DnsGuard › Guides › BIMI

BIMI explained

BIMI (Brand Indicators for Message Identification) lets mailbox providers show your logo next to messages from your domain. It's a reward for strong authentication: it only works once DMARC is enforced.

Requirements

  1. DMARC at enforcement: p=quarantine or p=reject, applying to all mail (no pct below 100), and subdomains not set to sp=none.
  2. Passing SPF or DKIM with alignment on the mail itself.
  3. A logo in SVG Tiny Portable/Secure (SVG Tiny PS) format, square, served over HTTPS. A regular SVG exported from a design tool usually needs converting.
  4. A mark certificate for most big inboxes: a Verified Mark Certificate (VMC), which needs a registered trademark, or a Common Mark Certificate (CMC), which Gmail also accepts for logos that have been in public use. Some providers show logos without a certificate; Gmail and Apple Mail don't.

What a BIMI record looks like

default._bimi.example.com.  TXT  "v=BIMI1; l=https://example.com/bimi/logo.svg; a=https://example.com/bimi/vmc.pem"

default is the selector almost everyone uses.

Common BIMI mistakes

How DnsGuard scores BIMI (10 of 100 points)

7 points for a valid record with an HTTPS logo URL (.svg expected; we warn if the URL doesn't end in .svg) and 3 more for an a= certificate URL. If DMARC isn't enforced, BIMI is capped at 3 points, because receivers will ignore it. DnsGuard checks the record's format only; it doesn't download or validate the logo or certificate.

Check your domain now

Free check of SPF, DKIM, DMARC, BIMI, MX, MTA-STS and TLS-RPT with a 0–100 score and plain-English fixes. No sign-up.

More guides: SPF · DKIM · DMARC · MTA-STS & TLS-RPT