BIMI readiness checklist: DMARC, SVG and certificates
Everything you need before a BIMI logo shows up: DMARC at enforcement, an SVG Tiny PS logo, an optional VMC or CMC, and a correctly formed DNS record.

On this page(9 sections)
- What BIMI is, and what it is not
- Prerequisite 1: DMARC at enforcement
- Prerequisite 2: aligned authentication on every stream
- Prerequisite 3: a logo in SVG Tiny Portable/Secure
- Prerequisite 4: a mark certificate (for most providers)
- Prerequisite 5: the BIMI DNS record
- A readiness checklist
- Why the logo might still not appear
- Key takeaways
BIMI puts your logo next to your messages in supporting inboxes, but only after a chain of prerequisites is in place. Most failed BIMI rollouts are not logo problems at all; they are DMARC problems that the logo exposed.
What BIMI is, and what it is not
Brand Indicators for Message Identification (BIMI) is a DNS-based way for a domain owner to tell mailbox providers which logo to show beside authenticated mail. The domain publishes a TXT record pointing to a logo file and, optionally, to a certificate that proves the right to use that logo. Receivers that support BIMI fetch the logo and display it when a message passes their checks.
BIMI is not an authentication protocol in its own right. It does not decide whether a message is genuine; it rides on top of DMARC. It is also not a guarantee. Every mailbox provider decides for itself whether to show a logo, and most also factor in sending reputation. Think of BIMI as a reward for strong authentication, not as a shortcut to it.
Prerequisite 1: DMARC at enforcement
This is the gate most domains fail. BIMI requires that your organizational domain publish a DMARC policy of p=quarantine or p=reject. A p=none policy, which only monitors, does not qualify, because it gives receivers no assurance that spoofed mail using your domain is being stopped.
Details that trip people up:
- The subdomain policy matters too. If you set
sp=none, receivers may decline to show a logo, since subdomains of your brand remain spoofable. - Partial enforcement is a problem. Under the original DMARC specification, a
pctvalue below 100 meant only some failing mail was subject to the policy. BIMI guidance has long expected full enforcement. Thepcttag was removed when DMARC was republished as RFC 9989 in 2026, so there is no reason to keep it in a record you are preparing for BIMI. - Messages must actually pass DMARC. The policy is about your domain; the logo decision is about each message. A message that fails DMARC will not get a logo regardless of your record.
_dmarc.example.com. TXT "v=DMARC1; p=reject; rua=mailto:[email protected]"
If you are still at p=none, the BIMI project is really a DMARC enforcement project. Do that first.
Prerequisite 2: aligned authentication on every stream
Every system that sends with your domain in the From header needs SPF or DKIM to pass and align. In practice that means aligned DKIM signatures from your mailbox provider, your transactional sender, your marketing platform and every vendor that sends on your behalf. DMARC aggregate reports are the inventory tool here: any legitimate source still failing alignment will have its mail quarantined or rejected once you enforce, and it will certainly not get a logo.
Prerequisite 3: a logo in SVG Tiny Portable/Secure
BIMI does not accept arbitrary image files. The logo must be an SVG file conforming to the SVG Tiny Portable/Secure profile (often written SVG Tiny PS), a restricted subset of SVG designed to be safe to render inside mail clients. Among other things, the profile forbids scripts, external references, animation and embedded raster images, and requires a title element and specific root attributes.
Practical requirements for the file:
- Served over HTTPS from a publicly reachable URL.
- A square aspect ratio with the mark centered, because many clients crop logos into a circle.
- A solid background color rather than transparency, so the logo reads well in both light and dark themes.
- Small file size; BIMI guidance recommends keeping it to tens of kilobytes.
Converting an ordinary logo export into a valid SVG Tiny PS file is usually the most fiddly part of the project, and we cover it step by step in a separate guide.
Prerequisite 4: a mark certificate (for most providers)
Some mailbox providers require a certificate that ties the logo to your organization before they display it. There are two kinds:
| Certificate | Main requirement | Typical use |
|---|---|---|
| Verified Mark Certificate (VMC) | The logo is a registered trademark | Brands with trademark registrations |
| Common Mark Certificate (CMC) | Evidence the logo has been in public use for a period | Brands without a registered mark |
Gmail requires a VMC or CMC to show a BIMI logo, and its documentation describes some differences in how the two are presented, with the verified checkmark tied to VMCs. Other providers have their own policies, and some show logos without any certificate for senders with strong reputation. Check each provider's current documentation for the inboxes your recipients use most; policies in this area have changed several times.
Certificates are issued by a small number of certificate authorities after identity and trademark or usage verification, and they expire, so renewal belongs on someone's calendar.
Prerequisite 5: the BIMI DNS record
The record lives at the default selector under _bimi:
default._bimi.example.com. TXT "v=BIMI1; l=https://example.com/brand/logo.svg; a=https://example.com/brand/vmc.pem"
v=BIMI1identifies the record.l=is the HTTPS URL of the SVG logo.a=is the HTTPS URL of the certificate file in PEM format. Leave it empty (a=;) if you have no certificate.
The default selector applies unless a message specifies another one with a BIMI-Selector header, which is rarely needed. Subdomains without their own record generally fall back to the organizational domain's record.
A readiness checklist
Work through this list in order; each item depends on the ones before it.
- DMARC published at
p=quarantineorp=reject, with no partial-enforcement settings and nosp=none. - Aggregate reports reviewed for at least a few weeks, with every legitimate source passing aligned SPF or DKIM.
- Sending reputation in good shape: low complaint rates, no current blocklist listings, consistent volume.
- Logo converted to SVG Tiny PS, square, with a solid background, validated with a BIMI checker.
- Logo hosted over HTTPS at a stable URL that will not move during a website redesign.
- VMC or CMC obtained if your key mailbox providers require one, with the PEM file hosted over HTTPS.
default._bimiTXT record published and verified withdig.- Test messages sent to accounts at supporting providers.
dig +short TXT default._bimi.example.com
curl -sI https://example.com/brand/logo.svg | head -1
Why the logo might still not appear
Even with everything correct, logos often take time to show up, and sometimes do not appear at all. Common reasons:
- The provider caches BIMI lookups and has not refreshed yet.
- The specific message failed DMARC, for example because it came through a forwarder.
- The provider applies reputation thresholds and your domain has not met them.
- The client or app version in use does not display BIMI logos.
- The certificate does not match the logo file byte-for-byte, or has expired.
Most BIMI validators will check record syntax, logo profile compliance and certificate consistency, which narrows the problem quickly.
Key takeaways
- BIMI rewards strong authentication; it does not replace it. DMARC at
quarantineorrejectis the non-negotiable starting point. - Every legitimate sender must pass aligned SPF or DKIM before you enforce.
- The logo must be SVG Tiny PS, square, hosted over HTTPS.
- Gmail requires a VMC or CMC; other providers set their own rules, so check current documentation.
- Publish
default._bimiwithl=anda=, test, and expect some delay before logos appear.
Start with Koltrix
Your domain, one inbox, and an API that sends.
A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.


