Brand Indicators for Message Identification (BIMI) lets domain owners display their official verified logo beside every delivered message in Gmail, Yahoo Mail, and Apple Mail. Earning the Gmail blue verified checkmark requires a Verified Mark Certificate (VMC) from an authorized CA — which in turn requires DMARC enforcement at p=reject, a registered trademark, and an SVG file built to a spec that most design tools won't produce by default. This guide walks through every step, including the parts the official documentation leaves ambiguous.

1. Prerequisites — What Must Be True Before You Start

BIMI has a strict dependency chain. Skipping any layer causes silent validation failure — the logo simply doesn't appear, with no error surfaced to the sender.

A. DMARC at p=reject or p=quarantine (pct=100)

Your root domain must publish a DMARC policy of p=quarantine with pct=100, or p=reject. A p=none policy is an explicit BIMI disqualifier. Subdomain policies (sp=) do not substitute for root domain enforcement.

The most common reason BIMI implementation fails at this stage: a domain that achieved p=reject for its primary mail stream but still has third-party sending services (CRM platforms, transactional email providers, marketing automation tools) that fail DMARC alignment. Every sending service must either align its SPF Return-Path or sign with DKIM under the root domain before moving to full enforcement.

v=DMARC1; p=reject; rua=mailto:dmarc-reports@yourdomain.com; ruf=mailto:dmarc-forensic@yourdomain.com; pct=100; adkim=s; aspf=s

B. SPF and DKIM Alignment — What "100%" Actually Means

BIMI validators check that outbound email passes DMARC — meaning at least one of SPF alignment or DKIM alignment must succeed on every sent message. In practice, DKIM alignment is more reliable for BIMI purposes because SPF alignment breaks when email is forwarded (the forwarding server's IP is not in your SPF record). Use DKIM as the primary alignment mechanism and treat SPF as secondary.

Strict alignment (adkim=s) requires the DKIM d= domain to exactly match the From: header domain. Relaxed alignment (adkim=r) allows subdomain matches. Most enterprise setups work at relaxed alignment — but if you use strict, ensure your email service signs with the exact root domain as the d= value.

C. Registered Trademark — Country and Class Requirements

Your logo must be a registered trademark. A pending trademark application does not qualify. The trademark must be registered in the jurisdiction where your CA operates — for global brands, this means USPTO (United States), EUIPO (European Union), or another WIPO-recognized IP office. The logo submitted to the CA for VMC issuance must visually match the trademark registration.

2. Preparing the BIMI SVG Tiny PS Logo File

Standard SVG files exported from Figma, Illustrator, or Inkscape will not display in mailbox clients. BIMI requires SVG Tiny Portable/Secure (SVG Tiny PS) — a restricted subset of SVG 1.2 that prohibits animations, external references, JavaScript, and embedded rasters.

Technical SVG Tiny PS Requirements

RequirementValue / RuleCommon Mistake
SVG version declarationversion="1.2" baseProfile="tiny-ps"Exporting at SVG 1.1 (default in most tools)
Aspect ratio1:1 square viewBox onlyLandscape or portrait logos — must be padded to square
Color modelSolid fills only; no gradients, no filtersDrop shadows, blurs, or gradient fills from brand guidelines
No external referencesNo <image>, no font links, no <use href> to external filesGoogle Fonts imported in the SVG, or raster logos embedded as base64
No scripts or animationsNo <script>, no <animate>, no SMILSVG animations added by export tools
Solid backgroundFull-bleed background color rectangle requiredTransparent background — shows as broken in most clients
File must be HTTPS-accessibleServed from a public HTTPS URL; no redirectsHosting on HTTP, or behind a redirect chain

Minimal Valid SVG Tiny PS Template

<?xml version="1.0" encoding="utf-8"?>
<svg version="1.2" baseProfile="tiny-ps"
     xmlns="http://www.w3.org/2000/svg"
     viewBox="0 0 512 512"
     width="512" height="512">
  <title>Your Brand Name</title>
  <!-- Solid background — required, no transparency -->
  <rect width="512" height="512" fill="#1a56db"/>
  <!-- Logo mark as pure vector paths -->
  <path d="M256 100 L380 380 L132 380 Z" fill="#ffffff"/>
</svg>

3. Verified Mark Certificate (VMC) — CA Comparison

A VMC is required by Gmail to display logos with the verified blue checkmark. Yahoo Mail and Apple Mail display logos without a VMC (using only the BIMI DNS record), but VMC-backed logos receive preferential rendering treatment.

