Implementing BIMI for Brand Recognition: A Production Guide

· Published · 15 min read

An authenticated email identity passing through alignment checks to a BIMI logo and mark certificate, with mailbox surfaces making independent display decisions

BIMI can let a supporting mailbox provider show your brand logo beside authenticated email. This guide gives you the current implementation path and puts each DNS record, certificate decision, and verification command beside a practical example.

BIMI is a display signal, not email authentication. SPF, DKIM, and DMARC must already work, and the receiving provider still decides whether to show the logo. A valid BIMI record therefore does not guarantee a logo, a verification checkmark, inbox placement, or protection from every phishing message.

Start here: the complete BIMI implementation path

StepWhat you doResult before continuing
1List every visible From domain and sending platform.A test message from each stream passes aligned SPF or DKIM and DMARC.
2Enforce DMARC with p=quarantine or p=reject, an appropriate sp and np policy, and production mode t=n.Legitimate mail continues to pass after enforcement.
3Choose self-asserted BIMI, a Common Mark Certificate (CMC), or a Verified Mark Certificate (VMC) from the requirements of the mailbox providers your recipients use.You know the certificate type, exact logo, domains, issuer, evidence, and budget.
4Prepare and validate the logo as SVG Tiny Portable/Secure, also called SVG Tiny-PS.The final square SVG passes validation and still looks clear at small size.
5Apply to a current Mark Verifying Authority if a VMC or CMC is required.The issued PEM contains the expected logo, domains, certificate, and chain.
6Host the SVG and PEM on stable public HTTPS URLs.External requests return the real files without login, bot challenge, or redirect loop.
7Publish one BIMI TXT record at default._bimi.example.com.Authoritative and public DNS resolvers return the intended value.
8Send real tests and check authentication, assets, certificate, and provider display.Evidence is recorded for each important provider and application.

Do not buy a certificate before confirming the exact logo and domain coverage. Do not enforce DMARC before all legitimate senders are aligned. Those two ordering mistakes cause most avoidable rework.

Step 1: put DMARC at enforcement without creating an outage

Complete these three prerequisites before publishing a BIMI record.

IdRequirementWhat to doExpected result
1Enforce DMARC safelyInventory every legitimate sender, prove aligned SPF or DKIM, review reports, then publish an enforcing p, sp, and np policy with t=n.Representative messages from every approved platform return dmarc=pass after enforcement.
2Choose the certificate pathUse target mailbox-provider requirements to choose self-asserted BIMI, a CMC, or a VMC before paying an issuer.The certificate type, exact logo, domains, issuer, evidence, price, and expected provider treatment are confirmed.
3Prepare a compliant logoUse a square SVG Tiny-PS file with baseProfile="tiny-ps", version="1.2", a meaningful <title>, and preferably <desc>.The final exported SVG passes validation and remains clear at small size.

DMARC example and what each part means

RFC 9989, published in May 2026, is the current DMARC standard. This production example follows the current tag set:

_dmarc.example.com. 3600 IN TXT "v=DMARC1; p=reject; sp=reject; np=reject; t=n; adkim=s; aspf=s; fo=0; rua=mailto:[email protected]; ruf=mailto:[email protected]"
  • v=DMARC1 identifies the record.
  • p=reject requests rejection for mail using the main domain that fails DMARC. Use it only after legitimate sources are aligned.
  • sp=reject applies the reject policy to existing subdomains that do not publish their own applicable policy.
  • np=reject applies to non-existent subdomains, such as a fabricated login-alert.example.com that returns NXDOMAIN.
  • t=n requests that the stated policy be applied. It is the RFC 9989 default, but including it makes production intent clear. t=y is test mode and asks for treatment one policy level below the stated policy.
  • adkim=s and aspf=s require exact-domain alignment. They are valid but optional. Relaxed alignment is the default and is often easier with ESP subdomains.
  • fo=0 requests a failure report when all underlying mechanisms fail to produce an aligned pass. It matters only with ruf, and receivers may not send failure reports.
  • rua requests aggregate reports. ruf requests privacy-sensitive message-level failure reports. Use monitored mailboxes and authorize cross-domain reporting destinations.

