BIMI|Guidelines

BIMI lets mailbox providers show your brand’s logo next to your emails in the inbox, but it’s not an authentication mechanism itself. It’s a reward layered on top of : only a domain that’s already properly locked down with , , and an enforced policy is eligible to use it.

Think of it as a badge, not a lock

BIMI doesn’t secure anything on its own: it’s a visible badge that mailbox providers display once you’ve already proven, via enforcement, that mail from your domain can be trusted.

Why it matters

A recognisable logo next to your emails increases trust and brand recognition in the inbox, but mailbox providers only grant it to domains that have already done the authentication work. That makes BIMI a strong incentive to reach enforcement (a policy of quarantine or reject), on top of the security benefits enforcement already provides. Not every mailbox provider supports BIMI yet (notably, Microsoft doesn’t, as of publication), so treat it as an enhancement for the providers that do, not something every recipient will see.

How it works

Three pieces need to be in place before a mailbox provider will show your logo: a policy enforced at quarantine or reject (applied to both the and its subdomains), a logo prepared as a specific security-restricted SVG profile, and, for most providers, a Verified Mark Certificate () proving you hold the trademark for that logo. All three are then referenced together in a single BIMI .

I need more information

The plain-language version above covers what most people need to know. The rest of this article is the detailed reference: exact record syntax, logo requirements, and the trademark process behind a .

General

  • The domain must be enforced with at p=reject; sp=reject, or a p=quarantine policy applied at 100% to both the and its subdomains; see DMARC | Guidelines if you haven’t reached enforcement yet.
  • The domain needs a good sender reputation and should be recognised as a legitimate bulk sender.
  • BIMI applies to every subdomain of the organisational parent domain it’s implemented on.
  • Not every mailbox provider supports BIMI; Microsoft is a notable exception at the time of writing. Check the BIMI Group’s current list of supporting providers before relying on it.

Configuration

  • The ‘s mail must be aligned with and/or for to pass; see DMARC | Alignment in Depth for what means in practice.
  • A BIMI record starts with v=BIMI1;.
  • The l= tag is required, and holds the HTTPS URI to the logo (SVG).
  • The a= tag holds the HTTPS URI to the Verified Mark Certificate (), and should be included for the mailbox providers that require one.
  • Only SVG and SVGZ formats are accepted for the l= tag, per 6170 section 5.2.
  • BIMI supports multiple record preferences via ; the default is default.
  • Example record: v=BIMI1; l=https://example.com/logo.svg; a=https://example.com/vmc.pem

The logo (SVG)

The logo must be square, saved in SVG format, and follow the SVG Tiny Portable/Secure (SVG-TPS) profile the BIMI Working Group defined, a deliberately restricted subset of SVG. It cannot contain <script> tags or reference any external resources, and typically needs some manual cleanup to meet the size and security requirements. Some mailbox providers additionally expect the logo to be your legally registered logotype specifically, not a secondary word mark or an unregistered variant.

The trademark (VMC)

Getting a Verified Mark Certificate requires an existing, current trademark registration for the exact image you want to display, at one of a defined list of recognised trademark offices (including the EUIPO, USPTO, UK IPO, and Benelux Office for Intellectual Property, among others). If your organisation doesn’t already hold that trademark, this is a legal process to start with your IP counsel well before you plan to launch BIMI, not a technical one.

Security

  • Only two Certificate Authorities currently issue VMCs: DigiCert and Entrust. Use only trusted, supported authorities.
  • The logo and certificate must not reference any external data; mailbox providers will BIMI records that do.
  • If the certificate references privacy-sensitive information, apply appropriate security controls to protect it.

References & further reading