BIMI: showing a brand logo next to its messages
BIMI lets mailbox providers display the logo of an authenticated domain. DMARC prerequisites, SVG format, VMC and CMC certificates, DNS record and pitfalls.
Bijgewerkt op 01/10/2026
BIMI (Brand Indicators for Message Identification) is a specification that lets a domain publish the location of its logo so that supporting mail clients display it next to authenticated messages. BIMI does nothing for delivery: it is a display mechanism, gated by strict DMARC authentication. The specification is maintained by the BIMI Group and published as an IETF draft (draft-brand-indicators-for-mail-identification).
How it works
When a message arrives, the mailbox provider evaluates DMARC. If the result is pass and the domain's policy is strict enough, it queries DNS for a BIMI record, fetches the logo from the given URL, optionally verifies the associated certificate, then hands the image to the mail client. Providers usually cache the logo and apply their own rules on top: domain reputation, sending history, presence of a certificate.
The logo is therefore never shown for a message that fails DMARC, which makes BIMI an incentive to tighten the policy more than a marketing tool as such.
DMARC prerequisites
Providers require, on the organisational domain:
- a
p=quarantineorp=rejectpolicy; pct=100(or nopcttag);- a subdomain policy
sp=that is notnone, if present.
A domain at p=none will never have its logo displayed, however good the BIMI record is.
The DNS record
The record is a TXT published under the default._bimi label (the default selector is default; other selectors can be named through a BIMI-Selector: header in the message).
default._bimi.example.com. IN TXT "v=BIMI1; l=https://assets.example.com/brand/logo.svg; a=https://assets.example.com/brand/vmc.pem"
v=BIMI1: version, mandatory;l=: HTTPS URL of the logo in SVG Tiny Portable/Secure format;a=: HTTPS URL of the mark certificate (VMC or CMC), optional in the specification but required by several providers.
A record with an empty l= and an empty a= explicitly means "no logo" for that selector.
Logo format
The file must follow the SVG Tiny Portable/Secure profile (SVG Tiny PS) defined by the BIMI Group: a restricted SVG Tiny 1.2 with no script, no external image, no animation or link, a baseProfile="tiny-ps" attribute and a <title> element. The image should be square, centred, preferably on a solid background, and under 32 KB. Export tools in drawing software rarely produce a compliant file without manual cleanup.
VMC and CMC certificates
A Verified Mark Certificate (VMC) is an X.509 certificate issued by an authority approved by the BIMI Group, attesting that the logo matches a trademark registered with a recognised office. The Common Mark Certificate (CMC), introduced in 2024, covers logos that are not registered but whose use by the domain has been established for at least twelve months; it unlocks display at some providers without the verification checkmark.
The certificate embeds the logo itself: the SVG published at the l= URL must be byte-for-byte identical to the certified one.
Deploying BIMI
- Bring the organisational domain to
p=quarantineorp=reject, withpct=100, after validating every source in the DMARC reports. - Produce the logo as SVG Tiny PS, validate it with a checking tool, publish it over HTTPS with a valid TLS certificate.
- Depending on the providers you target, obtain a VMC or a CMC from an approved authority and publish the PEM file over HTTPS.
- Publish the
default._bimirecord. - Check display in the target clients. Each provider applies its own conditions: some require a certificate, others display without one, and all take domain reputation into account.
Common mistakes
- DMARC at
p=noneorpctbelow 100: the logo is never shown. - Non-compliant SVG: a file exported with CSS styles, fonts or elements forbidden by the profile.
- HTTP URL or an expired TLS certificate on the server hosting the logo.
- Logo differing between the published file and the certificate.
- Forgotten subdomains: a stream sent from
news.example.comfirst looks updefault._bimi.news.example.com, then falls back to the organisational domain; a weak subdomain DMARC policy blocks display. - Expecting a deliverability effect: BIMI does not change how messages are classified.
What SenderRadar shows
SenderRadar indicates whether a BIMI record is published for the domain, whether the logo is reachable and conforms to the expected profile, whether a certificate is declared and in what state, and above all whether the domain's DMARC policy meets the display prerequisites. SenderRadar relies on its own analysis base to flag gaps between these elements.