Open Gmail and some senders have a logo next to their name while everyone else gets a grey circle with an initial. That logo is BIMI, and it's earned through DNS records, DMARC enforcement, and a certificate that proves the logo is yours.
This guide covers what BIMI requires, the two certificate types and which one you need, what it genuinely costs, which inboxes display it, and how to set it up without the silent failures that trip most people up.
BIMI shows your logo beside your emails in Gmail, Yahoo, Apple Mail, and Fastmail. You need DMARC at enforcement, a square SVG logo in a specific profile, a BIMI DNS record, and usually a certificate. A VMC requires a registered trademark and unlocks Gmail's blue checkmark plus Apple Mail. A CMC needs no trademark, just a year of public logo use, and shows your logo in Gmail without the checkmark. Outlook and Microsoft 365 do not display BIMI at all.
What BIMI Is (and Isn't)
BIMI stands for Brand Indicators for Message Identification. It's a DNS-based standard that tells participating mailbox providers where to find your logo and the certificate vouching for it.
It is not a replacement for SPF, DKIM, or DMARC. It sits on top of them, and it only works once those are solid. If your authentication isn't right, start with domain authentication before thinking about logos.
It's also not a deliverability feature. A broken BIMI record won't hurt your inbox placement; your logo just won't appear.
Which Inboxes Actually Show It
This matters more than any other factor, because it determines whether BIMI is worth the money for your audience.
Provider | Shows BIMI logo | Certificate needed |
|---|---|---|
Gmail / Google Workspace | Yes | VMC or CMC. The blue checkmark appears with a VMC only |
Apple Mail (iOS 16+, macOS Ventura+) | Yes | VMC |
Yahoo Mail / AOL | Yes | Check current requirements; a certificate is recommended |
Fastmail | Yes | Not required |
Outlook / Outlook.com / Microsoft 365 | No | Not applicable |
The Outlook gap is the deciding factor for most B2B senders. Microsoft's mail products don't read BIMI records, and there's no announced date for support. If most of your list is business addresses on Microsoft 365, a large share of your audience will never see the logo you're paying for. If your audience is consumer Gmail and Apple Mail, the coverage is good.
VMC vs CMC: Which Certificate Do You Need?
Until recently, Gmail required a VMC, which meant you needed a registered trademark. That changed with the Common Mark Certificate, and it's the development that makes BIMI realistic for smaller businesses.
VMC | CMC | |
|---|---|---|
Requires registered trademark | Yes | No |
Other requirement | Trademark in a recognized registry | Logo used publicly for at least 12 months |
Gmail logo | Yes | Yes |
Gmail blue checkmark | Yes | No |
Apple Mail | Yes | No |
Typical cost | Around $1,000–$1,500 per year | Varies by provider; check current rates |
Both are issued by approved certificate authorities and are valid for 397 days, so renewal is an annual job either way.
Choose a VMC if you hold a trademark and want the checkmark and Apple Mail coverage. Choose a CMC if you don't have a trademark but have used the same logo publicly for a year and mainly want Gmail logo display. Self-asserted records (a BIMI record with no certificate) work in a few places like Fastmail, but Gmail won't display them.
What You Need Before Starting
DMARC at enforcement:
p=quarantineorp=reject, applying to 100% of mail. If you're atp=none, that's your first project, and it takes weeks, not hours.SPF and DKIM passing and aligned with your From domain.
A square SVG logo in the SVG Tiny Portable/Secure profile (more below).
HTTPS hosting for the logo and certificate files, publicly accessible without authentication.
DNS access to publish a TXT record.
A certificate, VMC or CMC, unless you're only targeting providers that accept self-asserted records.
A consistent sending history. Providers also weigh your reputation; BIMI isn't a shortcut around a poor one. If you've had problems, see checking whether your domain is blacklisted.
Step 1: Get DMARC to Enforcement
Check your current record. If it reads p=none, you're monitoring, not enforcing, and BIMI won't activate.
The path is: publish p=none with a reporting address, review reports for a few weeks to find legitimate senders that fail, fix those, then move to p=quarantine, then p=reject. Make sure the policy applies to all your mail rather than a percentage.
This is the longest part of the project and the one most likely to break something, because every forgotten tool that sends as your domain surfaces here. Do it carefully; our deliverability guide covers the sequence.
Pro tip: Watch your DMARC reports for a full cycle after moving to enforcement, including monthly senders like invoicing tools, before you spend money on a certificate.
Step 2: Prepare the SVG Logo
The format requirements are strict and unforgiving:
SVG Tiny Portable/Secure (SVG P/S), a restricted profile of SVG Tiny 1.2. The root element needs
baseProfile="tiny-ps".A
<title>element describing the logo.Square, 1:1 aspect ratio.
A solid background colour, not transparency, since logos render inside a circle or square in most clients.
No scripts, no external references, no embedded raster images, no animation.
Text converted to paths, since external fonts won't load.
Under 32 KB.
Served over HTTPS with a valid certificate.
Validate with the BIMI Group's SVG validator before going further. A file that looks perfect in a browser can still fail validation.
