Adding your company logo to emails sounds simple. In practice, getting BIMI (Brand Indicators for Message Identification) working across supported mailbox providers takes more than uploading an image and adding a DNS record.
BIMI depends on your existing email authentication setup. Your sending domains need to pass DMARC, your logo needs to meet the required SVG format, and depending on the mailbox provider, you may need a BIMI certificate such as a Verified Mark Certificate (VMC) or Common Mark Certificate (CMC).
There is another point that is easy to miss: publishing BIMI does not guarantee that your logo will appear in every inbox. Each participating mailbox provider has its own requirements and decides when and where BIMI logos are displayed.
If you are planning a BIMI deployment, use this checklist before publishing your record. Each step covers what needs to be true, then shows where to do it in DMARCS, so you can work through the whole chain from one account at admin.dmarcs.com.
BIMI comes after SPF, DKIM and DMARC, not before them. The first question is simple: are all legitimate emails sent from your domain properly authenticated?
Review every service that sends email using your domain: Microsoft 365 or Google Workspace, marketing platforms, CRM and sales tools, customer support systems, transactional email services, HR and finance systems, website forms, cloud applications, monitoring platforms and third-party vendors sending on your behalf. If you have never done this, auditing who sends as you is the place to start.
A domain can have a perfectly valid BIMI record and still have authentication problems elsewhere. Google recommends SPF, DKIM and DMARC for email authentication, while the BIMI Group’s implementation guidance requires DMARC enforcement for BIMI.
Type TXT
Host _dmarc
Value v=DMARC1; p=none; rua=mailto:rua.reports@dmarcs.com; ruf=mailto:ruf.reports@dmarcs.com
Watch Sending Sources for at least two to four weeks so monthly senders, such as invoicing runs or newsletters, have a chance to show up.
This is where many BIMI projects uncover problems that have nothing to do with BIMI itself. If you still have unknown sending sources, resolve those first.
This is the main prerequisite. The BIMI Group’s guidance says the organisational domain must have DMARC enforcement at p=quarantine or p=reject, that pct must not be below 100%, and that the relevant organisational and subdomain policies need to be at enforcement. A policy of p=none is not enough.
A typical enforced policy looks like this:
v=DMARC1; p=quarantine; rua=mailto:rua.reports@dmarcs.com; pct=100
or:
v=DMARC1; p=reject; rua=mailto:rua.reports@dmarcs.com; pct=100
The right policy depends on your environment. Jumping from monitoring straight to rejection, without knowing your legitimate senders, can disrupt business email — the difference between quarantine and reject is worth understanding before you move.
_dmarc. Delete the existing _dmarc TXT record first, because a host can’t hold both a CNAME and a TXT.none > quarantine 25% > quarantine 50% > quarantine 100% > reject 50% > reject 100%
The Enforcement Guide only tells you whether you’re ready. The policy itself changes in Smart DMARC, or in the p= value of your own TXT record if you keep DMARC in your own DNS.
p=quarantine or p=rejectpct=100, or no lower percentage is setBIMI is not a replacement for DMARC. It builds on it.
Large organisations rarely send all email from one place. Alongside example.com you may have mail.example.com, marketing.example.com, support.example.com, and separate domains for other brands or business units. Before implementing BIMI, document which domains and subdomains carry customer-facing email. If you are running this across a large estate, managing DMARC at scale covers the wider problem.
The BIMI Group recommends publishing a default BIMI record at the organisational domain so subdomains inherit it. A specific subdomain can have its own BIMI record where needed. You don’t want to configure BIMI for one domain while another quietly sends thousands of messages a month.
sp= sets a separate one. Make sure sp= is at least as strict as p=, and that no subdomain publishes its own weaker _dmarc record.sp= is at least as strict as p=Your existing logo can’t simply be uploaded as a PNG or JPEG. BIMI needs it in the SVG Tiny Portable/Secure (SVG Tiny PS) profile, which comes with security restrictions: no scripts, no event handlers, no links to external files.
