BIMI and Verified Mark Certificates

4 min read
BIMI and Verified Mark Certificates

BIMI, short for Brand Indicators for Message Identification, lets a domain owner specify a logo that mailbox providers can display beside authenticated email. It is the visible reward for doing authentication properly. A domain must have DMARC at enforcement before BIMI will work, which gives organizations a concrete reason to finish their DMARC rollout.

What BIMI Does and Does Not Do

BIMI displays your logo in the sender avatar position in supporting inboxes. In Gmail, a logo backed by a Verified Mark Certificate also carries a blue verified checkmark.

BIMI does not improve inbox placement directly. Mailbox providers do not treat it as a ranking signal. Its benefits are brand recognition, a visual cue that helps recipients trust the message, and the stronger authentication it requires.

Requirements

Three things must be in place.

DMARC at Enforcement

Your organizational domain must publish a DMARC policy of p=quarantine or p=reject, applied to all mail. A policy of p=none does not qualify, and neither does a partial rollout or testing mode.

A Logo in the Right Format

The logo must be an SVG file in a restricted profile called SVG Tiny PS. It must be square, hosted at a public HTTPS address, and free of scripts, external references and embedded bitmap images. Standard SVG exports from design tools usually need converting.

A Mark Certificate

Most providers that show BIMI logos require a certificate proving you have the right to use the logo. There are two kinds.

VMC vs CMC

A Verified Mark Certificate, or VMC, requires the logo to be a registered trademark with a recognized intellectual property office. The certificate authority checks the registration and the identity of your organization. In Gmail, a VMC produces both the logo and the blue checkmark.

A Common Mark Certificate, or CMC, does not require a registered trademark. It is available for logos that can be shown to have been in public use for at least a year. In Gmail, a CMC displays the logo without the checkmark.

Both are issued by a small number of certificate authorities and renewed annually. A VMC typically costs more than a thousand US dollars a year. A CMC costs somewhat less.

Which Providers Support BIMI

Support varies, and it changes over time.

  • Gmail and Google Workspace display BIMI logos and require a VMC or CMC.
  • Apple Mail supports BIMI on recent versions of iOS, iPadOS and macOS and requires a mark certificate.
  • Yahoo Mail and AOL display logos without requiring a certificate, for bulk senders with a good reputation.
  • Fastmail supports BIMI.
  • Microsoft Outlook and Outlook.com do not render standard BIMI logos for inbound mail.

Check current provider documentation before committing to the cost of a certificate, especially if most of your audience uses Microsoft mailboxes.

The BIMI Record

BIMI is published as a DNS TXT record at the default._bimi label of your domain:

default._bimi.example.com TXT "v=BIMI1; l=https://example.com/logo.svg; a=https://example.com/certificate.pem"

  • l= is the HTTPS location of the SVG logo.
  • a= is the HTTPS location of the mark certificate.

The word default is a selector. Most domains only need the default one.

Implementation Steps

  1. Reach DMARC enforcement on the organizational domain.
  2. Confirm that every legitimate mail stream passes DMARC.
  3. Prepare the logo as a square SVG Tiny PS file.
  4. Check whether the logo is a registered trademark, to decide between a VMC and a CMC.
  5. Apply for the certificate. Validation can take several weeks.
  6. Host the logo and certificate at HTTPS addresses.
  7. Publish the BIMI record.
  8. Test with a BIMI checker and send test messages to supporting providers.

Common Problems

  • The logo does not appear. Display is at the provider's discretion and depends on sender reputation as well as the record. A correct setup on a low-reputation domain may still show no logo.
  • The SVG is rejected. The file is usually standard SVG and not the Tiny PS profile.
  • The DMARC policy does not qualify. Check for a subdomain policy of sp=none, which disqualifies the domain.
  • The logo does not match the certificate. The hosted SVG must be the same image embedded in the certificate.
  • The certificate has expired. Certificates need renewing each year.

Is BIMI Worth It?

For consumer brands sending significant volume to Gmail, Yahoo and Apple Mail users, BIMI is a worthwhile finishing step once DMARC is enforced. For small senders, or businesses whose recipients are mostly on Microsoft 365, the certificate cost is harder to justify. In either case, the DMARC work that BIMI demands is valuable on its own.

Need help implementing this?

Our team specializes in building scalable, high-deliverability email systems. Let us help you land in the inbox.

Talk to an Expert