Pro tip: Design for a small circle. Detailed wordmarks become illegible at inbox size; most brands end up using a monogram or icon.
Step 3: Obtain Your Certificate
Apply through an approved certificate authority such as DigiCert or Entrust.
For a VMC, you'll submit your trademark registration (from a recognized registry such as USPTO or EUIPO), your SVG, and business verification documents. The logo in the certificate must match your registered mark.
For a CMC, you demonstrate at least 12 months of continuous public use of the logo on a domain you own, rather than a trademark.
Either way, expect verification to take a couple of weeks, sometimes longer if documentation needs chasing. You'll receive a PEM file to host at a public HTTPS URL.
Pro tip: If you're planning to trademark the logo anyway, do that first and get a VMC. Switching from CMC to VMC later means a second application and a second fee.
Step 4: Publish the BIMI Record
Add a TXT record at default._bimi.yourdomain.com:
v=BIMI1; l=https://yourdomain.com/logo.svg; a=https://yourdomain.com/certificate.peml=points to the SVG.a=points to the certificate. Omit it only for a self-asserted record, which Gmail ignores.
Set a normal TTL and allow time for propagation. Confirm with dig TXT default._bimi.yourdomain.com or an online lookup.
Pro tip: Verify both URLs resolve publicly in a private browser window. A 403, a redirect, or a file behind a login breaks BIMI silently, with no error anywhere.
Step 5: Test and Monitor
Send to a Gmail address you control and check whether the logo appears. If it doesn't, use "Show original" to confirm DMARC passed, then recheck the SVG against the validator and the URLs for accessibility. Third-party BIMI inspectors will flag most record-level mistakes.
Then set two reminders: one to renew the certificate well before its 397-day expiry, since an expired certificate removes your logo immediately, and one to re-test after any DNS, logo, or ESP change.
Is BIMI Worth It for You?
Good fit: consumer-facing senders with meaningful volume, an audience concentrated in Gmail, Yahoo, and Apple Mail, a recognizable logo, and DMARC already at enforcement.
Poor fit right now: B2B senders whose recipients are mostly on Outlook and Microsoft 365, organizations still at p=none, and anyone whose logo is barely known, since a logo only reinforces recognition that already exists.
Worth noting on the claimed benefits: most published figures about open-rate lift from BIMI come from vendors selling BIMI services, and they rarely isolate BIMI from the deliverability improvements that come with reaching DMARC enforcement in the first place. Treat them as directional. The clearer wins are consistency of brand presentation and the fact that getting to enforcement makes exact-domain spoofing much harder, which genuinely helps against business email compromise.
Also worth saying plainly: BIMI doesn't stop phishing. Attackers simply use lookalike domains with their own logos, which is why your team still needs awareness training.
Common Mistakes
Starting BIMI while still at
p=none. Nothing else matters until DMARC is enforced.Using a rectangular logo. It must be square.
Transparent backgrounds. Give the SVG a solid background colour.
Wrong SVG profile. Ordinary SVG export won't pass; you need SVG P/S with
baseProfile="tiny-ps"and a<title>.Files behind authentication or a redirect. Both fail silently.
Assuming a CMC gets you the checkmark. It gets the logo in Gmail, not the badge, and not Apple Mail.
Expecting it to work in Outlook. It doesn't, and there's no announced date.
Forgetting renewal. The logo disappears the moment the certificate expires.
FAQ
What is BIMI?
A standard that lets your verified brand logo appear beside your messages in supported inboxes, using a DNS record plus a certificate, on top of enforced DMARC.
Do I need a trademark?
Not any more. A CMC requires only 12 months of continuous public logo use. A trademark is still needed for a VMC, which is what unlocks Gmail's blue checkmark and Apple Mail.
Does BIMI work in Outlook?
No. Outlook, Outlook.com, Exchange Online, and Microsoft 365 don't render BIMI logos, with no announced date for support.
How much does it cost?
A VMC typically runs around $1,000–$1,500 a year; CMC pricing varies by provider. Design and hosting are usually minor by comparison.
How long does setup take?
Certificate issuance takes a couple of weeks, and DNS propagates within a day. The real variable is DMARC: going from monitoring to enforcement safely often takes a month or more.
Will a bad BIMI record hurt deliverability?
No. The logo just won't show.
Does BIMI prevent phishing?
It makes impersonating your exact domain harder, mostly because of the DMARC enforcement underneath it. It does nothing about lookalike domains.
Do I need a certificate at all?
For Gmail, Apple Mail, and most providers, yes. Fastmail displays logos from self-asserted records, but that's a narrow audience.
Get the Foundations Right First
BIMI only works on top of correctly authenticated email. NevTan Mail gives you secure, ad-free business email on your own domain with a guided setup flow that walks you through MX, SPF, DKIM, DMARC, and Autodiscover and verifies each record, so the authentication BIMI depends on is in place from day one. You also get a calendar and meetings in the inbox, mailboxes, aliases, and groups in one admin console, two-factor authentication with security key support, and up to 10 mailboxes free forever.
