How to Set Up BIMI and Get Your Logo Into the Inbox

Published on
toolsemail-securitytechnical

Open your inbox and scan down the list of senders. Most of them show a grey circle with a letter in it. A few show an actual logo — the bank, the airline, maybe one retailer. Those few did something the rest didn't: they published a BIMI record.

It's a small visual difference that does a surprising amount of work. A logo in the sender slot tells a recipient, before they've read a word, that the message is from who it says it's from. And because BIMI only renders when your authentication is genuinely enforced, the logo is the one inbox signal a phisher can't copy.

Two new tools, live today. We've just shipped a free BIMI Record Generator and Checker — build a valid v=BIMI1 TXT record from your logo and certificate URLs, or look up any domain's existing record and preview the logo the way a mailbox would render it. Both run entirely in your browser.

What BIMI Actually Is

BIMI — Brand Indicators for Message Identification — is a DNS TXT record that tells participating mailbox providers where to find your logo. That's the whole mechanism. It's a pointer, not a protocol with any verification logic of its own.

The record lives at a selector subdomain, almost always default._bimi.yourdomain.com, and looks like this:

v=BIMI1; l=https://yourdomain.com/logo.svg; a=https://yourdomain.com/vmc.pem;

Three tags, and only the first two are strictly mandatory:

  • v=BIMI1 — the version. Always this.
  • l= — an HTTPS URL pointing to your logo in SVG Tiny PS format.
  • a= — an HTTPS URL pointing to a certificate that proves you're entitled to use that logo. Leave it empty (a=;) and you have what's called a self-asserted BIMI record.

What makes BIMI interesting isn't the record. It's the gate in front of it. A receiving server only bothers looking for your BIMI record after the message has passed DMARC at enforcement. No enforcement, no lookup, no logo — regardless of how perfect the record is.

That ordering is why BIMI is usually described as a reward rather than a feature. You can't buy your way to a logo; you have to get your authentication house in order first.

The Prerequisites, In Order

1. DMARC at enforcement

This is the one that stops most projects. Your domain needs a DMARC policy of p=quarantine or p=reject, applied to 100% of mail. A record sitting at p=none makes your BIMI record effectively invisible — mailbox providers won't even query it.

If you're not there yet, the path is well trodden: publish p=none with a reporting address, read the aggregate reports until every legitimate sender is passing SPF or DKIM in alignment, then tighten. Our guide to how SPF, DKIM, and DMARC work together covers the mechanics, and how to check your domain's records walks through the diagnostics. The DNS Checker will tell you in seconds where your policy currently stands, and the DMARC Analyzer turns the XML reports into something you can actually act on.

Budget real time for this. Red Sift, who do this for a living, quote six to eight weeks to reach enforcement on a domain of any complexity — then only seven to ten days for the certificate part.

BIMI doesn't accept PNG, JPG, or ordinary SVG. It requires SVG Tiny PS (Portable/Secure), a deliberately constrained profile designed so that a mail client can render your file without executing anything dangerous.

The requirements are specific:

  • baseProfile="tiny-ps" declared on the root <svg> element
  • A <title> element containing your organisation's name
  • Square aspect ratio — 1:1, no exceptions worth risking
  • A solid background, not transparency
  • No scripts, no animation, no embedded raster images, no external references of any kind
  • Under 32 KB, served over HTTPS

Most brand SVGs fail at least two of these straight out of the design tool. Export, then open the file in a text editor and delete anything that references the outside world.

This matters more than it sounds. In an analysis of 5.5 million domains published in February 2026, DMARCGuard found that of the 20,518 domains publishing a BIMI record, only 71.8% had a valid SVG behind it. The other 28.2% were pointing at 404s or the wrong image format — a record that looks correct in DNS and renders nothing at all.

3. A certificate — sometimes

Here's where BIMI stops being free.

A VMC (Verified Mark Certificate) is issued by a Mark Verifying Authority after they confirm you hold a registered trademark on the logo. It's the version that unlocks the most display surface, including Gmail's blue verified checkmark. Expect roughly $1,000–$1,500 a year at list price from DigiCert or Sectigo, less through resellers. Note that the issuer landscape shifted recently: Entrust wound down its public trust CA services in September 2025 and Sectigo absorbed that business, so if you're renewing an older certificate, check who's actually issuing it now.

A CMC (Common Mark Certificate) arrived in early 2025 as the escape hatch for organisations without a registered trademark. Instead of a trademark, you demonstrate 12 months of documented public use of the logo, verified through web archives. A CMC gets your logo into Gmail; it does not get you the checkmark. Pricing typically runs a few hundred dollars below a VMC.

Self-asserted BIMI — an empty a= tag — costs nothing and is still worth publishing, because some providers honour it. It just won't reach Gmail or Apple Mail.

Which Providers Actually Display Logos in 2026

This is the part of BIMI advice that ages badly, so here's the current state rather than the 2022 version.

Gmail — full support across web, desktop, and mobile, and by far the biggest prize. Requires DMARC enforcement plus either a VMC or a CMC. The blue verified checkmark is VMC-only; a CMC gets the logo alone. Google's own BIMI setup documentation is the authoritative reference for its requirements.

