BIMI|Guidelines
BIMI lets mailbox providers show your brand’s logo next to your emails in the inbox, but it’s not an authentication mechanism itself. It’s a reward layered on top of DMARC: only a domain that’s already properly locked down with SPF, DKIM, and an enforced DMARC policy is eligible to use it.
Think of it as a badge, not a lock
BIMI doesn’t secure anything on its own: it’s a visible badge that mailbox providers display once you’ve already proven, via DMARC enforcement, that mail from your domain can be trusted.
Why it matters
A recognisable logo next to your emails increases trust and brand recognition in the inbox, but mailbox providers only grant it to domains that have already done the authentication work. That makes BIMI a strong incentive to reach DMARC enforcement (a policy of quarantine or reject), on top of the security benefits enforcement already provides. Not every mailbox provider supports BIMI yet (notably, Microsoft doesn’t, as of publication), so treat it as an enhancement for the providers that do, not something every recipient will see.
How it works
Three pieces need to be in place before a mailbox provider will show your logo: a DMARC policy enforced at quarantine or reject (applied to both the organisational domain and its subdomains), a logo prepared as a specific security-restricted SVG profile, and, for most providers, a Verified Mark Certificate (VMC) proving you hold the trademark for that logo. All three are then referenced together in a single BIMI DNS TXT record.
I need more information
The plain-language version above covers what most people need to know. The rest of this article is the detailed reference: exact record syntax, logo requirements, and the trademark process behind a VMC.
General
- The domain must be enforced with DMARC at
p=reject; sp=reject, or ap=quarantinepolicy applied at 100% to both the organisational domain and its subdomains; see DMARC | Guidelines if you haven’t reached enforcement yet. - The domain needs a good sender reputation and should be recognised as a legitimate bulk sender.
- BIMI applies to every subdomain of the organisational parent domain it’s implemented on.
- Not every mailbox provider supports BIMI; Microsoft is a notable exception at the time of writing. Check the BIMI Group’s current list of supporting providers before relying on it.
Configuration
- The organisational domain‘s mail must be aligned with SPF and/or DKIM for DMARC to pass; see DMARC | Alignment in Depth for what alignment means in practice.
- A BIMI record starts with
v=BIMI1;. - The
l=tag is required, and holds the HTTPS URI to the logo (SVG). - The
a=tag holds the HTTPS URI to the Verified Mark Certificate (VMC), and should be included for the mailbox providers that require one. - Only SVG and SVGZ formats are accepted for the
l=tag, per RFC 6170 section 5.2. - BIMI supports multiple record preferences via selectors; the default selector is
default. - Example record:
v=BIMI1; l=https://example.com/logo.svg; a=https://example.com/vmc.pem
The logo (SVG)
The logo must be square, saved in SVG format, and follow the SVG Tiny Portable/Secure (SVG-TPS) profile the BIMI Working Group defined, a deliberately restricted subset of SVG. It cannot contain <script> tags or reference any external resources, and typically needs some manual cleanup to meet the size and security requirements. Some mailbox providers additionally expect the logo to be your legally registered logotype specifically, not a secondary word mark or an unregistered variant.
The trademark (VMC)
Getting a Verified Mark Certificate requires an existing, current trademark registration for the exact image you want to display, at one of a defined list of recognised trademark offices (including the EUIPO, USPTO, UK IPO, and Benelux Office for Intellectual Property, among others). If your organisation doesn’t already hold that trademark, this is a legal process to start with your IP counsel well before you plan to launch BIMI, not a technical one.
Security
- Only two Certificate Authorities currently issue VMCs: DigiCert and Entrust. Use only trusted, supported authorities.
- The logo and certificate must not reference any external data; mailbox providers will reject BIMI records that do.
- If the certificate references privacy-sensitive information, apply appropriate security controls to protect it.
References & further reading
- RFC 6170 – SVG Tiny Portable/Secure: datatracker.ietf.org/doc/html/rfc6170
- RFC 3709 – Internet X.509 Public Key Infrastructure: Logotypes: datatracker.ietf.org/doc/html/rfc3709
- RFC 5280 – Internet X.509 Public Key Infrastructure Certificate and CRL Profile: datatracker.ietf.org/doc/html/rfc5280
- BIMI Group – current mailbox provider support and specifications: bimigroup.org