Brand Indicators for Message Identification (BIMI) lets domain owners display their official verified logo beside every delivered message in Gmail, Yahoo Mail, and Apple Mail. Earning the Gmail blue verified checkmark requires a Verified Mark Certificate (VMC) from an authorized CA — which in turn requires DMARC enforcement at p=reject, a registered trademark, and an SVG file built to a spec that most design tools won't produce by default. This guide walks through every step, including the parts the official documentation leaves ambiguous.
1. Prerequisites — What Must Be True Before You Start
BIMI has a strict dependency chain. Skipping any layer causes silent validation failure — the logo simply doesn't appear, with no error surfaced to the sender.
A. DMARC at p=reject or p=quarantine (pct=100)
Your root domain must publish a DMARC policy of p=quarantine with pct=100, or p=reject. A p=none policy is an explicit BIMI disqualifier. Subdomain policies (sp=) do not substitute for root domain enforcement.
The most common reason BIMI implementation fails at this stage: a domain that achieved p=reject for its primary mail stream but still has third-party sending services (CRM platforms, transactional email providers, marketing automation tools) that fail DMARC alignment. Every sending service must either align its SPF Return-Path or sign with DKIM under the root domain before moving to full enforcement.
v=DMARC1; p=reject; rua=mailto:dmarc-reports@yourdomain.com; ruf=mailto:dmarc-forensic@yourdomain.com; pct=100; adkim=s; aspf=sB. SPF and DKIM Alignment — What "100%" Actually Means
BIMI validators check that outbound email passes DMARC — meaning at least one of SPF alignment or DKIM alignment must succeed on every sent message. In practice, DKIM alignment is more reliable for BIMI purposes because SPF alignment breaks when email is forwarded (the forwarding server's IP is not in your SPF record). Use DKIM as the primary alignment mechanism and treat SPF as secondary.
Strict alignment (adkim=s) requires the DKIM d= domain to exactly match the From: header domain. Relaxed alignment (adkim=r) allows subdomain matches. Most enterprise setups work at relaxed alignment — but if you use strict, ensure your email service signs with the exact root domain as the d= value.
C. Registered Trademark — Country and Class Requirements
Your logo must be a registered trademark. A pending trademark application does not qualify. The trademark must be registered in the jurisdiction where your CA operates — for global brands, this means USPTO (United States), EUIPO (European Union), or another WIPO-recognized IP office. The logo submitted to the CA for VMC issuance must visually match the trademark registration.
2. Preparing the BIMI SVG Tiny PS Logo File
Standard SVG files exported from Figma, Illustrator, or Inkscape will not display in mailbox clients. BIMI requires SVG Tiny Portable/Secure (SVG Tiny PS) — a restricted subset of SVG 1.2 that prohibits animations, external references, JavaScript, and embedded rasters.
Technical SVG Tiny PS Requirements
| Requirement | Value / Rule | Common Mistake |
|---|---|---|
| SVG version declaration | version="1.2" baseProfile="tiny-ps" | Exporting at SVG 1.1 (default in most tools) |
| Aspect ratio | 1:1 square viewBox only | Landscape or portrait logos — must be padded to square |
| Color model | Solid fills only; no gradients, no filters | Drop shadows, blurs, or gradient fills from brand guidelines |
| No external references | No <image>, no font links, no <use href> to external files | Google Fonts imported in the SVG, or raster logos embedded as base64 |
| No scripts or animations | No <script>, no <animate>, no SMIL | SVG animations added by export tools |
| Solid background | Full-bleed background color rectangle required | Transparent background — shows as broken in most clients |
| File must be HTTPS-accessible | Served from a public HTTPS URL; no redirects | Hosting on HTTP, or behind a redirect chain |
Minimal Valid SVG Tiny PS Template
<?xml version="1.0" encoding="utf-8"?>
<svg version="1.2" baseProfile="tiny-ps"
xmlns="http://www.w3.org/2000/svg"
viewBox="0 0 512 512"
width="512" height="512">
<title>Your Brand Name</title>
<!-- Solid background — required, no transparency -->
<rect width="512" height="512" fill="#1a56db"/>
<!-- Logo mark as pure vector paths -->
<path d="M256 100 L380 380 L132 380 Z" fill="#ffffff"/>
</svg>3. Verified Mark Certificate (VMC) — CA Comparison
A VMC is required by Gmail to display logos with the verified blue checkmark. Yahoo Mail and Apple Mail display logos without a VMC (using only the BIMI DNS record), but VMC-backed logos receive preferential rendering treatment.
