BIMI: Setup, Requirements and What It Actually Does (2026)

BIMI displays your brand logo next to authenticated emails in Gmail, Yahoo, Apple Mail and other providers. This guide covers what BIMI does (and doesn't do), the DMARC and SVG prerequisites, the Verified Mark Certificate, provider-by-provider support in 2026, and 10 common setup mistakes.
Alaa
By Alaa
SMTPedia documents email infrastructure end to end: SMTP standards from the RFC archive, delivera...
13 min read Updated Aug 27, 2026 121 views

Quick BIMI reference

BIMI (Brand Indicators for Message Identification) is the standard that lets you display your brand logo next to your authenticated emails in the recipient’s inbox. It is not a deliverability mechanism; it is a brand visibility layer on top of DMARC, and it only works once your authentication is already strict and clean.

What it doesDisplays your brand logo in the inbox, next to the sender name, at major providers
What it doesn’t doImprove deliverability, raise inbox placement, or fix authentication problems
Hard prerequisiteDMARC policy of p=quarantine or p=reject with at least 100 % coverage
Logo formatSVG Tiny Portable Secure (SVG 1.2 Tiny PS profile)
VMC (optional but expanding)Verified Mark Certificate from DigiCert or Entrust; required by Gmail, optional elsewhere
Supporting providers (2026)Gmail, Yahoo, Apple Mail, Fastmail, La Poste, ProtonMail (partial)

What is BIMI?

BIMI is an IETF-aligned standard that lets a domain owner publish a logo to be displayed by mailbox providers next to authenticated mail from that domain. The mailbox provider checks two things at delivery time: that the message passed DMARC with a sufficiently strict policy, and that a BIMI DNS record points to a valid logo image (and, optionally, a Verified Mark Certificate). When both conditions are met, the recipient sees the brand logo as the avatar instead of the default initial or generic icon.

The standard was proposed by AOL, Comcast, Google, and others in 2019 and has been gradually adopted across major providers since 2021. It is published in IETF drafts (draft-blank-ietf-bimi) and the BIMI Group (bimigroup.org) maintains operational documentation. As of 2026, Gmail, Yahoo, Apple Mail, Fastmail, La Poste, and ProtonMail (for paid accounts) all support BIMI display, with implementation details varying provider by provider.

The point of BIMI is brand visibility, not technical deliverability. A message that fails DMARC still fails DMARC, with or without BIMI. A message that lands in spam still lands in spam. What BIMI does is reward already-authenticated senders with a stronger visual identity in the inbox, on the theory that recipients trust mail with a recognized brand logo more than mail with an anonymous avatar.

Why BIMI matters (and when it doesn’t)

The case for implementing BIMI rests on three benefits, all measured rather than guaranteed:

  • Brand recognition. A logo next to your name in the inbox is more identifiable than an “S” avatar, especially at scale. Senders that report engagement metrics typically see open-rate lifts of 5 to 15 % after BIMI is live, with the variance depending heavily on existing brand recognition.
  • Anti-phishing signaling. Phishing campaigns impersonating your domain cannot show your logo because they can’t pass DMARC against your domain. The visible logo becomes a quick “this is legitimate” cue for recipients.
  • Authentication discipline. BIMI requires DMARC at p=quarantine or p=reject with full coverage, which forces you to actually finish DMARC roll-out rather than leaving it at p=none indefinitely. The hygiene benefit alone can justify the project.

The case against, or at least for delaying, is also real:

  • Cost. A VMC certificate (required for Gmail) runs around $1,200 to $1,500 per year per domain at DigiCert or Entrust. For a small sender or a personal domain, the math rarely works.
  • Trademark requirement. VMCs require a registered trademark for the logo. Senders without one cannot get a VMC and therefore cannot display in Gmail (the largest provider).
  • DMARC prerequisite. If your DMARC is at p=none or only partial coverage, you have weeks to months of cleanup before BIMI is even possible. That cleanup is the right work to do anyway, but it’s not the same project as BIMI.

BIMI is worth it for established brands with active marketing programs and clean authentication. It is not worth it for one-off senders, internal-only domains, or anyone still stabilizing DMARC.