Yahoo Mail and AOL — supported in webmail and mobile, and notably without a mandatory certificate. Yahoo was the original BIMI pilot partner and still honours self-asserted records, though it expects a strict DMARC policy. If you want to see your logo somewhere without spending money on a certificate, this is where you'll see it first.

Apple Mail — supported since iOS 16, iPadOS 16, and macOS Ventura 13, and it requires a VMC from a qualified CA. No self-asserted display, no CMC path. Apple also doesn't show a checkmark; the logo is the whole benefit.

Fastmail — displays BIMI logos without a strict certificate requirement. Small audience, but a useful second confirmation that your record and SVG are valid.

Zoho Mail and Proton Mail — partial or in-progress implementations. Treat any rendering there as a bonus rather than something to plan around.

Outlook, Outlook.com, and Exchange Online — still nothing. Microsoft was reported to be piloting BIMI in consumer Outlook back in late 2023; that pilot never became something a sender can rely on, and Microsoft has said Exchange Online does not render BIMI logos with no near-term plans to change that. Since the Outlook desktop and mobile apps display whatever the upstream mailbox provides, they show the default avatar no matter what you publish.

So the honest summary: BIMI buys you logo display for your Gmail, Yahoo/AOL, and Apple Mail recipients. Depending on your list, that may be 70% of your audience or it may be 20%. Work out which before you sign a certificate order.

Is It Worth It?

Adoption is still thin in absolute terms — that DMARCGuard scan put BIMI at 0.4% of all domains. But the distribution is lopsided in a way that tells you who's finding value in it. A June 2026 crawl of the top 10,000 domains found 8.9% publishing a BIMI record, rising to 15.7% among the top 1,000. Large consumer brands and financial services are the heavy adopters, which is exactly what you'd expect from a control whose main job is making impersonation visibly harder.

On engagement numbers, be sceptical of what you read. Most published BIMI statistics come from vendors selling certificates, and the eye-catching ones — 40% lifts, doubled brand recall — don't come with methodology you can inspect. The more modest figures are more believable: Red Sift's case study with TalkTalk reports a 4–6% improvement in engagement after implementation, and that's roughly the range most senders who test it properly seem to land in.

A few points in open rate is a reasonable return on a record you publish once. It is not, on its own, a reason to buy a certificate if you're not already at DMARC enforcement — in which case the enforcement is the win and the logo is the receipt.

Generating and Checking Your Record

Which brings us to the two new tools.

The BIMI Record Generator is the build side. Enter your domain, your selector (leave it as default unless you have a specific reason not to), your logo URL, and your VMC or CMC URL if you have one. It assembles the correctly formatted v=BIMI1 value, shows you the exact host name to create in DNS — default._bimi.yourdomain.com — and gives you a copy button. It also renders your SVG inline, which is a fast way to catch a logo that your DNS provider would happily accept and no mail client would ever display.

The Checker tab on the same page is the verify side. Enter any domain and it queries the _bimi TXT record live, parses out the version, logo, and certificate URLs, and previews the logo inside a circular mask — approximately how Gmail and Yahoo will crop it. Useful for three things:

  • Confirming your own record propagated after a DNS change.
  • Debugging a logo that isn't appearing. Nine times out of ten it's the SVG, not the record, and the preview makes that obvious immediately.
  • Looking at how other brands did it. Type in ebay.com, or any large retailer or bank you receive mail from — their record shows you a working configuration, including whether they went the VMC route.

Like our CSS Inliner and DNS Checker, both BIMI tools are 100% client-side. The generator is pure computation in your browser — nothing is submitted anywhere. The checker sends its DNS lookup straight from your browser to a public DNS-over-HTTPS resolver, so the domains you check never pass through our servers and there's nothing for us to log. No account, no rate limit, no stored history.

A Realistic Rollout

If you're starting from scratch, the order matters — doing it out of order wastes money:

  1. Check where you stand. Run your domain through the DNS Checker and note your DMARC policy.
  2. Get to p=quarantine, then p=reject. Use the DMARC Analyzer on your aggregate reports to confirm every legitimate sender passes before you tighten. Do not skip this.
  3. Produce the SVG Tiny PS logo and host it on HTTPS. Verify it renders in the generator's preview.
  4. Publish a self-asserted record first (a=;). Free, and it gets you Yahoo, AOL, and Fastmail display — plus real-world proof that your logo file is valid.
  5. Send yourself a test message to a Yahoo address. If the logo appears, the pipeline works end to end. If you want to inspect the authentication verdict the receiver recorded, save the message as an .eml and read the Authentication-Results header in our EML Viewer.
  6. Then decide on a certificate. Now you know your logo and DNS are correct, and the only question left is whether Gmail and Apple Mail display is worth the annual cost for your audience.

That sequencing means the only thing you can't test before paying is the certificate itself — everything else is verifiable for free.

Start With Your Record

BIMI is the rare email project where the hard part isn't the thing being announced. The DNS record takes two minutes. Getting to DMARC enforcement is the work, and it's work worth doing whether or not a logo ever appears.

If you're already enforcing, you're one TXT record and one SVG away. Build it with the free BIMI Record Generator and Checker — generate the record, preview the logo, publish it, then check it back. Nothing stored, nothing to sign up for.