/ TL;DR
BIMI shows your verified logo next to your name in supported inboxes, but only on mail that authenticates under an enforced DMARC policy. The setup is four parts: DMARC at quarantine or reject, an SVG Tiny P/S logo hosted over HTTPS, a BIMI DNS record, and — for some inboxes — a certificate.
The certificate decision is the whole game. Self-asserted BIMI needs no certificate and displays in Yahoo, AOL, and Fastmail. A CMC skips the trademark requirement and unlocks the Gmail logo, though not the blue checkmark. A VMC needs a registered trademark and is what lights the Gmail checkmark and Apple Mail. Expect a certificate to cost roughly 750 to 1,700 dollars a year.
Start with self-asserted to prove the chain works, then add a certificate for the inboxes your audience actually uses. DMARC enforcement is the gate — nothing shows until you're past p=none.
/ 01
What BIMI is, and what changed
BIMI — Brand Indicators for Message Identification — is the standard that puts your logo next to your emails in the inbox. When a message from your domain authenticates and aligns under DMARC, a supporting mailbox provider fetches the logo you've published in DNS and shows it beside your name, before the recipient opens anything. It's a visible trust signal earned by authentication, and because the logo appears only on mail that passes your enforced policy, it makes visually impersonating your brand meaningfully harder. One honest caveat on that signal: Gmail also lets any user set a profile picture with no verification at all, and it surfaces in the same spot a BIMI logo would — so a certificate-backed, verified logo is what truly distinguishes you from someone who merely uploaded your logo as their own account avatar to appear legitimate.
For years BIMI had a hard ceiling: to display in Gmail, the big prize, you needed a Verified Mark Certificate, and that required a registered trademark. Plenty of legitimate organizations don't have a trademarked logo, or are mid-rebrand, or simply don't want to spend the year-plus that trademark registration can take. That requirement kept BIMI a large-enterprise feature and left everyone else with logos only in Yahoo.
The change that makes 2026 the year to revisit BIMI is the Common Mark Certificate. Introduced across 2024 and 2025 and now supported by Gmail, the CMC removes the trademark requirement — you prove instead that you've publicly used the logo on your domain for at least twelve months, verified through archives. That single change widened BIMI's practical eligibility enormously: a business with an established logo and no trademark can now get that logo showing in Gmail. The rest of this guide is the path from nothing to a displayed logo, and the honest decision points along the way.
/ 02
The four prerequisites
BIMI sits on top of a stack, and every layer below it has to be solid first. There are four prerequisites, and skipping the order is the single biggest cause of wasted effort.
The first and most important is DMARC at enforcement. Your domain needs SPF or DKIM passing and aligned, and a DMARC policy of p=quarantine or p=reject covering all your mail. A record at p=none does not qualify — no mailbox provider will process a BIMI record for a domain still in monitoring mode, because the whole point of the logo is to reward a sender who is actively blocking spoofed mail. If you're not yet at enforcement, that's the real project; BIMI is the reward at the end of it.
The second is a compliant logo: your artwork converted to the SVG Tiny P/S profile, square and clean, which is strict enough that most exported SVGs fail it. The third is HTTPS hosting — the logo, and later the certificate, must sit on a stable public server reachable over HTTPS with the correct content type. The fourth is the BIMI DNS record itself, a TXT record pointing at the logo and optionally the certificate.
Notice the sequence: enforcement first, logo and hosting next, record last, certificate in parallel once the trademark or usage proof is ready. Our authentication guide covers getting from p=none to enforcement without breaking mail, and the DMARC checker confirms where your policy stands right now.
/ 03
Preparing the SVG logo
BIMI doesn't accept an ordinary SVG. It requires SVG Tiny P/S — a locked-down, portable-and-secure subset that mailbox providers can render safely and identically. A logo exported from a design tool is valid SVG and almost always fails Tiny P/S, because it carries the very things the profile bans: scripts, animation, external references, embedded raster images, editor metadata, or a canvas that isn't a square starting at the origin. Any one of those is a rejection, and the failure mode is silent — the logo simply doesn't appear.
The specific requirements are worth knowing so you can hand your designer a real brief. The file must declare version 1.2 and the tiny-ps base profile, use a square viewBox that starts at 0 0, carry a title element describing the logo, and contain no scripts, external links, or raster images. There's no pixel dimension to optimize for the way a favicon has one; instead the artwork has to read clearly when shrunk to roughly 20 to 40 pixels and cropped into a circle or rounded square, so simple, bold, centered artwork wins and fine detail disappears.
You don't have to wrestle this by hand. Our SVG to BIMI converter takes a normal SVG and rewrites it into a compliant Tiny P/S file — stripping the forbidden elements, squaring and centering the viewBox, and adding the title — with a before-and-after preview so you can see the crop. Once you have a candidate, the BIMI generator and validator checks it against the rules and builds the record. Get the logo right before you spend anything on a certificate, because a non-compliant SVG fails at every provider regardless of what certificate backs it.
/ 04
VMC vs CMC vs self-asserted
This is the decision that shapes your whole rollout, so it's worth being precise. There are three levels of proof you can attach to a BIMI record, and each unlocks a different set of inboxes.
Self-asserted means no certificate at all — you leave the certificate tag empty and simply publish the logo. It costs nothing beyond hosting, and Yahoo, AOL, and Fastmail will display your logo on well-authenticated mail. Gmail and Apple Mail will not. It's the ideal first step: it proves your entire chain works before you spend a cent.
