Skip to content
Writing
NewBIMIVMCDeliverabilityDMARCSecurity

BIMI and VMC Certificates: Getting Your Verified Logo into Gmail and Apple Mail

Display your official verified brand avatar and blue checkmark beside outgoing emails in Gmail, Apple Mail, and Yahoo with BIMI and Verified Mark Certificates.

What is BIMI and why does it drive email trust and open rates?

Brand Indicators for Message Identification (BIMI) is an email specification (drafted by the AuthIndicators Working Group) that allows authenticated domain owners to display their verified brand logo directly next to incoming messages in consumer email clients.

When implemented alongside a Verified Mark Certificate (VMC), BIMI enables the coveted verified blue checkmark in Gmail, instant brand icon placement in Apple Mail (iOS 16+ and macOS Ventura+), and verified sender avatars in Yahoo Mail.

Beyond visual branding, BIMI represents the pinnacle of sender authentication. Because BIMI requires strict DMARC enforcement, phishers and domain spoofers cannot replicate your verified mark. Deliverability benchmarks show a 15% to 28% increase in initial open rates for transactional and onboarding emails once BIMI badges appear in the inbox.

The 3 non-negotiable BIMI prerequisites

Before attempting to publish a BIMI record, your sending domain must satisfy three strict technical prerequisites. If any single condition is unfulfilled, mail servers will silently ignore your BIMI record:

  • 1. Strict DMARC Policy Enforcement: Your domain must publish a DMARC policy with p=reject or p=quarantine, and pct must be set to 100 (or omitted, which defaults to 100%). Domains with p=none or pct<100 are rejected immediately.
  • 2. 100% SPF and DKIM Alignment: The envelope "From" domain must cryptographically align with your DKIM signature domain (d=yourdomain.com) and SPF authentication domain.
  • 3. High Sender Reputation: Consumer mailbox providers (particularly Gmail and Yahoo) calculate a domain reputation score. Spammers and newly minted domains with erratic volume cannot display BIMI logos even with valid certificates.
Prerequisite RequirementValid Value for BIMICommon Disqualifying Error
DMARC Policy (p=)p=reject or p=quarantinep=none (Audit mode does not qualify)
DMARC Percentage (pct=)pct=100 (or omitted)pct=50 or pct=25 (Gradual rollout fails)
DKIM Signature Alignmentd=yourdomain.com (Aligned)d=shared-esp.com (Unaligned third-party)
Logo FormatSVG Tiny 1.2 Portable/SecureStandard SVG, PNG, JPG, or WebP
Certificate (for Gmail)Verified Mark Certificate (VMC)Self-signed certificate or no cert

SVG Tiny 1.2 Portable/Secure profile specifications

Mailbox providers will not render standard SVG files because modern SVGs support JavaScript execution, external entity references, and CSS links that pose severe security vulnerabilities.

Your logo must strictly adhere to the SVG Tiny 1.2 Portable/Secure profile specified by the BIMI working group:

  • Strict 1:1 Square Aspect Ratio: The viewBox must be square (e.g. 0 0 100 100). The image should be centered with adequate whitespace padding because clients will crop it into a circle.
  • Zero External Links or Scripts: Any <script>, <style> importing external fonts, or <image> referencing raster bitmaps will fail validation.
  • File Size Under 32 KB: Keep paths simplified and remove unnecessary Adobe Illustrator or Figma metadata.
  • Gzip Compression Forbidden: The file must be served uncompressed with Content-Type: image/svg+xml.
XML
<?xml version="1.0" encoding="utf-8"?>
<svg version="1.2" baseProfile="tiny-ps" xmlns="http://www.w3.org/2000/svg"
     width="100%" height="100%" viewBox="0 0 100 100">
  <title>Your Company Logo</title>
  <circle cx="50" cy="50" r="48" fill="#10b981" />
  <path d="M30 50 L45 65 L70 35" stroke="#ffffff" stroke-width="8" fill="none" stroke-linecap="round"/>
</svg>

Verified Mark Certificates (VMC) vs Common Mark Certificates (CMC)

While Yahoo Mail allows senders with high reputation to display logos without a certificate, Gmail and Apple Mail strictly require a cryptographically signed certificate to prevent brand impersonation.

A Verified Mark Certificate (VMC) is a digital certificate issued by an authorized Certificate Authority (CA) — currently DigiCert and Entrust — confirming that your organization is the registered legal trademark owner of the displayed logo.

Feature VectorVerified Mark Certificate (VMC)Common Mark Certificate (CMC)
Trademark RequirementRegistered trademark with official IP officePrior unregistered commercial use
Gmail Blue CheckmarkGuaranteed upon reputation passEvaluated on case-by-case basis
Apple Mail SupportFull support (BIMI badge rendered)Full support
Issuing CAsDigiCert, EntrustDigiCert, Entrust
Approximate Cost$1,000 – $1,500 / year$700 – $1,000 / year

To qualify for a VMC, your brand mark must be officially registered as a wordmark or design mark with a recognized intellectual property office (such as the USPTO in the United States, EUIPO in Europe, UKIPO in the United Kingdom, or WIPO).

Publishing the BIMI DNS TXT record

Once your SVG Tiny P.S. logo and VMC certificate PEM file are hosted on a publicly accessible HTTPS web server, publish your BIMI DNS record.

Add a DNS TXT record at the subdomain default._bimi.yourcompany.com:

  • v=BIMI1: Identifies the record as a BIMI version 1 declaration (mandatory).
  • l=https://...: Direct HTTPS URL pointing to your validated SVG Tiny P.S. file.
  • a=https://...: Direct HTTPS URL pointing to the certificate bundle (.pem) containing your VMC and intermediate root CA chain.
DNS
; Authoritative BIMI DNS Record
default._bimi.yourcompany.com. IN TXT "v=BIMI1; l=https://www.yourcompany.com/branding/bimi-logo.svg; a=https://www.yourcompany.com/branding/bimi-cert.pem;"

Testing, debugging, and validation checklist

Before expecting logos to appear in live user inboxes, run through this pre-flight verification checklist:

1. Verify HTTPS accessibility: Ensure both the SVG and PEM URLs respond with HTTP 200 and serve valid SSL certificates without redirects.

2. Test DMARC alignment: Send an email through SadaSend to a Gmail address and inspect the raw email headers (Show original). Verify dkim=pass (d=yourdomain.com) and dmarc=pass.

3. Inspect BIMI parsing: Use the official BIMI Inspector tool to confirm the SVG syntax parses without errors.

4. Allow DNS propagation: Mailbox providers cache DNS lookups for 24–48 hours based on your DNS record TTL.

BIMI troubleshooting matrix: Fixing common validation failures

If your logo fails to render in Gmail or Apple Mail, consult this diagnostic matrix:

Observed FailureRoot CauseResolution Step
BIMI record not foundRecord published at root instead of default._bimiEnsure host name is default._bimi.yourdomain.com.
SVG rejected by parserFile contains forbidden CSS classes or scriptsSanitize file using SVG Tiny P.S. validator and remove XML namespaces.
Gmail blue checkmark missingVMC certificate missing intermediate CA bundleConcatenate intermediate CA certificates into the hosted .pem file.
Logo shows in Yahoo but not GmailYahoo does not require VMC, but Gmail doesAcquire a verified VMC certificate from DigiCert or Entrust.
DMARC policy rejectedDMARC record contains pct=50 or p=noneSet DMARC policy to p=reject; pct=100 in DNS.
Free plan

Building AI agents that send email?

Scoped API keys, per-key recipient allowlists, approval mode and a hosted MCP server with ten tools — on the free plan, without a card.