All posts

BIMI Setup Guide: What It Needs and Whether It's Worth It

··6 min read

BIMI lets mailbox providers show your logo next to your email. It needs three things: DMARC at p=quarantine or p=reject, a logo in the SVG Tiny PS format hosted over HTTPS, and a DNS record at default._bimi.yourdomain. Gmail also requires a paid mark certificate, either a VMC (trademarked logo) or a CMC (logo in use for 12 months).

Whether that's worth it depends almost entirely on the first requirement. If you are already at DMARC enforcement, BIMI is a few hours of work and an annual certificate fee. If you aren't, the certificate is the least of it.

What BIMI requires, item by item

Requirement Details Source
DMARC at enforcement p=quarantine or p=reject; not p=none. Google also requires pct=100 Google: Set up BIMI
Aligned authentication SPF or DKIM aligned with the visible From domain BIMI Group FAQ
SVG logo SVG Tiny PS profile; no scripts, external links, animation or embedded bitmaps; square Google; BIMI Group
Gmail-specific SVG rules At least 96 x 96 px in absolute pixels; solid background recommended; 32 KB or smaller recommended Google
HTTPS hosting Served over HTTPS, TLS 1.2+ recommended, image/svg+xml content type Google; BIMI Group
DNS record TXT at default._bimi.yourdomain BIMI Group
Mark certificate VMC or CMC for Gmail; optional at some other providers Google; BIMI Group

The DNS record itself is short:

default._bimi.example.com. TXT "v=BIMI1; l=https://example.com/bimi/logo.svg; a=https://example.com/bimi/cert.pem"

l= is the logo and a= is the certificate. Leave a= empty or omit it for a self-asserted logo, which the BIMI Group says is shown by "Yahoo, Fastmail, and LaPoste" but not by Gmail.

One trap with the DMARC requirement: a policy in testing mode isn't enforcement. The BIMI Group's FAQ defines enforcement as quarantine or reject, "not p=none" and not pct<100. Under the new DMARC standard, RFC 9989, the testing flag is t=y, and the same logic applies. If you're mid-rollout following our p=none to p=reject guide, BIMI waits until you finish.

VMC or CMC?

This is the decision that drives cost and timeline.

Verified Mark Certificate (VMC) Common Mark Certificate (CMC)
What the logo must be A registered trademark, or a government mark A logo in use on your domain for at least 12 months, or a modified version of a registered mark
How it's checked Trademark registration with an IP office the issuer recognises Prior use: the logo must be on your site now and must appear on the same domain in an archive.org capture at least 12 months earlier
Gmail logo Yes Yes (supported since September 2024)
Gmail checkmark Yes No
Lead time Trademark registration "can take 6 to 12 months" (Google) if you don't already have one Depends on whether archive.org captured your site 12+ months ago
Validity Max 398 days Max 398 days

The prior-use rule is in section 3.2.16.1 of the Mark Certificate requirements (version 1.8, June 2026). The issuer must verify that the logo "was historically displayed at least 12 months earlier than the date of Mark verification on the same Domain Name," and the only approved archive source listed is archive.org. So before you apply for a CMC, search the Wayback Machine for your homepage. If there's no capture showing the same logo a year ago, you'll be refused, however long you've really used it.

Both certificate types expire after at most 398 days, so budget for annual renewal, and for the logo file to change if your branding does.

What does a certificate cost?

We tried to read published prices on 1 October 2026 and couldn't get a figure we'd stand behind. The issuer pages we fetched either needed JavaScript to show pricing or showed figures that didn't add up to a clear annual price. The BIMI Group's FAQ says only that pricing "varies by MVA" and to "expect an annual fee." Ask at least two issuers from the BIMI Group's list for a written quote.

Who actually uses it: 40 domains checked

We queried default._bimi and _dmarc for 40 large consumer and B2B brands with dig on 1 October 2026.