Two CAs are currently authorized to issue VMCs for BIMI:
| Issuing CA | Approximate Annual Price | Issuance Timeline | Trademark Offices Accepted | Notes |
|---|---|---|---|---|
| DigiCert | $1,499 / year | 5–10 business days after trademark verification | USPTO, EUIPO, UK IPO, CIPO, IP Australia, and others | Widest jurisdiction support; most common choice for US/EU brands |
| Entrust | $1,300 / year (approx.) | 7–14 business days | USPTO, EUIPO, CIPO, and select others | Slightly narrower jurisdiction list; competitive pricing |
The CA will ask for: your trademark registration certificate, proof that the SVG logo matches the registered mark, and your domain's administrative contact details. The review is manual and cannot be expedited. Start the VMC process early — attempting to push to BIMI display before the certificate is issued results in logo display only on Yahoo/Apple, not Gmail.
The VMC is a .pem file that must also be hosted at a public HTTPS URL, referenced in the BIMI DNS record via the a= parameter.
4. Publishing the BIMI DNS Record
Once your SVG and VMC files are hosted, publish a TXT record at default._bimi.yourdomain.com. The default selector applies to all mail from the domain. You can also publish selector-specific records for subdomain or campaign-level control.
| Host / Subdomain | Record Type | Value |
|---|---|---|
default._bimi | TXT | v=BIMI1; l=https://yourdomain.com/bimi-logo.svg; a=https://yourdomain.com/bimi-vmc.pem; |
Without a VMC, omit the a= parameter entirely. Including a broken or inaccessible a= URL will cause Gmail to suppress logo display even on clients that don't require VMC.
5. Inbox Client Rendering Comparison
BIMI rendering varies significantly across mail clients. Not all clients that claim BIMI support actually display logos in all contexts:
| Mail Client | VMC Required? | Logo Displayed In | Verified Checkmark? | Notes |
|---|---|---|---|---|
| Gmail (web) | Yes | Inbox list + message header | Yes — blue checkmark on hover | Requires DMARC p=reject or p=quarantine pct=100 |
| Gmail (Android/iOS) | Yes | Inbox list only (avatar position) | No checkmark in mobile UI | Logo may not appear in all Gmail mobile versions |
| Yahoo Mail | No | Inbox sender avatar | No | Earliest adopter; no VMC requirement |
| Apple Mail (macOS Ventura+) | No | Inbox list + message view | No | Respects BIMI DNS record without VMC |
| Fastmail | No | Message header | No | Early BIMI adopter |
| Outlook (Microsoft 365) | N/A | Not supported | N/A | Microsoft uses its own Sender Verification system instead |
6. Common BIMI Implementation Failures and How to Diagnose Them
Most BIMI failures are silent — the logo simply doesn't appear. These are the most common root causes, in order of frequency:
- DMARC not at full enforcement: The domain is at
p=quarantine; pct=50— BIMI requirespct=100. Check with a DMARC checker and look specifically at thepcttag. - SVG file fails Tiny PS validation: The file loads in browsers but fails BIMI validators. Run the SVG through the BIMI Group's official validator at
bimigroup.org. Common culprits:version="1.1"instead of"1.2", a<defs>block containing filter effects, or a gradient fill. - SVG or VMC not HTTPS-accessible: The file returns a redirect (301/302) rather than a direct 200. Use
curl -I https://yourdomain.com/bimi-logo.svgto verify the response is a direct200 OK. - DNS TTL delay: BIMI records can take 24–48 hours to propagate. Gmail's BIMI validation also has its own caching layer — changes may take 3–5 days to reflect in inbox rendering.
- VMC
a=URL broken: If thea=parameter points to an inaccessible URL, Gmail suppresses the logo entirely — even if the SVG is valid. Temporarily remove thea=parameter to isolate whether the VMC or SVG is the failure point.
7. Validating Your BIMI Setup
Verify your complete BIMI configuration with IncogSay's free BIMI Trust Inspector. The tool validates your DMARC prerequisite enforcement level, fetches and parses your BIMI DNS record, checks HTTPS accessibility and redirect behavior on your SVG and VMC URLs, validates SVG Tiny PS header compliance, and previews how your logo will render in supported inbox clients — all without sending a test email.
For ongoing monitoring, set a calendar reminder to re-check your BIMI configuration after any DNS change, SVG update, or VMC renewal. VMC certificates expire annually — an expired VMC silently removes the Gmail verified checkmark while leaving the Yahoo/Apple logo display intact, which can be confusing to diagnose.