// Engineering Log

DNS configuration for mail and website: Part 4 — BIMI: company logo in email

Published on 2026-09-22

// Fast route

This article belongs to the topic Networking and routing.

BIMI (Brand Indicators for Message Identification) — a standard that allows a mail service to show a company’s logo next to its messages. The logo is tied to the domain via a DNS record, and the right to it is confirmed by a certificate. Not every mail client shows it and not for every sender: BIMI works only on top of configured mail protection and only for services that support it.

What you need for the logo to appear

Gmail’s requirements are the most detailed and strict, so they are a good reference.

  1. SPF, DKIM and DMARC configured. Messages must pass DMARC validation. How these records are structured — in part 2 of the series.
  2. Strict DMARC policy. The p parameter must be quarantine or reject; p=none is not suitable for BIMI. If the record contains pct, it must be 100 — the policy must apply to all messages.
  3. Logo in SVG Tiny PS format with dimensions in absolute pixels, at least 96×96.
  4. VMC or CMC certificate confirming the right to the logo. A standalone SVG file without a certificate is not accepted by Gmail.
  5. A BIMI DNS record with the addresses of the logo and the certificate.

VMC and CMC certificates

  • VMC (Verified Mark Certificate) is issued for a logo registered as a trademark in a patent office recognized by the issuing authorities. In Gmail, a blue verification check appears next to senders with a VMC.
  • CMC (Common Mark Certificate) is an option for those who do not have a registered trademark. The logo is shown in Gmail, but without the checkmark.

Certificates are issued by certificate authorities from the BIMI Group list; as of September 2026 it includes DigiCert, GlobalSign and SSL.com. DigiCert issues both VMC and CMC. Entrust, which was mentioned in earlier BIMI guides, is absent from the current list of issuing authorities.

Certificates are paid, issued for one year and require organizational verification. It is difficult for a Russian company to obtain them: foreign authorities accept payment by cards that do not work in Russia, and the trademark registration must be in an office recognized by the issuing authority.

Where the logo is shown

According to BIMI Group, BIMI is supported by Gmail, Apple Mail, Yahoo, Fastmail, Zoho Mail, La Poste, Onet, Comcast and a number of other services. Apple Mail shows the logo in iOS 16, iPadOS 16, macOS Ventura and newer, and also on iCloud.com; for this a VMC or other proof of brand ownership is required.

No Russian mail services are in the list of BIMI supporters. If your main audience uses Yandex.Mail and Mail.ru, they will not see the logo.

The SVG Tiny Portable/Secure (SVG Tiny PS) format is a reduced SVG without scripts, animation or external references. The profile and version must be specified in the root tag:

xml
<svg xmlns="http://www.w3.org/2000/svg" version="1.2" baseProfile="tiny-ps"
     width="512" height="512" viewBox="0 0 512 512">
  <title>Company name</title>
  <!-- logo content -->
</svg>

Practical requirements:

  • square composition: mail clients show the logo in a circle or square, edges are cropped;
  • solid background, not transparent;
  • a <title> element with the company name;
  • dimensions in pixels, at least 96.

A typical SVG from a graphics editor almost always needs refinement. It’s more convenient to entrust conversion to a designer or use BIMI Group’s validation tools.

The logo file and the certificate (the .pem file issued by the certificate authority) are hosted over HTTPS on your website, for example in the /bimi/ directory.

BIMI DNS record

The record is created for the selector default in the _bimi subdomain:

default._bimi.example.ru.  IN  TXT  "v=BIMI1; l=https://example.ru/bimi/logo.svg; a=https://example.ru/bimi/vmc.pem"
  • v=BIMI1 — version;
  • l= — address of the SVG logo;
  • a= — address of the VMC or CMC certificate.

If the logo is embedded in the certificate, by Google’s example you can leave l= empty and specify only a=. Without a= Gmail will not show the logo.

DNS changes take effect after the previous record’s TTL expires; how to check that the record is visible — in part 3 of the series.

Implementation steps

  1. Verify that all company messages pass SPF and DKIM, including newsletters, CRM messages and invoices from the accounting system.
  2. Enable DMARC with p=none and collect reports for two to four weeks.
  3. Find and fix all legitimate mail sources that fail validation.
  4. Move DMARC to p=quarantine, then to p=reject.
  5. Prepare the logo in SVG Tiny PS and obtain the certificate.
  6. Publish the BIMI record and send a test message to a Gmail address.

Steps 1–4 are useful on their own: a strict DMARC protects the domain from email spoofing, even if you never get to the logo.

Common mistakes

  • DMARC with p=none. The most common reason the logo doesn’t appear.
  • No certificate. A BIMI record and an SVG file alone are not enough for Gmail.
  • SVG not compliant with the Tiny PS profile: contains scripts, external links, has a transparent background or lacks baseProfile="tiny-ps".
  • Logo or certificate not available over HTTPS — for example, protected by authentication or served with a site certificate error.
  • Expecting the logo to appear for Russian recipients. Yandex.Mail and Mail.ru do not support BIMI.

// Similar task

If you are dealing with something similar

This article belongs to one of the main working topics. You can keep reading on the topic, go to the homepage to understand what I do, or open the service pages directly.

Article topic

Networking and routing

MikroTik, VPN, routing, DNS, BGP, connectivity, and access troubleshooting.

Typical tasks behind this topic

  • Set up VPN and secure access to office or cloud
  • Fix routing, DNS, or unstable connectivity
  • Configure MikroTik, firewall, and external links

// Next step

If you need help with this topic, not just another article, it is better to go straight to the service page. The homepage and topic collection stay available as secondary routes.

Open services

// Contact

Need help?

Get in touch with me and I'll help solve the problem

I reply within one business day (03:00-13:00 GMT)

Или оставьте заявку здесь:

Confirm that you are not a bot.

Write and get a quick reply