BIMI prerequisites

  1. DMARC at p=quarantine or p=reject. A policy of p=none does not qualify. The DMARC TXT record must publish either p=quarantine with pct=100, or p=reject (any percentage, but full coverage is best practice). See our DMARC setup guide and the reject vs quarantine roadmap for the staging plan.
  2. Clean SPF and DKIM. Both must be passing and aligned for the volume of mail you actually send. BIMI fails silently if a campaign fails DMARC.
  3. SVG logo in Tiny PS profile. Standard SVG is not enough. The logo must conform to the SVG 1.2 Tiny Portable Secure profile: no scripts, no animations, no external references, no raster images embedded, square aspect ratio, centered design.
  4. Logo hosted on HTTPS. The BIMI DNS record points to an HTTPS URL where the SVG is served with proper Content-Type and TLS.
  5. (For Gmail) A Verified Mark Certificate. Gmail will only display BIMI logos backed by a VMC. Other providers display without one, but the Gmail audience is large enough that most senders go for the VMC.
  6. Registered trademark of the logo. Required by DigiCert and Entrust to issue a VMC. The mark must be registered in a jurisdiction recognized by the issuer (most major trademark offices qualify).

The three components: DMARC, SVG, VMC

1. DMARC alignment

BIMI uses the existing DMARC pass result as its authentication gate. The mailbox provider checks DMARC first, then if (and only if) DMARC passes with a qualifying policy, it queries the BIMI record. There is no separate authentication step.

The logo file is the visible component. It must be a Tiny PS SVG (a restricted profile of SVG 1.2 Tiny), typically 32 x 32 to 96 x 96 viewBox, square, with a transparent or solid background that works on both light and dark inbox themes. Designers usually start from an existing brand SVG and run it through validators (the BIMI Group provides one at bimigroup.org/svg-validator).

3. The Verified Mark Certificate (VMC)

The VMC is a digital certificate that binds the logo to your domain and proves trademark ownership. Issued by DigiCert or Entrust (the only authorized CAs as of 2026). The certificate is hosted at an HTTPS URL referenced from the BIMI DNS record. Validity is typically 1 year, requiring annual renewal.

Step-by-step setup

  1. Confirm DMARC. Check your _dmarc.example.com TXT record. Confirm p=quarantine with pct=100 or p=reject. Watch DMARC aggregate reports for 2-4 weeks to confirm no legitimate sources are failing.
  2. Design or convert the logo to SVG Tiny PS. Square viewBox, no scripts, no external refs, no animations. Validate at bimigroup.org/svg-validator. Host on HTTPS with Content-Type image/svg+xml.
  3. Register or confirm the trademark. Submit to USPTO, EUIPO, or the equivalent office in your jurisdiction if not already done. Typical processing time is 6 to 18 months for new applications. VMCs require the mark to be registered, not just pending.
  4. Purchase a VMC. Apply at digicert.com or entrust.com. They verify trademark ownership, domain control, and (typically) corporate identity. Provisioning takes 1 to 3 weeks once documentation is complete.
  5. Publish the BIMI DNS record. Add a TXT record at default._bimi.example.com with the format below. The l= tag points to the SVG, a= points to the VMC (omit a= if you are not using a VMC).
default._bimi.example.com. IN TXT "v=BIMI1; l=https://example.com/logo.svg; a=https://example.com/vmc.pem"
  1. Test. Use the BIMI Inspector (bimigroup.org/bimi-generator-and-inspector/) to verify the record, fetch the SVG, validate the VMC, and confirm everything resolves correctly.
  2. Send a test message. Send a campaign to a Gmail address you control and a Yahoo address. Wait for delivery; the logo should appear next to the sender name within 24 to 48 hours of the first send from that domain after BIMI is live.
  3. Monitor. Watch DMARC aggregate reports for any new failures introduced by traffic patterns you didn’t account for. Renew the VMC annually.