Result Domains
BIMI record with a certificate (a= populated) 18
BIMI record, no certificate (self-asserted) 5
No BIMI record 17

The detail is more useful than the totals:

  • Every domain with a BIMI record also had DMARC at quarantine or reject. That's a requirement, so it's expected, but it confirms the order: enforcement came first.
  • Most of the domains without BIMI are at enforcement too. Google, Yahoo, Microsoft, Stripe, Nike, Walmart, Target and others publish p=reject and no BIMI record. They are eligible and have chosen not to, which is worth remembering before you treat BIMI as essential.
  • The banks and payment companies in the sample all had certificates. Bank of America, Chase, Wells Fargo, American Express and PayPal each published a BIMI record with a=. Phishing risk is highest for them, and that's where a verified logo arguably earns its fee.
  • Some big brands self-assert. Spotify, Salesforce and Mailchimp publish a logo with no certificate, so Gmail shows nothing for them while Yahoo may.
  • Three domains returned a non-BIMI TXT record for default._bimi (an SPF string, for example) because their DNS has a wildcard. If you check your own domain and see something odd, that's probably why. It isn't a BIMI record.

Forty domains is a sample, not a census. A larger sample is in our BIMI adoption study.

Setting it up

  1. Reach DMARC enforcement on your organisational domain, and on any subdomain you send from, at pct=100 (or with pct omitted). Check it with our DMARC checker.
  2. Produce the SVG. Google notes "there are no applications to create an SVG file that meets all BIMI requirements" and that files typically need editing by hand. Export from your design tool, then set version="1.2" and baseProfile="tiny-ps" on the root element, remove x= and y= attributes there, add a <title>, and strip anything external. Put the logo on a solid square background. The BIMI Group publishes conversion and checking tools.
  3. Get the certificate (VMC or CMC). The issuer validates your organisation and your right to the mark, and returns a PEM file. Your SVG is embedded in the certificate, so the logo you host must match it.
  4. Host both files over HTTPS at stable URLs. Check the SVG is served as image/svg+xml.
  5. Publish the TXT record at default._bimi.yourdomain.
  6. Send to Gmail and Yahoo test accounts and look. Display is at each provider's discretion. The BIMI Group's own FAQ notes that "Each participating mailbox provider has their own criteria," and reputation plays a part, so a correct setup may not show a logo straight away.

Is it worth it? A decision table

Your situation Our view
DMARC still at p=none Not yet. Put the effort into reaching enforcement, which protects your domain whether or not a logo appears
At enforcement, registered trademark, consumer-facing brand often impersonated Yes. A VMC with Gmail's checkmark is the strongest version, and phishing targets benefit most
At enforcement, no trademark, logo on your site for 12+ months and archived Reasonable, via CMC, if your audience is mostly on Gmail and recognises your logo
At enforcement, mostly sending one-to-one B2B or cold email Low priority. Recipients are judging the sender's name and the message, and a CMC fee buys little
Brand-new domain or logo Wait. A CMC needs 12 months of archived history

The honest summary from the BIMI Group's own FAQ is that BIMI "does not change message delivery". It's a display signal. The real value of a BIMI project is that it forces DMARC enforcement, the part that actually stops someone sending mail as you. Check where you stand with our free deliverability audit.

Common questions

Do I need a trademark for BIMI?

Not any more, for Gmail. A Verified Mark Certificate (VMC) needs a registered trademark, but a Common Mark Certificate (CMC), which Gmail has accepted since September 2024, can be issued for a logo you have displayed on your own website for at least 12 months, verified through archive.org.

Does BIMI improve deliverability?

The BIMI Group itself says BIMI does not change message delivery and is a display signal on top of authentication. Its practical deliverability benefit is indirect: you must reach DMARC enforcement first, and that work protects your domain from spoofing whether or not a logo ever appears.

What DMARC policy does BIMI require?

p=quarantine or p=reject. Google's BIMI documentation says p=none is not supported and that pct must be 100. A policy in testing mode, such as pct=0 or the newer t=y, does not count as enforcement.

Can I use BIMI without a certificate?

Yes, at some providers. The BIMI Group lists Yahoo, Fastmail and La Poste as supporting self-asserted logos, published with no certificate. Gmail will not show a logo without a VMC or CMC.

Why do I see a blue checkmark next to some senders in Gmail?

Google's BIMI documentation says Gmail shows a checkmark next to senders verified with a VMC. Senders using a CMC can get their logo displayed but not the checkmark.

Verify unlimited addresses for $29.99/month

Real SMTP mailbox checks. No credits, no per-email fees.

Get Started