Before changing DMARC, send a message from every ESP, application, help desk, billing platform, and custom MTA. In the received headers, confirm that dmarc=pass and that the visible From domain aligns with the DKIM signing domain or SPF Mail From domain. The SPF, DKIM, and DMARC guide explains that preparation.

The BIMI standard permits a self-asserted SVG without a certificate, but support is limited. Gmail requires a VMC or CMC and does not use the standalone SVG route. Choose from your actual recipient-provider mix.

IdFeatureVMCCMC
1PurposeCertificate for a qualifying registered mark. It can support certificate-required providers and Gmail's verified checkmark when all other Gmail conditions are met.Certificate for a common mark that does not use the VMC trademark route. Gmail can show its logo without the VMC checkmark.
2BIMI requirementNot mandatory in the base BIMI standard, but required for the VMC-specific treatment and accepted by providers that require a certificate.Not mandatory in the base standard. It is an additional certificate path accepted by providers such as Gmail.
3Trademark requirementThe issuer validates an eligible registered mark under current Mark Certificate rules.A registered trademark is not the defining requirement. The issuer verifies organization, domain, logo, rights, and required evidence, which can include a period of prior use.
4Supported providersCheck the current BIMI Group provider page and each target provider because display and certificate acceptance can change.Gmail publicly supports CMC. Confirm every other target provider before buying because CMC support is not uniform.
5Issuing authoritiesUse a Mark Verifying Authority on the current BIMI Group issuer list. Issuer listing does not guarantee acceptance by every mailbox provider.
6CostPrice depends on issuer, domain coverage, validation, support, and certificate product.Request a written quote for the exact CMC scope. Do not budget from an unrelated certificate or an internet estimate.
7Verification processValidation of the applicant, domain control, organization, registered mark, logo, and certificate data.Validation of the applicant, domain control, organization, logo rights and use, and certificate data. It is not an unverified or free certificate.

In simple terms, choose a VMC when the exact logo has a qualifying registered trademark and the verified treatment matters. Ask about a CMC when the logo is not eligible for that VMC route or is an allowed variation. Consider self-asserted BIMI only when the providers important to you explicitly support it.

Choose a BIMI Certificate Provider (once your logo is ready)

Provider choice affects logo eligibility, domain coverage, documents, PEM construction, renewal, price, and mailbox acceptance. Start with the current BIMI Group Mark Verifying Authority list, then ask the mailbox providers important to your audience whether they accept that issuer and certificate type.

IdCurrent authorityListingWhat to confirm before buying
1DigiCertListed by the BIMI Group as a Mark Verifying Authority.VMC or CMC availability, exact domain and mark scope, provider acceptance, validation steps, reissue terms, renewal, and total current cost.
2GlobalSignListed by the BIMI Group as a Mark Verifying Authority.VMC or CMC availability, exact domain and mark scope, provider acceptance, validation steps, reissue terms, renewal, and total current cost.
3SSL.comListed by the BIMI Group as a Mark Verifying Authority.VMC or CMC availability, exact domain and mark scope, provider acceptance, validation steps, reissue terms, renewal, and total current cost.

Ask each candidate provider the same questions: Is this logo eligible for VMC or CMC? Which domains and subdomains will the certificate cover? Can one certificate cover this exact domain and logo plan? Which trademark office or use evidence is accepted? Which mailbox providers accept the certificate today? What will issuance, reissuance, and renewal cost? What happens if the logo changes?

Free checkers such as the BIMI Group tools, Valimail's BIMI tools, and EasyDMARC's BIMI lookup can help find DNS or asset errors. They do not approve a trademark, issue a certificate, or guarantee that a mailbox provider will display the logo.

Apply for a BIMI Certificate: but where?

Apply directly to one of the current Mark Verifying Authorities after the issuer confirms that your exact logo and domains are eligible. A trademark office registers a mark. It does not issue the BIMI certificate. The issuer validates your organization, domain control, mark or common-mark evidence, and logo, then issues the VMC or CMC.