SVG logo requirements in detail

The SVG Tiny Portable Secure profile is more restrictive than standard SVG. The full list:

  • Profile declaration. The file must start with <svg xmlns="http://www.w3.org/2000/svg" version="1.2" baseProfile="tiny-ps">.
  • No scripts. No <script> elements, no event handlers (onclick, etc.).
  • No external references. No <use href="external">, no external CSS, no external fonts.
  • No raster images. No <image> elements with embedded JPGs or PNGs. Pure vector only.
  • No animations. No <animate>, no SMIL, no CSS transitions or animations.
  • Square viewBox. Width and height must be equal. Typical values: 32, 64, 96, 128.
  • Title element. A <title> element is required, describing the logo.
  • File size. Recommended under 32 KB. Larger files work technically but slow down inbox rendering.
  • Background. Solid or transparent. Avoid intricate detail that disappears at small render sizes (most providers display at 24 to 48 pixels).

Verified Mark Certificate explained

The VMC is what distinguishes BIMI from “just publish an SVG and hope”. Without a VMC, a malicious sender who manages to pass DMARC for your domain could also display your logo, defeating the purpose. The VMC is a cryptographic proof that the logo at the URL belongs to the legal entity claiming the trademark.

Issuance involves three layers of verification:

  1. Trademark verification. The certificate authority queries the relevant trademark office (USPTO, EUIPO, JPO, IPI, etc.) to confirm the mark is registered to the entity applying.
  2. Domain control. Standard ACME-style validation (DNS TXT record or HTTP file) proves you own the domain.
  3. Corporate identity. Sometimes a formal Letter of Authorization or chain-of-control documentation is required, especially for subsidiaries or licensed brands.

Pricing (DigiCert and Entrust list prices, 2026): around $1,200 to $1,500 per year per domain. Bulk discounts apply for groups of domains. Some ESPs (Mailchimp, Salesforce Marketing Cloud, others) offer bundled VMC packages for their enterprise customers.

A second-tier option exists: Common Mark Certificates (CMC), introduced in 2024, allow logos that aren’t trademark-registered to be verified via prior-use evidence rather than trademark registration. CMC support is rolling out across providers; Gmail does not yet display CMC-backed logos as of mid-2026.

Provider support (2026)

ProviderBIMI displayVMC required?Notes
GmailYesYes (VMC mandatory)Largest BIMI audience; the main reason most senders implement
Yahoo MailYesNoDisplays without VMC; first major provider to support BIMI
Apple Mail (iCloud)YesYesRequires VMC since iOS 16; partial roll-out
FastmailYesNoEarly adopter; displays without VMC
La PosteYesNoFrench regional provider
ProtonMailPartialNoPaid plans only as of mid-2026
Outlook (consumer, Microsoft 365)Non/aMicrosoft has tested BIMI in pilots; no public roll-out
AOL MailYesNoShared infrastructure with Yahoo

The big gap is Microsoft. Outlook and Microsoft 365 do not currently display BIMI logos at scale, which means BIMI’s reach today is roughly the Gmail + Yahoo + Apple combined audience. For B2B senders heavy on Outlook, that’s a smaller share than for B2C senders.

10 common BIMI mistakes

  1. Publishing BIMI before DMARC is at p=quarantine or p=reject. The record will validate but the logo will not display anywhere.
  2. Using a standard SVG instead of SVG Tiny PS. Standard SVG with scripts or external references is rejected by every BIMI validator.
  3. Non-square logo viewBox. Rectangular logos cannot be rendered as inbox avatars. Crop or pad to square.
  4. Hosting the SVG on HTTP instead of HTTPS. BIMI strictly requires HTTPS for the logo URL.
  5. Incorrect Content-Type on the SVG. Must be image/svg+xml. Some CDNs default to text/xml or application/octet-stream, which fails validation.
  6. Buying a VMC for a logo without a registered trademark. The CA will reject the application; the registration is mandatory for VMCs (CMCs are an alternative, but not Gmail-supported yet).
  7. Publishing the BIMI record at the wrong subdomain. The standard is default._bimi.; a typo like _bimi. alone won’t be queried by providers.
  8. Forgetting to renew the VMC. Certificates expire annually; logos stop displaying immediately on expiry.
  9. Expecting BIMI to fix deliverability. It doesn’t. If your messages were going to spam before BIMI, they go to spam after BIMI too.
  10. Designing a logo too detailed for small render sizes. Most inboxes render at 24 to 48 pixels. Fine detail disappears. Design for the small size first, scale up.