This is where your design and IT teams need to work together. A logo that looks good on a website may not work at the small size an inbox uses. Keep the BIMI version simple, recognisable at small sizes, suited to a square display area and free of fine detail.
If you host the logo yourself instead, it must be served over HTTPS and be publicly reachable. Opening in a browser doesn’t prove it’s valid for BIMI.
This is one of the biggest decisions in the project. A logo can be asserted for BIMI in three ways: self-asserted, with a Common Mark Certificate (CMC), or with a Verified Mark Certificate (VMC).
The BIMI Group notes that self-asserted records have limited support across mailbox providers. A VMC is tied to a registered trademark and verifies authorised use of the logo. A CMC is a newer certificate route for eligible marks. There is no single display rule: each mailbox provider decides which certificates it accepts.
If Gmail visibility is part of the goal, don’t leave the certificate question until the end. Certificate requirements have long been a central part of Gmail’s BIMI support.
Open Brand → VMC Tracker. It’s one page that shows how far along you are across the trademark office, the certificate authority, your design team and your DNS.
| Step | Who checks it |
|---|---|
| Trademark Verified | You tick it once the trademark registration is done |
| DMARC Enforcement | Checked automatically against live DNS (quarantine or reject) |
| SVG Logo Ready | You tick it once you have a valid SVG Tiny PS logo |
| Purchase VMC | You tick it once the certificate is issued |
| Publish BIMI | Checked automatically once your BIMI record is live |
When the certificate arrives, you need it in PEM format (a text file starting -----BEGIN CERTIFICATE-----), under 512KB. Not a zip, not a .p7b, not the private key. Your certificate authority can supply the PEM version.
You can publish BIMI before the certificate is ready. The logo will show in providers that don’t require one, and you add the certificate later.
Once authentication and the logo are ready, you can publish. The record lives at default._bimi.example.com. Its basic structure is:
v=BIMI1; l=https://example.com/bimi/logo.svg; a=https://example.com/bimi/certificate.pem
v= identifies the BIMI version, l= points to the SVG logo, and a= points to the VMC or CMC. For a self-asserted record, a= can be left out.
DMARCS gives you two ways to publish. Pick one per domain.
DMARCS hosts the logo, the certificate and the record. Your side is one CNAME.
default._bimi host, pointing at the DMARCS-hosted target. Copy the target from the app rather than retyping it.Type CNAME
Host default._bimi
Value (DMARCS-hosted target, copied from BIMI Inspector)
The advantage: when you replace the logo or renew the certificate later, you upload the new file in DMARCS. Your DNS doesn’t change.
Use this if you’d rather keep the logo and certificate on your own servers.
Type TXT
Host default._bimi
Value v=BIMI1; l={logoUrl}; a={certUrl};
default._bimi, so you don’t end up with two records.General guidance, not from DMARCS docs: if your DNS is on Cloudflare, set the default._bimi CNAME to DNS only (grey cloud), not proxied. Otherwise Cloudflare answers in place of DMARCS.
default._bimiv=BIMI1 included (self-hosted)l= points to the correct SVGa= points to the correct certificate where applicableDon’t stop at checking that the BIMI record exists. A working deployment depends on every link holding, in this order:
If any one of these fails, the logo may not appear.
p= and pct= after a change.The BIMI Group’s own BIMI Inspector is a useful independent second opinion.
default._bimi (Live & Protecting, if hosted)A validator can confirm your configuration is technically sound. It can’t guarantee a logo in every inbox, because mailbox providers make their own display decisions. Yahoo, for example, says its BIMI display depends on a valid record, an enforced DMARC policy, mail volume, and sufficient sender reputation and engagement.
So test with real messages across corporate, marketing and transactional mail, different From addresses, different sending platforms, different domains and subdomains, and the mailbox providers your audience actually uses (Gmail, Yahoo Mail and others).
check@dmarcs.com, from the mail system you want to test. Checking Microsoft 365? Send from Outlook, not from a marketing tool.Domain Health confirms that each system authenticates. The logo itself you confirm by sending to real Gmail and Yahoo mailboxes and looking.
