Skip to content

BIMI

Definition

BIMI is a way to have your logo shown beside your messages in a supporting mail client. You publish a record in DNS pointing at a logo file in a particular SVG profile, and the client displays it only for mail that already passes DMARC at an enforcing policy. Several providers also require a certificate attesting that the mark is yours.

At a glance

Category
Brand and authentication
Published at
A TXT record at default._bimi.<domain>
Logo format
SVG Tiny Portable/Secure, square, on a solid background
Requires
DMARC at quarantine or reject, enforced
Often requires
A Verified Mark Certificate, referenced by the record
Specified by
The BIMI Group

How it works

You publish a TXT record at a BIMI selector under your domain, normally the default one. The record names the URL of your logo and, when a certificate is used, the URL of that certificate. A supporting mail client checks that the message passed DMARC with a policy of quarantine or reject, fetches the record, fetches the logo, validates the certificate if it demands one, and then draws the mark next to the sender's name. Nothing is shown when any of those checks fails, and nothing is retried on the reader's behalf.

Why it matters

The practical value of BIMI is not the logo, it is what you have to do to earn it. A domain cannot qualify without DMARC at enforcement, which means every legitimate sender on that domain has already been found and authenticated. Teams that treat the logo as the goal often complete an authentication project they had been deferring for years. The visual result is real but modest: it is recognition in a crowded list, not deliverability, and no provider treats it as a ranking signal.

Example

A domain publishes a TXT record at default._bimi.example.com whose value is v=BIMI1; l=https://example.com/logo.svg; a=https://example.com/mark.pem. The logo is a square SVG in the restricted profile, with no scripts, no external references and a solid background. The domain's DMARC record already says p=reject. A reader on a supporting client sees the mark in the message list; a reader on a client that does not implement BIMI sees exactly what they saw before, and nothing breaks.

Common mistakes

  1. 01Publishing a BIMI record while DMARC is still at p=none, which disqualifies the domain no matter how correct the logo is.
  2. 02Serving an ordinary SVG rather than the restricted profile the specification requires, so the mark is fetched and then rejected.
  3. 03Assuming the logo will appear everywhere: support differs by provider, and several require a certificate before they will draw anything.

Frequently asked questions

Do I need a certificate for BIMI?

It depends on the mailbox provider. Some display a mark from the record alone, while others require a Verified Mark Certificate from an approved authority and will show nothing without one.

Will BIMI improve my deliverability?

Not directly. The DMARC enforcement it requires may well improve it, because enforcement means your authentication is complete, but the mark itself is a display feature rather than a reputation signal.

Which logo file works?

A square SVG in the Tiny Portable/Secure profile, with a solid background and no external references or scripting. An ordinary export from a design tool will usually be rejected until it is converted to that profile.

Sources

Last updated 16 September 2026.

Start sending this morning

Verify a domain and send your first email in minutes.