Two CAs are currently authorized to issue VMCs for BIMI:

Issuing CAApproximate Annual PriceIssuance TimelineTrademark Offices AcceptedNotes
DigiCert$1,499 / year5–10 business days after trademark verificationUSPTO, EUIPO, UK IPO, CIPO, IP Australia, and othersWidest jurisdiction support; most common choice for US/EU brands
Entrust$1,300 / year (approx.)7–14 business daysUSPTO, EUIPO, CIPO, and select othersSlightly narrower jurisdiction list; competitive pricing

The CA will ask for: your trademark registration certificate, proof that the SVG logo matches the registered mark, and your domain's administrative contact details. The review is manual and cannot be expedited. Start the VMC process early — attempting to push to BIMI display before the certificate is issued results in logo display only on Yahoo/Apple, not Gmail.

The VMC is a .pem file that must also be hosted at a public HTTPS URL, referenced in the BIMI DNS record via the a= parameter.

4. Publishing the BIMI DNS Record

Once your SVG and VMC files are hosted, publish a TXT record at default._bimi.yourdomain.com. The default selector applies to all mail from the domain. You can also publish selector-specific records for subdomain or campaign-level control.

Host / SubdomainRecord TypeValue
default._bimiTXTv=BIMI1; l=https://yourdomain.com/bimi-logo.svg; a=https://yourdomain.com/bimi-vmc.pem;

Without a VMC, omit the a= parameter entirely. Including a broken or inaccessible a= URL will cause Gmail to suppress logo display even on clients that don't require VMC.

5. Inbox Client Rendering Comparison

BIMI rendering varies significantly across mail clients. Not all clients that claim BIMI support actually display logos in all contexts:

Mail ClientVMC Required?Logo Displayed InVerified Checkmark?Notes
Gmail (web)YesInbox list + message headerYes — blue checkmark on hoverRequires DMARC p=reject or p=quarantine pct=100
Gmail (Android/iOS)YesInbox list only (avatar position)No checkmark in mobile UILogo may not appear in all Gmail mobile versions
Yahoo MailNoInbox sender avatarNoEarliest adopter; no VMC requirement
Apple Mail (macOS Ventura+)NoInbox list + message viewNoRespects BIMI DNS record without VMC
FastmailNoMessage headerNoEarly BIMI adopter
Outlook (Microsoft 365)N/ANot supportedN/AMicrosoft uses its own Sender Verification system instead

6. Common BIMI Implementation Failures and How to Diagnose Them

Most BIMI failures are silent — the logo simply doesn't appear. These are the most common root causes, in order of frequency:

  1. DMARC not at full enforcement: The domain is at p=quarantine; pct=50 — BIMI requires pct=100. Check with a DMARC checker and look specifically at the pct tag.
  2. SVG file fails Tiny PS validation: The file loads in browsers but fails BIMI validators. Run the SVG through the BIMI Group's official validator at bimigroup.org. Common culprits: version="1.1" instead of "1.2", a <defs> block containing filter effects, or a gradient fill.
  3. SVG or VMC not HTTPS-accessible: The file returns a redirect (301/302) rather than a direct 200. Use curl -I https://yourdomain.com/bimi-logo.svg to verify the response is a direct 200 OK.
  4. DNS TTL delay: BIMI records can take 24–48 hours to propagate. Gmail's BIMI validation also has its own caching layer — changes may take 3–5 days to reflect in inbox rendering.
  5. VMC a= URL broken: If the a= parameter points to an inaccessible URL, Gmail suppresses the logo entirely — even if the SVG is valid. Temporarily remove the a= parameter to isolate whether the VMC or SVG is the failure point.

7. Validating Your BIMI Setup

Verify your complete BIMI configuration with IncogSay's free BIMI Trust Inspector. The tool validates your DMARC prerequisite enforcement level, fetches and parses your BIMI DNS record, checks HTTPS accessibility and redirect behavior on your SVG and VMC URLs, validates SVG Tiny PS header compliance, and previews how your logo will render in supported inbox clients — all without sending a test email.

For ongoing monitoring, set a calendar reminder to re-check your BIMI configuration after any DNS change, SVG update, or VMC renewal. VMC certificates expire annually — an expired VMC silently removes the Gmail verified checkmark while leaving the Yahoo/Apple logo display intact, which can be confusing to diagnose.