BIMI FAQ

Does BIMI improve email deliverability?

No. BIMI is a display feature, not a filtering signal. A message that fails DMARC still fails DMARC; a message that lands in spam still lands in spam. What BIMI can do is increase open rates and recognition once messages have already reached the inbox, by attaching a verified logo to the sender identity. The improvement is in engagement, not in inbox placement.

Do I need a VMC to implement BIMI?

For Gmail display, yes (or a CMC, with limited support). For Yahoo, Fastmail, La Poste, and AOL, no, the SVG alone is enough. For Apple Mail since iOS 16, yes. Most senders implement with a VMC because Gmail is too large an audience to skip. Senders without a registered trademark or without the budget for a $1,200 to $1,500 annual cert can still deploy BIMI for Yahoo and the smaller providers.

How long does it take to set up BIMI from scratch?

The DNS record and SVG hosting can be done in an hour. The VMC takes 1 to 3 weeks of certificate authority processing. The hardest part is usually getting DMARC to p=quarantine or p=reject with full coverage, which takes 4 to 12 weeks for a sender starting at p=none. Total realistic timeline: 6 to 16 weeks from kickoff to live logos in inboxes.

Can I publish BIMI without a VMC and add the VMC later?

Yes. The BIMI record can publish only the l= tag (logo URL) initially. Logos will display at Yahoo, Fastmail, La Poste, and AOL but not Gmail or Apple. Later, when the VMC is issued, add the a= tag pointing to the certificate and Gmail starts displaying within 24 to 48 hours of the next send.

What happens to BIMI if my DMARC policy fails?

A message that fails DMARC at delivery time will not display the BIMI logo for that message. The logo display is per-message, not per-domain: each individual message is checked, and only those that pass DMARC trigger the logo. This is why getting DMARC coverage to 100 % is important before going live with BIMI; otherwise some campaigns display the logo and some don’t, looking like a bug to recipients.

Does Outlook or Microsoft 365 support BIMI?

Not as of mid-2026. Microsoft has tested BIMI in limited pilots but has not announced a public roll-out. For B2B senders with a Microsoft-heavy audience, this is the biggest gap in BIMI’s coverage. The standard’s value still comes from Gmail, Yahoo, and Apple, which together cover the majority of consumer mailboxes.

Final words

BIMI is the visible reward for senders who finish the DMARC project. It does not replace authentication, it does not improve placement, and it is not cheap, especially with a VMC. But for established brands that already authenticate cleanly, it adds a meaningful trust signal at the moment recipients scan their inbox, and that signal compounds over thousands of impressions per day.

The honest order of work is: get DMARC to p=reject at 100 % first, run that for a few weeks to confirm stability, then implement BIMI. Skipping the DMARC work to “get BIMI live” is a waste of time because the logo will not display.

For broader context, see our guides on DMARC setup, SPF, DKIM, and the Deliverability hub.

Clean your list before you send.

SMTPing catches what regex misses: disposable addresses, role-based emails, catch-all domains, syntax errors, dead mailboxes and known traps. 13 validation types, 25 free checks daily, no card required.

Try SMTPing →

About the Author

Alaa - SMTPedia author

Alaa · LinkedIn

Email infrastructure specialist with 8+ years of hands-on experience in SMTP, deliverability, and email verification. I’ve configured and troubleshot mail systems across Postfix, Exchange, and cloud relays, managed IP reputation and warmup campaigns, and built verification pipelines processing millions of addresses. My work spans DNS authentication (SPF, DKIM, DMARC, BIMI), bounce handling, blocklist monitoring, and compliance frameworks including CAN-SPAM and GDPR. I write every article on SMTPedia to give email professionals, developers, and marketers the accurate, RFC-grounded reference they need.


About SMTPedia

SMTPedia is an independent email industry reference covering SMTP, IMAP, POP3, email deliverability, marketing platforms, DNS authentication, and email verification. Every article is researched from official provider documentation, IETF RFCs, and industry best practices. Settings and configurations are verified quarterly.

We are cited as a source by ChatGPT, Microsoft Copilot, and thousands of email professionals worldwide. Learn more about our editorial process.