  1. Choose the exact final logo. Do not apply with one version and publish another.
  2. Use the WIPO Global Brand Database and the relevant national or regional office to find the registration and owner details.
  3. Send the logo, domain list, registration or use evidence, and organization details to the candidate certificate provider for eligibility review.
  4. Receive a written scope and quote. Confirm certificate type, domains, logo, provider acceptance, validity, reissue terms, and renewal process.
  5. Complete the issuer's organization, contact, domain-control, and mark validation.
  6. Inspect the issued PEM before publishing it. Check the subject, issuer, dates, covered identity, logo, and complete certificate chain.

Documents to prepare

Document groupExamplesHow to prepare them
Applicant and businessBusiness name, applicant name and address, registration document, nationality or legal status, and authorized contact.Make the legal entity consistent with the mark owner or documented licensee, domain control, and certificate application.
Mark and logoTrademark application or registration, exact logo image, mark class and description, Nice classification, and goods or services.Use the exact mark representation the issuer approves. A visually similar logo may not be equivalent.
Rights and useProof of use, declaration of use, consent, license, or power of attorney.CMC and licensed-mark evidence varies by issuer. Ask for the exact evidence window and accepted documents.
Fees and priorityApplication receipt, extra class or service fees, priority claim, foreign registration, and translations.Trademark-office and legal fees are separate from the certificate price. Requirements and timelines vary by jurisdiction and case.

Trademark-registration time depends on the office, objections, classes, evidence, disputes, and legal process. Use the office's current status information and qualified trademark advice for a business deadline.

Authorized trademark offices for a VMC

The authorized-office appendix in the current VMC requirements lists these eight offices. Confirm the registration, mark type, ownership, and current issuer rules before applying.

IdCountry or regionAuthorized trademark office
1United StatesUnited States Patent and Trademark Office (USPTO)
2CanadaCanadian Intellectual Property Office (CIPO)
3European UnionEuropean Union Intellectual Property Office (EUIPO)
4United KingdomUK Intellectual Property Office
5GermanyGerman Patent and Trade Mark Office (DPMA)
6JapanJapan Patent Office (JPO)
7SpainSpanish Patent and Trademark Office (OEPM)
8AustraliaIP Australia
CheckWhat the file needsBeginner example
ProfilebaseProfile="tiny-ps" and version="1.2".These attributes tell a BIMI parser which restricted SVG profile is intended.
IdentityA meaningful <title>; add <desc> for accessibility and compatibility.<title>Example Company logo</title>
ShapeA square viewBox with safe space around the mark.viewBox="0 0 96 96"
ContentVector paths and supported shapes, without script, animation, links, or externally loaded resources.Convert fonts to paths so the receiver does not need your font file.
DisplayA clear design at about 20 to 40 pixels and through circular or rounded crops.A compact symbol normally works better than a long wordmark.
CompatibilityKeep the uncompressed SVG at or below 32 KB. Google documents at least 96 by 96 absolute pixel dimensions.Validate the final exported file, not only the designer's source file.

A minimal structure looks like this. Replace the sample rectangle with the approved vector paths; this snippet alone is not your registered or verified mark.

<svg xmlns="http://www.w3.org/2000/svg"
     version="1.2" baseProfile="tiny-ps"
     width="96px" height="96px" viewBox="0 0 96 96">
  <title>Example Company logo</title>
  <desc>White Example symbol on a blue square</desc>
  <rect width="96" height="96" fill="#123a63"/>
  <!-- Replace with the approved vector logo paths. -->
</svg>

Can BIMI Work Without a Website?

Yes. You do not need a public marketing website, but BIMI still needs DNS and publicly reachable assets. Use a stable HTTPS asset host or object-storage/CDN endpoint under organizational control. A temporary file-sharing URL, private bucket, signed URL that expires, login page, or bot challenge will fail.

RequirementExpected resultExample
Public HTTPSAnonymous external fetch returns 200 with valid TLS 1.2 or later.https://assets.example.com/bimi/logo.svg
Correct contentThe SVG URL returns SVG, not an HTML error page. The PEM URL returns the intended certificate chain.SVG commonly uses image/svg+xml.
Stable addressThe URL does not expire or change during a website deployment.Use a version-controlled asset path and monitor its hash.
Provider ruleThe host and URL meet the target provider and certificate issuer requirements.Google's standalone SVG guidance requires a public web server in the same domain, while Gmail itself requires a VMC or CMC path. Follow the current provider instructions.

