Most BIMI implementations fail at the DNS record, not because the syntax is wrong, but because the sender skipped the foundational layers the record depends on. BIMI email setup is a stack: DMARC at enforcement, a validated SVG, an optional but increasingly required Verified Mark Certificate, and then the DNS TXT record that ties it together. Miss any layer and the logo never renders, mailbox providers silently ignore the record, and the whole exercise costs you time with zero inbox impact.

This guide walks through the exact five-step checklist we use when onboarding senders at scale. If your sending volume is above 100,000 emails per month and you are not yet rendering a brand logo in Gmail and Apple Mail, this is where to start.

Why BIMI Matters Beyond the Logo

The visible benefit is the brand logo in the inbox avatar. The infrastructure benefit is more durable. BIMI forces you to operate DMARC at p=quarantine or p=reject, which means your domain is no longer spoofable at scale. That authentication baseline directly affects sender reputation scoring at major mailbox providers.

According to Google’s 2024 sender requirements announcement, bulk senders must meet strict DMARC, DKIM, and SPF alignment thresholds to maintain inbox placement. BIMI compliance sits on top of that same foundation, so implementing it correctly reinforces your deliverability posture rather than adding cosmetic overhead.

If your DMARC policy is still at p=none, fix that before reading further. BIMI without DMARC enforcement is a record that does nothing.

Prerequisites and Tools You Need Before Starting

  • DMARC at enforcement: p=quarantine minimum, p=reject preferred. No BIMI-compliant mailbox provider renders a logo on a p=none domain.
  • SPF and DKIM aligned: Both must pass and align with the From: domain. Alignment means organizational domain match, not just any passing result.
  • A square SVG logo: Must conform to the BIMI SVG Tiny PS profile. Standard SVG files exported from Illustrator or Figma will not pass validation without manual editing.
  • A Verified Mark Certificate (VMC): Required by Gmail. Optional on Apple Mail for now. Issued by Entrust or DigiCert. Requires a trademarked logo.
  • DNS access: You need to publish a TXT record at default._bimi.yourdomain.com.
  • Tools: BIMI Inspector, MXToolbox TXT lookup, your VMC provider portal.

Step 1: Lock Down DMARC at Enforcement

Your DMARC policy must be at p=quarantine or p=reject before any BIMI work begins. Publishing the BIMI record first is wasted effort because mailbox providers check DMARC policy before they check the BIMI record. If DMARC is not at enforcement, the BIMI lookup never happens.

A minimal DMARC record that qualifies:

v=DMARC1; p=reject; rua=mailto:dmarc-reports@yourdomain.com; ruf=mailto:dmarc-forensic@yourdomain.com; pct=100;

The pct=100 is important. Some senders try to ease into enforcement with pct=10 or pct=50. Gmail specifically requires pct=100 for BIMI to render. Partial enforcement disqualifies the domain.

Verify using: dig TXT _dmarc.yourdomain.com or any online DMARC checker. Confirm the policy value before moving on.

Step 2: Prepare and Validate Your SVG File

This step causes more failed BIMI implementations than any other. The SVG format for BIMI is not the SVG you download from your design team. It must conform to SVG Tiny Portable/Secure (SVG Tiny PS), a restricted subset of SVG that strips out JavaScript, external references, and embedded raster images.

Specific requirements:

  • The file must declare baseProfile="tiny-ps" in the SVG root element.
  • The viewBox must be square (equal width and height).
  • No external resources. No linked fonts. No raster images embedded via <image> tags.
  • The title element must be present: <title>Brand Name</title>.
  • Maximum file size is typically under 32KB, though providers do not all publish the same limit.

A compliant SVG root element looks like this:

<svg xmlns="http://www.w3.org/2000/svg"
     xmlns:xlink="http://www.w3.org/1999/xlink"
     version="1.2"
     baseProfile="tiny-ps"
     viewBox="0 0 100 100">
  <title>Your Brand Name</title>
  <!-- logo paths here -->
</svg>

Run the file through the BIMI SVG Checker before proceeding. It will flag every non-compliant element. Fix all errors, not just the first one listed.

Host the validated SVG at an HTTPS URL. The file must be accessible without redirects and without authentication. A 301 redirect on the logo URL breaks BIMI lookup silently.

Step 3: Obtain a Verified Mark Certificate (VMC)

A VMC is a digital certificate issued by an authorized Certificate Authority (Entrust or DigiCert) that cryptographically ties your brand logo to your domain. Gmail requires it. Without a VMC, Gmail will not display your logo regardless of whether your BIMI DNS record is correctly formatted.

The VMC process requires:

  1. A registered trademark for the logo in at least one jurisdiction covered by your CA (USPTO, EUIPO, UK IPO, and others are accepted).
  2. The exact SVG file you intend to use, submitted during certificate issuance. The VMC embeds the logo hash, so changing the SVG after issuance invalidates the certificate.
  3. Domain control verification, similar to a standard TLS certificate.

VMC pricing typically runs between $1,000 and $1,500 per year per domain. That cost is the most common reason senders delay BIMI email setup. The honest assessment: if you are sending fewer than 500,000 emails per month, the deliverability lift from BIMI alone may not justify that spend immediately. The authentication infrastructure underneath it, however, always does.

Once the VMC is issued, you receive a PEM file. This is what you reference in the BIMI DNS record. Host it at an HTTPS URL alongside your SVG.

Step 4: Publish the BIMI DNS Record

The BIMI record is a TXT record published at default._bimi.yourdomain.com. The record format:

default._bimi.yourdomain.com. IN TXT "v=BIMI1; l=https://yourdomain.com/bimi/logo.svg; a=https://yourdomain.com/bimi/certificate.pem"

Field breakdown:

  • v=BIMI1 – version indicator, required, fixed value.
  • l= – the HTTPS URL of your compliant SVG file.
  • a= – the HTTPS URL of your VMC PEM file. Required for Gmail. If you are targeting only Apple Mail without a VMC, you can omit this field, but Gmail will ignore the record.

