# Get your logo into mail clients with BIMI

BIMI allows you to show your logo beside a verified email in supported mail clients, sometimes accompanied by a blue checkmark next to the name. The receiving provider checks that the logo belongs to the sender, using DMARC and, where it requires one, a certificate. The mail client then decides how to show it.

BIMI doesn’t add an authentication check of its own, but it makes successful verification through DMARC more visible to users by adding a trusted mark.

## Who supports BIMI

Not every receiving provider or mail client supports BIMI. The receiving provider checks DMARC and the BIMI record when the message arrives. The mail client decides whether to draw the logo, and how.

### Receiving providers supporting BIMI

| Receiving provider | No certificate | CMC | VMC |
| --- | --- | --- | --- |
| **Google Mail / Gmail** | No | Yes | Yes, |
| **Yahoo Mail and AOL\*** | Yes | Yes | Yes |
| **iCloud Mail** | No | No | Yes |
| **Microsoft 365 and Outlook.com** | No | No | No |

(\*): Yahoo Mail shows the logo when the BIMI record points at a valid SVG, DMARC is enforced, the message is bulk mail, and Yahoo already sees enough reputation and engagement for that sender. They do not require a certificate. See [Yahoo's sender rules](https://senders.yahooinc.com/bimi/).

### Mail clients supporting BIMI

| Mail client | Shows the logo |
| --- | --- |
| **Gmail (web and mobile app)** | Yes |
| **Apple Mail\*** | Yes |
| **Outlook** | No |
| **Thunderbird** | No |

(\*): Apple Mail draws the logo when a provider Apple trusts has added the BIMI headers to the message.

## How to get your logo into mail clients

1. **Complete the DMARC journey**

   Set BIMI up once legitimate mail is authenticating and you are comfortable enforcing DMARC. If you are still at `p=none`, stay there. Read your DMARC reports, get each sending provider passing DKIM and, if possible, SPF as well, with alignment, and only then move to `p=quarantine` or `p=reject`. Find out more on [how DMARC works](https://dmarced.eu/en/learn/email-security/dmarc/overview). By enabling strict enforcement too fast, you risk losing legitimate mail.

   In case the domain you send from is a subdomain (e.g. `crm.example.com`), you also need to set up DMARC for the domain above it (e.g. `example.com`) with `p=quarantine` or `p=reject` enforcement to become eligible for BIMI.

   Make sure your DMARC policy covers every message (omitting any `pct=` tag) and test mode is disabled (omitting `t=y`). If you use a subdomain policy (`sp=` tag), make sure it's set to either `sp=quarantine` or `sp=reject` as well, or omit it to fall back to the policy set in the `p=` tag.

   You can validate your DMARC record including these tags using the [DMARC check tool](https://dmarced.eu/en/tools/dmarc-check).

2. **Prepare the logo file**

   Use the logo you want in the sender avatar, as a square image on a solid background, centered in the frame. Mail clients may crop it to a circle or a rounded square, and a transparent background often comes out as a surprise color.

   The file has to be SVG Tiny PS, the strict profile BIMI uses. A normal SVG export from a design tool is not that file. The root element needs `baseProfile="tiny-ps"` and `version="1.2"`, a `<title>` with your organization name, and no scripts, animation, outside images, or `x` and `y` attributes on the root. Keep it under 32 KB. The [BIMI Group’s logo guide](https://bimigroup.org/creating-bimi-svg-logo-files/) has the profile and a reference file. Expect to export SVG Tiny 1.2 and then edit the file, or to run it through a BIMI converter and check the result against that guide.

   Later, this file has to be made available via a public HTTPS web address.

3. **Get a certificate for that logo**

   The certificate proves you are allowed to use that image. Buy it from a mark verifying authority on the [BIMI Group’s issuer list](https://bimigroup.org/vmc-issuers/). These are paid certificates, and you need to renew them. The logo inside the certificate has to be the same SVG you publish. Changing the artwork later requires a new certificate.

   There are two types of certificates:

   - Get a **Verified Mark Certificate (VMC)** when you want the logo in the most places. That is the certificate behind Gmail’s checkmark and the one Apple Mail is set up for. It requires a **registered figurative trademark** of the logo you chose in the previous step with a trademark office the certificate issuer recognizes. It does not have to cover every country you send mail to.
   - Get a **Common Mark Certificate (CMC)** when the logo is not registered, or when you need a small variation of a logo that is. The issuer checks that you have already been using that logo in public. Plan on about a year of use. Gmail can show that logo, without the checkmark, whereas iCloud does not accept a CMC, so Apple Mail will not show that logo.

4. **Publish the BIMI record**

   Add a TXT record where you already manage the domain’s DNS. Example BIMI record:

   Block Field

   Here, `default` is the BIMI selector, in case there are multiple BIMI identities. Setting up the record under the domain you registered (`example.com` in this example) makes the identity available to subdomains as well.

   `v=BIMI1` marks the record as BIMI. `l=` is the SVG from the step above. `a=` is the certificate file, served over HTTPS as a \`.pem\`. Upload the file your issuer gives you, with the intermediate and root certificates appended in the order they specify. The image at `l=` and the image inside the certificate have to match. The receiving provider compares the SVG at `l=` with the logo inside the certificate.

## See also

- [BIMI Group implementation guide](https://bimigroup.org/implementation-guide/)