What is BIMI and why does it drive email trust and open rates?
Brand Indicators for Message Identification (BIMI) is an email specification (drafted by the AuthIndicators Working Group) that allows authenticated domain owners to display their verified brand logo directly next to incoming messages in consumer email clients.
When implemented alongside a Verified Mark Certificate (VMC), BIMI enables the coveted verified blue checkmark in Gmail, instant brand icon placement in Apple Mail (iOS 16+ and macOS Ventura+), and verified sender avatars in Yahoo Mail.
Beyond visual branding, BIMI represents the pinnacle of sender authentication. Because BIMI requires strict DMARC enforcement, phishers and domain spoofers cannot replicate your verified mark. Deliverability benchmarks show a 15% to 28% increase in initial open rates for transactional and onboarding emails once BIMI badges appear in the inbox.
The 3 non-negotiable BIMI prerequisites
Before attempting to publish a BIMI record, your sending domain must satisfy three strict technical prerequisites. If any single condition is unfulfilled, mail servers will silently ignore your BIMI record:
- 1. Strict DMARC Policy Enforcement: Your domain must publish a DMARC policy with p=reject or p=quarantine, and pct must be set to 100 (or omitted, which defaults to 100%). Domains with p=none or pct<100 are rejected immediately.
- 2. 100% SPF and DKIM Alignment: The envelope "From" domain must cryptographically align with your DKIM signature domain (d=yourdomain.com) and SPF authentication domain.
- 3. High Sender Reputation: Consumer mailbox providers (particularly Gmail and Yahoo) calculate a domain reputation score. Spammers and newly minted domains with erratic volume cannot display BIMI logos even with valid certificates.
| Prerequisite Requirement | Valid Value for BIMI | Common Disqualifying Error |
|---|---|---|
| DMARC Policy (p=) | p=reject or p=quarantine | p=none (Audit mode does not qualify) |
| DMARC Percentage (pct=) | pct=100 (or omitted) | pct=50 or pct=25 (Gradual rollout fails) |
| DKIM Signature Alignment | d=yourdomain.com (Aligned) | d=shared-esp.com (Unaligned third-party) |
| Logo Format | SVG Tiny 1.2 Portable/Secure | Standard SVG, PNG, JPG, or WebP |
| Certificate (for Gmail) | Verified Mark Certificate (VMC) | Self-signed certificate or no cert |
SVG Tiny 1.2 Portable/Secure profile specifications
Mailbox providers will not render standard SVG files because modern SVGs support JavaScript execution, external entity references, and CSS links that pose severe security vulnerabilities.
Your logo must strictly adhere to the SVG Tiny 1.2 Portable/Secure profile specified by the BIMI working group:
- Strict 1:1 Square Aspect Ratio: The viewBox must be square (e.g. 0 0 100 100). The image should be centered with adequate whitespace padding because clients will crop it into a circle.
- Zero External Links or Scripts: Any <script>, <style> importing external fonts, or <image> referencing raster bitmaps will fail validation.
- File Size Under 32 KB: Keep paths simplified and remove unnecessary Adobe Illustrator or Figma metadata.
- Gzip Compression Forbidden: The file must be served uncompressed with Content-Type: image/svg+xml.
<?xml version="1.0" encoding="utf-8"?>
<svg version="1.2" baseProfile="tiny-ps" xmlns="http://www.w3.org/2000/svg"
width="100%" height="100%" viewBox="0 0 100 100">
<title>Your Company Logo</title>
<circle cx="50" cy="50" r="48" fill="#10b981" />
<path d="M30 50 L45 65 L70 35" stroke="#ffffff" stroke-width="8" fill="none" stroke-linecap="round"/>
</svg>Verified Mark Certificates (VMC) vs Common Mark Certificates (CMC)
While Yahoo Mail allows senders with high reputation to display logos without a certificate, Gmail and Apple Mail strictly require a cryptographically signed certificate to prevent brand impersonation.
A Verified Mark Certificate (VMC) is a digital certificate issued by an authorized Certificate Authority (CA) — currently DigiCert and Entrust — confirming that your organization is the registered legal trademark owner of the displayed logo.
| Feature Vector | Verified Mark Certificate (VMC) | Common Mark Certificate (CMC) |
|---|---|---|
| Trademark Requirement | Registered trademark with official IP office | Prior unregistered commercial use |
| Gmail Blue Checkmark | Guaranteed upon reputation pass | Evaluated on case-by-case basis |
| Apple Mail Support | Full support (BIMI badge rendered) | Full support |
| Issuing CAs | DigiCert, Entrust | DigiCert, Entrust |
| Approximate Cost | $1,000 – $1,500 / year | $700 – $1,000 / year |
To qualify for a VMC, your brand mark must be officially registered as a wordmark or design mark with a recognized intellectual property office (such as the USPTO in the United States, EUIPO in Europe, UKIPO in the United Kingdom, or WIPO).
Publishing the BIMI DNS TXT record
Once your SVG Tiny P.S. logo and VMC certificate PEM file are hosted on a publicly accessible HTTPS web server, publish your BIMI DNS record.
Add a DNS TXT record at the subdomain default._bimi.yourcompany.com:
- v=BIMI1: Identifies the record as a BIMI version 1 declaration (mandatory).
- l=https://...: Direct HTTPS URL pointing to your validated SVG Tiny P.S. file.
- a=https://...: Direct HTTPS URL pointing to the certificate bundle (.pem) containing your VMC and intermediate root CA chain.
; Authoritative BIMI DNS Record
default._bimi.yourcompany.com. IN TXT "v=BIMI1; l=https://www.yourcompany.com/branding/bimi-logo.svg; a=https://www.yourcompany.com/branding/bimi-cert.pem;"Testing, debugging, and validation checklist
Before expecting logos to appear in live user inboxes, run through this pre-flight verification checklist:
1. Verify HTTPS accessibility: Ensure both the SVG and PEM URLs respond with HTTP 200 and serve valid SSL certificates without redirects.
2. Test DMARC alignment: Send an email through SadaSend to a Gmail address and inspect the raw email headers (Show original). Verify dkim=pass (d=yourdomain.com) and dmarc=pass.
3. Inspect BIMI parsing: Use the official BIMI Inspector tool to confirm the SVG syntax parses without errors.
4. Allow DNS propagation: Mailbox providers cache DNS lookups for 24–48 hours based on your DNS record TTL.
BIMI troubleshooting matrix: Fixing common validation failures
If your logo fails to render in Gmail or Apple Mail, consult this diagnostic matrix:
| Observed Failure | Root Cause | Resolution Step |
|---|---|---|
| BIMI record not found | Record published at root instead of default._bimi | Ensure host name is default._bimi.yourdomain.com. |
| SVG rejected by parser | File contains forbidden CSS classes or scripts | Sanitize file using SVG Tiny P.S. validator and remove XML namespaces. |
| Gmail blue checkmark missing | VMC certificate missing intermediate CA bundle | Concatenate intermediate CA certificates into the hosted .pem file. |
| Logo shows in Yahoo but not Gmail | Yahoo does not require VMC, but Gmail does | Acquire a verified VMC certificate from DigiCert or Entrust. |
| DMARC policy rejected | DMARC record contains pct=50 or p=none | Set DMARC policy to p=reject; pct=100 in DNS. |
Building AI agents that send email?
Scoped API keys, per-key recipient allowlists, approval mode and a hosted MCP server with ten tools — on the free plan, without a card.