How do you set up BIMI for your email domain?

White envelope with verified sender shield and gold wax seal on a modern desk, surrounded by professional stationery in navy and gold tones.

Setting up BIMI for your email domain involves publishing a special DNS TXT record that points to a hosted, BIMI-compliant SVG version of your logo. Before that record does anything visible, you need a fully authenticated sending domain with DMARC enforcement in place. This guide walks through each step, from prerequisites to troubleshooting, so you can get your brand logo displaying in supported inboxes.

What do you need before setting up BIMI?

Before you can implement BIMI, your domain must have SPF, DKIM, and DMARC authentication fully configured, with DMARC set to either a quarantine or reject policy. A DMARC policy of p=none is not sufficient. Without enforcement-level DMARC, mailbox providers will simply ignore your BIMI record entirely.

Here is a checklist of what you need in place before moving forward:

  • SPF record: A valid SPF record published in your DNS that authorizes your sending sources
  • DKIM signing: All outgoing mail signed with a DKIM key aligned to your domain
  • DMARC policy: A DMARC record set to p=quarantine or p=reject with consistent alignment
  • A hosted SVG logo: Your logo file must be publicly accessible via an HTTPS URL
  • A clean sender reputation: Mailbox providers use BIMI as a reward for trustworthy senders, so your domain’s sending history matters

If your DMARC policy is still at the monitoring stage, prioritize moving it to enforcement first. BIMI implementation is the final layer in a well-built email authentication stack, not a shortcut through it.

How do you create a BIMI-compliant SVG logo?

A BIMI-compliant SVG logo must follow the SVG Tiny Portable/Secure (SVG P/S) profile, a strict subset of the standard SVG format. Not every SVG file qualifies. The file must be square, contain no embedded scripts or external references, and meet specific structural requirements defined by the BIMI Working Group.

Key requirements for your SVG file include:

  • The file must conform to the SVG Tiny 1.2 P/S specification
  • The root element must include the correct namespace and title elements
  • The image must have a 1:1 aspect ratio (square format)
  • No external fonts, scripts, animations, or linked resources are permitted
  • The logo should be on a solid or transparent background, centered within the viewBox

Most standard SVG exports from design tools like Adobe Illustrator or Figma will not meet these requirements out of the box. You will need to manually clean the file or use a dedicated BIMI SVG converter tool to validate and reformat it. Once your SVG is ready, host it on a publicly accessible HTTPS URL, ideally on your own domain.

How do you publish a BIMI DNS record?

To publish a BIMI record, you add a DNS TXT record to your domain under the subdomain default._bimi. The record follows a straightforward format and points to the URL where your SVG logo is hosted. Once published, mailbox providers can look up the record and retrieve your logo for display.

The basic structure of a BIMI DNS record looks like this:

Name: default._bimi.yourdomain.com
Value: v=BIMI1; l=https://yourdomain.com/logo.svg;

If you have a Verified Mark Certificate (VMC), you add a second parameter to the record pointing to your certificate file. Without a VMC, the a= tag is either omitted or left empty. After publishing, DNS propagation typically takes between a few minutes and 48 hours. Most providers will begin checking the record once propagation completes.

Do you need a Verified Mark Certificate for BIMI?

A Verified Mark Certificate is not required for all mailbox providers, but it is required for Gmail and is increasingly expected by others. Without a VMC, some providers like Apple Mail may still display your logo, but Gmail will not show the blue verified checkmark indicator and may not display the logo at all, depending on their current policy.

A VMC is a digital certificate issued by an authorized Certificate Authority (such as Entrust or DigiCert) that cryptographically ties your logo to your trademarked brand. To obtain one, your logo must be a registered trademark in the relevant jurisdiction. The process involves:

  • Confirming your logo is an active registered trademark
  • Submitting your BIMI-compliant SVG to the Certificate Authority for validation
  • Completing identity and trademark verification
  • Receiving and hosting the .pem certificate file at a public HTTPS URL
  • Updating your BIMI DNS record to include the a= tag pointing to that certificate

The cost and timeline for a VMC vary depending on the Certificate Authority and the complexity of your trademark verification. For brands that rely heavily on Gmail deliverability or want the verified checkmark trust signal, the VMC is worth pursuing.

How do you test and verify your BIMI setup?

After publishing your BIMI DNS record, you should verify the setup using dedicated BIMI lookup tools before sending any campaigns. Testing confirms that your DNS record is correctly formatted, your SVG is accessible and compliant, and your DMARC policy meets the threshold required by mailbox providers.

Useful approaches for testing your BIMI implementation include:

  • Use a BIMI Inspector tool (several are available from email authentication providers) to validate your DNS record syntax and SVG file
  • Send a test email to a Gmail or Yahoo address and check whether the logo appears in the sender field
  • Run a DMARC check to confirm your policy is at enforcement level and that alignment is passing
  • Verify that your SVG URL returns a valid response over HTTPS with no redirect issues

If your VMC is in place, also confirm the certificate file is accessible at the URL specified in your DNS record. A broken link to either the SVG or the VMC will silently prevent logo display without generating an obvious error.

Why isn’t your BIMI logo showing up in Gmail or Yahoo?

If your BIMI logo is not appearing in Gmail or Yahoo, the most common reasons are a DMARC policy that has not reached enforcement, an SVG file that does not meet the SVG P/S specification, or a missing or invalid VMC for Gmail. Each of these issues will silently block logo display without notifying the sender.

Work through this diagnostic checklist to identify the cause:

  • DMARC not at enforcement: Confirm your policy is p=quarantine or p=reject, not p=none
  • SVG format issues: Re-validate your SVG against the SVG Tiny P/S specification using a BIMI SVG validator
  • Missing VMC for Gmail: Gmail requires a VMC to display the logo; without it, the logo will not appear regardless of other settings
  • HTTPS hosting problems: Confirm your SVG and VMC URLs are publicly accessible, return a 200 status, and are served over valid HTTPS
  • DNS propagation delay: If you recently published or updated your record, allow up to 48 hours before expecting results
  • Sender reputation: Mailbox providers may withhold BIMI display for domains with poor sending history even when technical requirements are met

Yahoo and Apple Mail have somewhat more lenient requirements than Gmail and may display your logo without a VMC. If your logo appears in those clients but not Gmail, the VMC is almost certainly the missing piece.

How Email Industries helps with BIMI implementation

Getting BIMI right requires more than just publishing a DNS record. It depends on a solid authentication foundation, a properly formatted logo, and in many cases a verified certificate that ties your brand to a registered trademark. We help businesses navigate every layer of this process, including:

  • Auditing and hardening your SPF, DKIM, and DMARC configuration to meet BIMI prerequisites
  • Reviewing and validating your SVG logo for compliance with the SVG Tiny P/S specification
  • Guiding you through the VMC application process and coordinating with Certificate Authorities
  • Publishing and verifying your BIMI DNS record across your sending domains
  • Diagnosing display failures in Gmail, Yahoo, and other supported mailbox providers

Our Deliverability Assurance Packages cover the full authentication stack, from foundational setup through advanced brand protection. If your BIMI logo still is not showing up or you want to make sure everything is configured correctly from the start, contact us and we will take a look at what is standing in the way.

Related Articles

Share the Post

Related Posts

The Best Senders Read This – Do You?

Get expert-backed strategies, real-world case studies, and insider email deliverability tips straight to your inbox. Join the Inbox Insiders.