A third-party host can be technically reachable, but provider, issuer, domain-control, and operational rules can differ. Confirm the final host before certificate issuance and test from outside your office network.

Step 4: plan domains, subdomains, and multiple logos

Certificate Subject Alternative Names, verified domains, mark identity, selectors, issuer products, and mailbox-provider support determine how many certificates you need. Confirm the complete domain-and-logo plan with the issuer before purchasing.

IdDomain structureNumber of logosCurrent planning rule
1Single domainOneOften one certificate, but confirm that the domain and exact mark are included.
2Single domainMultipleEach distinct verified mark may require separate certificate evidence and a supported selector plan. Confirm with issuer and providers.
3Multiple domainsOneOne certificate may cover multiple validated domains if the issuer product and certificate scope permit it. Do not assume.
4Multiple subdomainsOneAn organizational-domain BIMI assertion can be inherited by subdomains without their own assertion, but DMARC alignment, certificate scope, and provider rules still apply.
5Multiple domainsMultipleMap each From domain to its logo, selector, certificate evidence, owner, and target providers before requesting a quote.
6Multiple subdomainsMultiplePublish deliberate subdomain assertions or supported selectors and confirm every domain-logo combination with the issuer.

Example: if billing.example.com and news.example.com use the same logo, the organizational-domain default assertion might be inherited. If support.example.com needs a different logo, publish a deliberate assertion for that subdomain or use a supported selector design. Each stream must still pass DMARC using its visible From domain. Additional selectors also require sender and provider support, not just an extra TXT record.

Step 5: publish the BIMI DNS record

For mail sent from [email protected], publish the default selector as a TXT record at default._bimi.example.com:

default._bimi.example.com. 3600 IN TXT "v=BIMI1; l=https://assets.example.com/bimi/logo.svg; a=https://assets.example.com/bimi/mark.pem"
PartWhat it doesWhat you replace
defaultThe normal BIMI selector.Keep default unless you deliberately implemented and tested another selector.
_bimiPlaces the TXT record in the BIMI DNS namespace.Do not publish the record at the bare domain.
v=BIMI1Identifies the BIMI version and must appear first.Nothing.
l=Points to the separate SVG logo.Use the exact public HTTPS SVG URL. Google also documents a certificate form with an empty l= because the logo is embedded in the PEM.
a=Points to the VMC or CMC evidence document.Use the exact public HTTPS PEM URL supplied and constructed according to issuer and provider guidance.

Publish one TXT value for the selector. Do not copy the example domain, and do not split the value into several separate TXT records. Your DNS control panel may add quotation marks automatically.

Optional public lookup examples

LinkedIn and CNN are useful for practicing a live BIMI lookup. Their records and asset URLs can change, so use them as observations, not configuration templates.

host -t TXT default._bimi.linkedin.com
host -t TXT default._bimi.cnn.com

# Clearer TXT-only output when dig is available:
dig +short TXT default._bimi.linkedin.com
dig +short TXT default._bimi.cnn.com

host -t TXT requests TXT records. dig +short TXT asks the same question with compact output. An empty answer can mean that the current domain has no default BIMI record, the selector differs, or DNS has not propagated. A third-party result changing later does not mean your own record is wrong.

Step 6: verify DNS, files, certificate, and real messages

dig +short TXT _dmarc.example.com
dig +short TXT default._bimi.example.com

curl -fsSIL https://assets.example.com/bimi/logo.svg
curl -fsSIL https://assets.example.com/bimi/mark.pem

openssl x509 -in mark.pem -noout \
  -subject -issuer -serial -dates -fingerprint -sha256
CommandWhat it checksExpected result
dig +short TXT _dmarc.example.comThe published DMARC policy.One intended policy with p=quarantine or p=reject, the intended sp and np values, and production mode t=n.
dig +short TXT default._bimi.example.comThe default BIMI assertion visible in public DNS.One intended v=BIMI1 value with the correct URLs.
curl -fsSIL URLTLS, redirects, HTTP status, and response headers without printing the file body.A successful public response, correct final host, and expected content type.
openssl x509 ...Certificate subject, issuer, serial, validity, and SHA-256 fingerprint from a local PEM.The expected organization or identity, issuer, and unexpired dates. Use the issuer's chain-validation method as well.

