BIMI explained
BIMI (Brand Indicators for Message Identification) lets mailbox providers show your logo next to messages from your domain. It's a reward for strong authentication: it only works once DMARC is enforced.
Requirements
- DMARC at enforcement:
p=quarantineorp=reject, applying to all mail (nopctbelow 100), and subdomains not set tosp=none. - Passing SPF or DKIM with alignment on the mail itself.
- A logo in SVG Tiny Portable/Secure (SVG Tiny PS) format, square, served over HTTPS. A regular SVG exported from a design tool usually needs converting.
- A mark certificate for most big inboxes: a Verified Mark Certificate (VMC), which needs a registered trademark, or a Common Mark Certificate (CMC), which Gmail also accepts for logos that have been in public use. Some providers show logos without a certificate; Gmail and Apple Mail don't.
What a BIMI record looks like
default._bimi.example.com. TXT "v=BIMI1; l=https://example.com/bimi/logo.svg; a=https://example.com/bimi/vmc.pem"
v=BIMI1: version, required.l=: HTTPS URL of the SVG Tiny PS logo.a=: HTTPS URL of the VMC or CMC (a PEM file). Leave it empty if you don't have one.
default is the selector almost everyone uses.
Common BIMI mistakes
- Publishing BIMI while DMARC is still
p=none. The record is ignored. - Serving the logo over
http://, or as a PNG or a regular SVG instead of SVG Tiny PS. - Expecting the logo to show in Gmail without a certificate.
How DnsGuard scores BIMI (10 of 100 points)
7 points for a valid record with an HTTPS logo URL (.svg expected; we warn if the URL doesn't end in .svg) and 3 more for an a= certificate URL. If DMARC isn't enforced, BIMI is capped at 3 points, because receivers will ignore it. DnsGuard checks the record's format only; it doesn't download or validate the logo or certificate.
Check your domain now
Free check of SPF, DKIM, DMARC, BIMI, MX, MTA-STS and TLS-RPT with a 0–100 score and plain-English fixes. No sign-up.
More guides: SPF · DKIM · DMARC · MTA-STS & TLS-RPT