A CMC, the Common Mark Certificate, is the 2024–2025 addition that changed the math. It's a real certificate issued by an authority like DigiCert or Entrust, but instead of a registered trademark it requires proof that you've publicly used the logo on your domain for at least twelve months. A CMC unlocks logo display in Gmail — a genuine milestone — plus Yahoo and others, but it does not trigger Gmail's blue verified checkmark, which stays reserved for the VMC.
A VMC, the Verified Mark Certificate, is the full-strength option: it requires a registered figurative trademark for your logo, and it's what lights up Gmail's blue checkmark and satisfies Apple Mail. It's the strongest trust signal and the most work — trademark registration alone can run many months if you don't already have one. Certificates of either kind carry an annual fee, commonly in the range of about 750 to 1,700 dollars depending on the authority, and you host the issued file yourself.
The clean way to think about it: self-asserted for a Yahoo-first test, CMC when you want the Gmail logo without a trademark, and VMC when the Gmail checkmark or Apple Mail reach justifies the trademark and the cost.
/ 05
Who displays what
The reason the certificate decision matters is that providers diverge sharply on what they'll show, and choosing a certificate before you know your audience's inbox mix wastes money. Here's the 2026 landscape.
Gmail requires a certificate — a CMC displays your logo, and only a VMC adds the blue verified checkmark next to it. There's no self-asserted display in Gmail. Yahoo and AOL are the opposite: they display self-asserted logos with no certificate at all, subject to their own reputation and engagement checks, and a VMC there earns a purple verification mark. Fastmail also shows self-asserted logos, which makes it, like Yahoo, a useful place to confirm a no-certificate rollout is working.
Apple Mail should be treated as certificate territory for planning; don't budget on self-asserted display there. One practical wrinkle at Apple: certificate acceptance can be narrower than at Gmail, so if Apple Mail is central to your audience, confirm your chosen authority is one Apple accepts before purchasing.
The takeaway is to start from your recipient mix, not from the certificate catalog. A business-to-consumer sender with heavy Gmail traffic can't stop at self-asserted and should plan for at least a CMC. A sender whose audience clusters in Yahoo can get most of the visible benefit with no certificate spend at all. Map your list to providers first, then buy only what your inboxes require.
/ 06
Publishing the DNS record
The BIMI record is a single TXT entry, published at the host default._bimi.yourdomain.com. Its structure is simple: a version tag, a logo location, and an optional certificate location. A self-asserted record carries just the version and the logo; a certificate-backed record adds the certificate URL in the evidence tag.
A complete certificate-backed record reads like v=BIMI1; l=https://yourdomain.com/logo.svg; a=https://yourdomain.com/vmc.pem. The l= tag points to the SVG, the a= tag to the certificate PEM file, and for self-asserted you leave a= empty or omit it. Both URLs must be HTTPS, publicly reachable, and served with the right content type, because a provider that can't fetch either one shows nothing.
The host label deserves attention: default._bimi is the selector most senders use, and it must sit under the organizational domain that carries your enforced DMARC and matches your visible From address. The BIMI generator builds the exact record from your logo and certificate URLs so you can hand it to whoever manages your DNS, and re-checks it once it's live.
/ 07
Why the logo isn't showing
Publishing a valid record and seeing no logo is the most common BIMI experience, and the causes fall into a short, ordered list. Work through them in sequence, because the later checks assume the earlier ones pass.
Start with DMARC, because it's the usual culprit. If your policy is still p=none, or if one of your sending sources fails alignment, providers won't process BIMI — a single misaligned vendor stream can suppress the logo across all your mail. Your DMARC aggregate reports are where you find the offender. Next, confirm retrieval: fetch both the logo and, if present, the certificate URL yourself over HTTPS from outside your network, and check the content type is correct — a wrong MIME type, an HTTP link, or anything behind authentication breaks it silently.
Then the logo format: run it through a validator to confirm it's genuinely SVG Tiny P/S, since a file that looks converted can still fail on a stray attribute. After that, provider policy — Gmail needs a certificate you may not have published, and each provider applies its own reputation and volume thresholds before displaying a logo, so a new or low-trust sender may see nothing even with everything technically correct. Finally, caching and propagation: DNS and provider-side checks can lag, so give changes time before concluding they failed.
A disciplined test order saves hours: confirm DMARC alignment across every sender, verify the SVG and certificate resolve externally, validate the logo, then send real messages to Gmail, Yahoo, and Apple Mail and give the providers time to catch up. Verification is ongoing, not a one-time event — a new vendor or a broken alignment can quietly cost you the logo months later, which is why continuous DMARC monitoring is what keeps BIMI lit.
/ 08
Which path to take
For most senders the right sequence is the same, and it front-loads the free, reversible steps. Get to DMARC enforcement first — that's non-negotiable and valuable on its own, logo or not. Convert and validate your SVG. Then publish a self-asserted record and confirm your logo appears in Yahoo and Fastmail. At that point your entire chain is proven working, and you've spent nothing on certificates.
Only then make the certificate decision, and make it from data. Look at what share of your audience is on Gmail and Apple Mail versus Yahoo. If Gmail is a large slice, a CMC is usually the pragmatic buy — it displays your logo there without the trademark hurdle, at a fraction of the total effort of a VMC. Reserve the VMC for when the Gmail blue checkmark or Apple Mail genuinely matters to your brand and you either hold a registered trademark or are willing to pursue one.
What ties all of it together, and what keeps the logo showing after launch, is the authentication posture underneath. BIMI is the visible payoff of enforced DMARC, aligned senders, and a reputation worth trusting — and every one of those has to stay healthy across every service that sends as you, indefinitely. That standing operation, keeping the whole chain aligned and enforced as your sending changes, is what we run.
/ 09 — FAQ