Record what you see, and don’t treat a logo in one mailbox as proof the deployment is complete.
BIMI is not a set-and-forget DNS record. Marketing adds a new email platform. A CRM starts sending directly. A business unit launches a subdomain. The brand team changes the logo. Any of these can break the chain, and because BIMI sits on top of DMARC, a quiet authentication failure is enough to make the logo disappear.
Set up alerts under Organization → Alerting with New Alert, pick a trigger and Save. Alerts are always emailed; some can also post to Microsoft Teams or Slack.
| Alert | Why it matters for BIMI |
|---|---|
| DMARC Downgrade | Someone loosens the policy (for example reject to none) and BIMI stops qualifying |
| Auth Rate Drop | Pass rates fall, often a new or misconfigured sender |
| New Forwarder Detected | A new forwarding source appears in your reports |
| DNS Record Change | A monitored DNS record changes |
| New Subdomain | A subdomain appears that your policy and BIMI plan may not cover |
| SPF Lookup Limit | SPF creeps toward 10 lookups, before mail starts failing |
Keep working these pages too:
A VMC is a paid certificate with an expiry date. When it lapses, your logo stops showing and nothing tells you. Put the renewal date in your calendar when you buy it.
A brand refresh can create an unexpected BIMI task. The BIMI Group specifically calls out logo changes as a technical consideration for organisations already using BIMI. If you hold a VMC or CMC, the certificate covers a specific mark, so a new logo usually means a new certificate as well.
default._bimi CNAME stays as it is.Your brand team should bring in whoever owns email security or DNS before a major logo change goes live, not after.
Use this as the final pre-deployment review. The right-hand column shows where to check each item in DMARCS.
| Area | What must be true | Where in DMARCS |
|---|---|---|
| Email authentication | All legitimate senders identified; SPF and DKIM configured and aligned | Sending Sources, SPF Surveyor, DKIM Inspector |
| DMARC enforcement | p=quarantine or p=reject at 100%; readiness above 95% pass |
Enforcement Guide, Smart DMARC |
| Domain structure | Brand domains verified; subdomains documented; sp= at least as strict as p= |
Domain Management, Subdomain Monitor |
| Logo | SVG Tiny PS, under 2MB, served over HTTPS, readable at small sizes | BIMI Inspector (Inbox Preview), VMC Tracker |
| Certificate | VMC or CMC decision made; PEM file under 512KB; renewal date recorded | VMC Tracker, BIMI Inspector |
| DNS | One record at default._bimi; correct l= and a= values |
BIMI Inspector (hosted) or BIMI Builder (self-hosted) |
| Validation | Badge shows Live & Protecting; VMC Tracker auto-checks ticked | BIMI Inspector, VMC Tracker, Dashboard |
| Testing | Each sending platform passes; logo seen in Gmail and Yahoo | Domain Health, plus real mailboxes |
| Ongoing | Alerts on downgrades, DNS changes and new subdomains; regular source review | Alerting, Sending Sources, DNS History |
BIMI is usually sold as a way to put your logo next to your emails. That’s the visible part.
The work starts much earlier. Before a mailbox provider will consider your logo, you need to know who sends email as you, authenticate those sources, enforce DMARC at 100%, publish a valid BIMI record and supply a logo that meets the technical rules. Certificates add another layer where required.
That’s why BIMI works best as part of a wider email authentication programme rather than a one-off DNS job. In DMARCS the same account that shows your sending sources, tells you when you’re ready to enforce and moves your policy up is also where you publish the logo, track the certificate and get alerted when something slips. If you would rather walk through it with someone, get in touch.
The logo is what people see in the inbox. The work behind it is what keeps it there.
Secure your domain and boost brand visibility with BIMI. Display your trademarked logo in supported inboxes after DMARC enforcement. Step-by-step guide included.
Tell us where your domains stand today and we will take it from there.