What is BIMI and How to Set It Up
Edit in CMSBIMI (Brand Indicators for Message Identification) lets your logo appear next to your messages in supporting inboxes. This guide covers what you need before you start, the DNS record itself, and what to expect after publishing.
If anything is unclear, reach out to support and we’ll help you get set up.
What you’ll need before you start
Section titled “What you’ll need before you start”BIMI has prerequisites that sit outside of DNS. Get these in place first or the logo won’t render even with a valid record.
A DMARC policy at enforcement
Section titled “A DMARC policy at enforcement”Your domain’s DMARC record must be set to either p=quarantine or p=reject, with pct=100. Most mailbox providers also expect your domain to have been at enforcement for at least 30 days before they’ll pull and display the logo.
If your DMARC is still at p=none, BIMI will not work. Move to p=quarantine first, watch your aggregate reports for a couple of weeks, then tighten if needed. See setting up your sending domain for DMARC basics.
A logo in SVG Tiny-PS format
Section titled “A logo in SVG Tiny-PS format”BIMI does not accept regular SVG files. It requires the SVG Tiny Portable/Secure profile (SVG Tiny-PS), a stripped-down variant of SVG Tiny 1.2. Key constraints:
- The root
<svg>element must include the attributebaseProfile="tiny-ps". - No scripts, external references, animation, or embedded raster images.
- File size capped at 32 KB.
- Square aspect ratio (1:1), centered, with a solid background.
Several free converters exist (BIMI Group maintains a list at bimigroup.org), or your designer can export from Illustrator with the Tiny 1.2 profile and hand-edit the baseProfile attribute.
A certificate (for Gmail and Apple Mail)
Section titled “A certificate (for Gmail and Apple Mail)”Gmail and Apple Mail require the logo to be backed by either a Verified Mark Certificate (VMC) or a Common Mark Certificate (CMC), issued by an authorized Mark Verifying Authority (currently DigiCert or Entrust).
- VMC — requires a registered trademark on your logo.
- CMC — lighter-weight option for non-trademarked logos; fewer mailbox providers honor it.
Yahoo and Fastmail display the logo without a certificate, but Gmail/Apple coverage is why most senders pursue one.
A place to host the SVG
Section titled “A place to host the SVG”The logo file must be served over HTTPS at a stable URL — ideally on your own domain, e.g. https://yourbrand.com/bimi/logo.svg.
Steps to publish the BIMI record
Section titled “Steps to publish the BIMI record”-
Log in to your DNS provider (Cloudflare, Route 53, GoDaddy, Namecheap, etc.) and find where to add a new record.
-
Create a TXT record — BIMI is a TXT record, not a custom type.
-
Set the Host / Name field to
default._bimi. Your provider appends the domain, so the record resolves todefault._bimi.yourdomain.com. Thedefaultselector is what providers look up first; additional selectors are possible but rarely needed. -
Set the Value field — two required tags separated by a semicolon:
v=BIMI1; l=https://yourbrand.com/bimi/logo.svgv=BIMI1— the version tag, always exactly this.l=— the HTTPS URL of your hosted SVG (lowercase L).
If you have a VMC or CMC, add the
a=tag pointing to the certificate:v=BIMI1; l=https://yourbrand.com/bimi/logo.svg; a=https://yourbrand.com/bimi/vmc.pem -
Save the record.
-
Verify with a BIMI checker — MX Toolbox’s BIMI lookup (
https://mxtoolbox.com/bimi.aspx) or BIMI Group’s inspector. These flag syntax issues, SVG profile problems, or missing certificate references.
How long until the logo shows up?
Section titled “How long until the logo shows up?”- DNS propagation typically takes 24 to 48 hours.
- Mailbox providers cache BIMI lookups, so logo display often lags DNS by several days to a few weeks.
- If you’ve just moved DMARC to enforcement, the 30-day window starts from that change — not from when you publish the BIMI record.
Send a test message to a Gmail or Yahoo address after a week. If the logo still isn’t appearing after 30 days at DMARC enforcement, run the record through a BIMI checker again.
Common reasons the logo doesn’t appear
Section titled “Common reasons the logo doesn’t appear”- DMARC is still at
p=none, orpctis below 100. - The SVG was exported as standard SVG, not Tiny-PS (missing
baseProfile="tiny-ps"). - The SVG URL isn’t HTTPS, or returns a redirect.
- The mailbox provider requires a VMC and the record doesn’t include an
a=tag. - The receiving inbox isn’t a BIMI-supporting provider — Outlook.com, for instance, doesn’t render BIMI logos as of this writing.
- DMARC has been at enforcement for less than 30 days.
If you’ve checked all of the above and the logo still isn’t displaying, support can help you dig into the DNS, SVG, and certificate setup.
Quick reference
Section titled “Quick reference”| Tag | Required | Purpose |
|---|---|---|
v | Yes | Version. Always BIMI1. |
l | Yes | HTTPS URL of the hosted SVG Tiny-PS logo. |
a | For Gmail / Apple | HTTPS URL of the VMC or CMC certificate. |
| Prerequisite | Why it matters |
|---|---|
DMARC at p=quarantine or p=reject, pct=100 | BIMI will not render without it |
| 30 days at DMARC enforcement | Most providers gate logo display on this |
| SVG Tiny-PS, ≤ 32 KB, square, solid background | Required SVG profile; standard SVG is rejected |
| VMC or CMC certificate | Required by Gmail and Apple Mail |
| HTTPS hosting for the SVG | Required by spec |
Related
Section titled “Related”Still can’t find what you need? Contact support.