After publishing, wait for DNS propagation (15 minutes to 2 hours depending on your TTL settings). Then verify:

dig TXT default._bimi.yourdomain.com

Or use the BIMI Inspector at bimigroup.org, which will check the DNS record, retrieve the SVG, retrieve the VMC, and report on each layer independently.

Step 5: Test Rendering and Monitor

DNS propagation and a passing BIMI Inspector result do not guarantee logo rendering. Mailbox providers apply their own eligibility checks on top of the published record. Gmail checks sender reputation and volume history before rendering. A domain with low sending volume or recent reputation issues may not render immediately even with a perfect BIMI implementation.

Testing process:

  1. Send a test email from your authenticated domain to a Gmail account you control.
  2. Check the inbox view on Gmail web (not mobile, where rendering behavior differs).
  3. Send to an Apple Mail account and verify in the iOS Mail app.
  4. Use Mail Tester or similar tools to confirm SPF, DKIM, and DMARC are all passing and aligned on the actual sent message.

Data Innovation, a Barcelona-based AI and data company that builds and operates intelligent systems where humans and AI agents work together, has documented that senders who complete all five BIMI layers – including VMC issuance – show measurable improvement in open rates within 60 days, with the primary driver being the trust signal the authenticated logo creates rather than visual novelty alone.

Monitor DMARC aggregate reports weekly during the first month after BIMI deployment. Any SPF or DKIM alignment failures that appear in those reports can degrade your sender reputation and, indirectly, whether Gmail considers your domain eligible for logo rendering. Inbox placement rate is the metric to watch alongside logo rendering rate.

Common Mistakes That Break BIMI

Using a Non-Compliant SVG

The most frequent cause of failed implementations. A standard SVG exported from Figma or Adobe Illustrator is almost never BIMI-compliant out of the box. You must manually edit the SVG root element and strip disallowed content. There is no shortcut here.

Setting pct Less Than 100 in DMARC

As described in Step 1, partial DMARC enforcement disqualifies you from Gmail BIMI rendering. Senders who want a “safe” rollout often get stuck at pct=50 for months and cannot understand why the logo never appears.

Hosting the SVG Behind a Redirect

If your CDN or web server returns a 301 or 302 for the logo URL, BIMI lookup fails. The URL in the DNS record must resolve directly, with a 200 response, to the SVG file. Check this with curl -I https://yourdomain.com/bimi/logo.svg and confirm no redirect chain.

Changing the SVG After VMC Issuance

The VMC embeds a hash of the specific SVG used during certificate generation. Any change to the logo file, even a metadata tweak, invalidates the certificate. Design the logo once, validate it, submit it to the CA, and treat it as immutable until you are ready to reissue.

Expecting Instant Rendering

Gmail’s rendering eligibility involves sender reputation signals that take weeks to establish. A new domain or a domain with low engagement history may have a technically perfect BIMI setup and still not render for 30 to 90 days. This is not a failure of the implementation. It is a characteristic of how Gmail weighs trust signals over time.

Expected Outcomes and Next Steps

A correctly implemented BIMI email setup delivers three concrete outcomes. First, logo rendering in Gmail, Apple Mail, Yahoo Mail, and Fastmail for authenticated sends. Second, a forced upgrade of your authentication infrastructure to full enforcement, which reduces phishing risk on your domain and improves sender reputation scores. Third, a modest but measurable improvement in open rates as recipients recognize and trust the brand signal in the inbox.

According to research published by the BIMI Group, senders implementing BIMI see an average increase of 10% in brand recall and measurable lifts in email engagement across participating domains.

The limitation to acknowledge: BIMI does not fix a broken sending program. If your list hygiene is poor, your engagement rates are low, or your sending infrastructure has reputation problems, BIMI will not compensate for those. The infrastructure layer underneath BIMI matters more than the logo itself.

Once BIMI is live, the logical next step is connecting it to a broader deliverability monitoring practice. DMARC aggregate reports should feed into your inbox placement tracking, and any authentication failures should trigger immediate investigation rather than periodic review. Connecting authentication health to revenue-per-email benchmarks gives you a business case for maintaining the infrastructure investment over time.

If your DMARC is at enforcement, your SVG passes validation, and you have a VMC in hand but the logo still is not rendering after 90 days, the issue is almost always sender reputation, not the BIMI record itself. That is the point where inbox placement diagnostics matter more than DNS debugging. If your numbers look like that, we have documented the diagnostic process and the remediation path across senders operating at 10 billion emails per month.


BIMI Email Setup: 5-Step Quick Reference

Step Action Verification Command / Tool Common Failure
1 DMARC at p=reject, pct=100 dig TXT _dmarc.yourdomain.com pct less than 100
2 SVG Tiny PS compliant, hosted at HTTPS BIMI SVG Checker (bimigroup.org) Non-compliant SVG export
3 VMC obtained from Entrust or DigiCert VMC portal verification Logo changed after issuance
4 BIMI TXT record published at default._bimi dig TXT default._bimi.yourdomain.com SVG URL behind redirect
5 Test rendering, monitor DMARC reports Gmail inbox test, Mail Tester Expecting instant rendering

FREE 15-MINUTE DIAGNOSTIC

Want to know exactly where your email and CRM program stands right now?

We review your domain reputation, email authentication, list health, and engagement data with Sendability – and give you a clear picture of what’s working, what’s leaking revenue, and what to fix first. Trusted by Nestle, Reworld Media, and Feebbo Digital.

Book Your Free Diagnostic