Next, send through every real platform to accounts at the providers that matter. Save the raw headers. Confirm the visible From domain, dkim=pass, spf=pass, dmarc=pass, and alignment. Test Gmail web and mobile separately when Gmail matters. A Gmail VMC can receive a checkmark, while a CMC logo does not receive that VMC checkmark.

If the BIMI logo does not appear

SymptomCheck firstMeaning
DMARC failsRaw received headers and the visible From, DKIM, and Mail From domains.Fix sender authentication and alignment before BIMI.
DMARC passes but policy is ineligiblep, sp, np, and t.p=none is monitoring, and t=y asks receivers not to apply the full stated policy. Use a fully enforced current policy for BIMI.
BIMI record is missingExact domain, selector, record type, authoritative DNS, and TTL.The record may be at the wrong name or not yet visible.
SVG or PEM cannot be fetchedHTTPS status, TLS chain, redirects, content type, CDN blocks, and public access.The provider cannot retrieve or parse the asset.
Certificate is rejectedIssuer, type, domain, mark, chain, validity, and target-provider acceptance.A public checker passing does not guarantee provider acceptance.
Everything validates but one provider shows nothingCurrent provider support, reputation, account type, UI surface, caching, and certificate requirement.Display remains the mailbox provider's decision.

Do not weaken DMARC because a logo is missing. Roll back or correct the BIMI assertion while keeping valid authentication enforcement. Google provides a first-party Gmail BIMI troubleshooting guide for its specific checks.

Final production checklist

  1. Every visible From domain and legitimate sender is inventoried.
  2. Representative messages pass aligned SPF or DKIM and DMARC.
  3. DMARC uses quarantine or reject with the intended sp and np policy and production mode t=n.
  4. The exact logo, legal owner or licensee, domain scope, and provider audience are agreed.
  5. Self-asserted, CMC, or VMC was chosen from current mailbox-provider requirements.
  6. The selected certificate issuer is on the current BIMI Group list and accepted by target providers.
  7. The SVG Tiny-PS file validates and remains readable at small size.
  8. The SVG and PEM return the correct public files over stable HTTPS.
  9. The issued certificate, chain, domains, mark, validity, and renewal owner are recorded.
  10. One correct TXT assertion is published at the intended BIMI selector.
  11. Real messages were tested through each sending platform and important provider.
  12. DNS, DMARC, asset status and hash, certificate expiry, and unauthorized changes are monitored.

Review the BIMI Group implementation guide, sender FAQ, Google BIMI setup requirements, and the selected issuer's current instructions before production publication. NitWings can help with BIMI and VMC deployment when the work spans DMARC enforcement, certificate issuance, SVG validation, hosting, DNS, or provider troubleshooting.

Related technical notes

One email message receives an opaque identity token that remains connected as the message crosses several mail servers on its delivery pathEmail Infrastructure & Authentication · Feb 21, 2025 · 25 min read

Email Message-ID Implementation: A Production Guide

Implement globally unique Message-ID headers, trace customer abuse safely, protect recipient privacy, preserve retry identity, and correlate delivery events.

A modular email operations control plane connects customer data, content, and application events to managed delivery, marketing automation, and self-managed MTA pathsEmail Infrastructure & Authentication · Nov 7, 2022 · 18 min read

ESP and Email Tools: Choosing a Production Stack

Choose an ESP, delivery API, marketing platform, MTA, testing system, and provider diagnostics from evidence, traffic requirements, and exit controls.

Technical review

Need this checked against your own sending system?

Share the domain, headers, bounces, provider warning, logs, or infrastructure symptom and NitWings will identify the practical next step.

Schedule a Technical Review
Advertisement