Get your logo into mail clients with BIMI

Fränz Friederes
Engineer & Founder
BIMI allows you to show your logo beside a verified email in supported mail clients, sometimes accompanied by a blue checkmark next to the name. The receiving provider checks that the logo belongs to the sender, using DMARC and, where it requires one, a certificate. The mail client then decides how to show it.
BIMI doesn’t add an authentication check of its own, but it makes successful verification through DMARC more visible to users by adding a trusted mark.
Who supports BIMI
Not every receiving provider or mail client supports BIMI. The receiving provider checks DMARC and the BIMI record when the message arrives. The mail client decides whether to draw the logo, and how.
Receiving providers supporting BIMI
| Receiving provider | No certificate | CMC | VMC |
|---|---|---|---|
| Google Mail / Gmail | No | Yes | Yes, |
| Yahoo Mail and AOL* | Yes | Yes | Yes |
| iCloud Mail | No | No | Yes |
| Microsoft 365 and Outlook.com | No | No | No |
(*): Yahoo Mail shows the logo when the BIMI record points at a valid SVG, DMARC is enforced, the message is bulk mail, and Yahoo already sees enough reputation and engagement for that sender. They do not require a certificate. See Yahoo's sender rules.
Mail clients supporting BIMI
| Mail client | Shows the logo |
|---|---|
| Gmail (web and mobile app) | Yes |
| Apple Mail* | Yes |
| Outlook | No |
| Thunderbird | No |
(*): Apple Mail draws the logo when a provider Apple trusts has added the BIMI headers to the message.
How to get your logo into mail clients
- Complete the DMARC journey
Set BIMI up once legitimate mail is authenticating and you are comfortable enforcing DMARC. If you are still at
p=none, stay there. Read your DMARC reports, get each sending provider passing DKIM and, if possible, SPF as well, with alignment, and only then move top=quarantineorp=reject. Find out more on how DMARC works. By enabling strict enforcement too fast, you risk losing legitimate mail.In case the domain you send from is a subdomain (e.g.
crm.example.com), you also need to set up DMARC for the domain above it (e.g.example.com) withp=quarantineorp=rejectenforcement to become eligible for BIMI.Make sure your DMARC policy covers every message (omitting any
pct=tag) and test mode is disabled (omittingt=y). If you use a subdomain policy (sp=tag), make sure it's set to eithersp=quarantineorsp=rejectas well, or omit it to fall back to the policy set in thep=tag.You can validate your DMARC record including these tags using the DMARC check tool.
- Prepare the logo file
Use the logo you want in the sender avatar, as a square image on a solid background, centered in the frame. Mail clients may crop it to a circle or a rounded square, and a transparent background often comes out as a surprise color.
The file has to be SVG Tiny PS, the strict profile BIMI uses. A normal SVG export from a design tool is not that file. The root element needs
baseProfile="tiny-ps"andversion="1.2", a<title>with your organization name, and no scripts, animation, outside images, orxandyattributes on the root. Keep it under 32 KB. The BIMI Group’s logo guide has the profile and a reference file. Expect to export SVG Tiny 1.2 and then edit the file, or to run it through a BIMI converter and check the result against that guide.Later, this file has to be made available via a public HTTPS web address.
- Get a certificate for that logo
The certificate proves you are allowed to use that image. Buy it from a mark verifying authority on the BIMI Group’s issuer list. These are paid certificates, and you need to renew them. The logo inside the certificate has to be the same SVG you publish. Changing the artwork later requires a new certificate.
There are two types of certificates:
- Get a Verified Mark Certificate (VMC) when you want the logo in the most places. That is the certificate behind Gmail’s checkmark and the one Apple Mail is set up for. It requires a registered figurative trademark of the logo you chose in the previous step with a trademark office the certificate issuer recognizes. It does not have to cover every country you send mail to.
- Get a Common Mark Certificate (CMC) when the logo is not registered, or when you need a small variation of a logo that is. The issuer checks that you have already been using that logo in public. Plan on about a year of use. Gmail can show that logo, without the checkmark, whereas iCloud does not accept a CMC, so Apple Mail will not show that logo.
- Publish the BIMI record
Add a TXT record where you already manage the domain’s DNS. Example BIMI record:
Textdefault._bimi.example.com. IN TXT "v=BIMI1; l=https://example.com/brand/logo.svg; a=https://example.com/brand/logo-certificate.pem"Here,
defaultis the BIMI selector, in case there are multiple BIMI identities. Setting up the record under the domain you registered (example.comin this example) makes the identity available to subdomains as well.v=BIMI1marks the record as BIMI.l=is the SVG from the step above.a=is the certificate file, served over HTTPS as a `.pem`. Upload the file your issuer gives you, with the intermediate and root certificates appended in the order they specify. The image atl=and the image inside the certificate have to match. The receiving provider compares the SVG atl=with the logo inside the certificate.