain a VMC, you'll get a PEM file to host alongside the logo.
- Publish the TXT record at the
defaultselector:
Without a VMC, either omitdefault._bimi.example.com. TXT "v=BIMI1; l=https://example.com/bimi/logo.svg; a=https://example.com/bimi/vmc.pem"a=or leave it empty (a=;), Yahoo will still display the logo. - Send test mail to Gmail and Yahoo accounts and wait, logo display can take days as providers fetch and validate, and Gmail also weighs sender reputation.
Common mistakes
- DMARC at
p=none. The number one reason BIMI "doesn't work". The record can be perfect; no enforcement, no logo. pct=50orsp=noneleftovers. Partial enforcement disqualifies you at most providers. Subdomain policy counts too.- A normal SVG instead of Tiny PS. Exports straight from design tools nearly always fail validation. Run it through a BIMI SVG converter/validator.
- Logo URL breaking later. The asset is fetched continually, not once. A site migration that 404s
/bimi/logo.svgquietly removes your logo everywhere. - Letting the VMC expire. It's a certificate; it renews annually like one. An expired VMC drops your Gmail logo and checkmark.
Monitoring BIMI going forward
BIMI is a chain of dependencies, DMARC policy, DNS record, hosted SVG, VMC validity, and a regression in any link silently removes your logo. Nobody files a ticket about a missing avatar; you just lose the trust signal you paid for.
DomainsDoc checks the full chain continuously: the BIMI record syntax, the logo URL's reachability, and the DMARC enforcement level it depends on, alongside SPF, DKIM, MX, and the rest of your domain's health. Add your domain and we'll alert you the moment any link weakens; plans are on the pricing page.
Frequently asked questions
What is BIMI in plain English?
Do I really need DMARC at p=quarantine or p=reject for BIMI?
What is a VMC and do I need one?
What format does the BIMI logo need to be?
My BIMI record is valid but Gmail still shows no logo. Why?
Continuous SPF, DKIM, DMARC, blacklist, SSL, and uptime checks. Alerts the moment something breaks.