BIMI Setup Guide: How to Add Your Brand Logo to Emails

🕐 ✍️ Sandeep Saxena🗂️ Email Deliverability, Email AuthenticationUpdated

BIMI Setup Guide: how to add your brand logo to emails - the DNS record, SVG rules, VMC vs CMC, and what Gmail, Yahoo and Apple Mail show.

BIMI - Brand Indicators for Message Identification - is the standard that puts your logo next to your emails in the inbox, and in Gmail's case can add a blue verified checkmark beside your name. Marketing teams want it for the brand impressions. Security teams should want it for a sneakier reason: BIMI is the only email standard that pays you to finish your DMARC rollout.

This guide covers what BIMI actually requires in 2026 (the certificate landscape changed meaningfully), which mailbox providers show what, the record and SVG rules, the failures that keep valid-looking setups from ever displaying a logo - and an honest answer to whether you need it at all.

What BIMI actually is

Gmail mobile app showing an HDFC Bank email with the round HDFC logo as the sender avatar and a blue verified checkmark next to the sender name
HDFC Bank has earned this spot: its logo and the blue verified checkmark sit right beside the sender name. In one glance a customer knows the email is really from their bank - that is trust, built straight into the inbox (Gmail mobile).

Technically, BIMI is one DNS TXT record that points to your logo:

Host:   default._bimi.yourdomain.com
Type:   TXT
Value:  v=BIMI1; l=https://yourdomain.com/logo.svg; a=https://yourdomain.com/vmc.pem

The l= tag is the logo (a strictly-profiled SVG, more below). The a= tag is the certificate that proves the logo is really yours - required by some providers, ignored by others. Receivers that support BIMI look this record up after your message has already passed authentication, and only then consider showing the logo.

That word "after" is the entire story. BIMI displays nothing unless your domain first passes DMARC at enforcement. The logo is a reward for authentication done properly.

Here is what a live record looks like when you inspect it. Two real Indian banks, pulled with our free BIMI lookup - the record, the published SVG logo it renders, and the certificate behind it:

BIMI Lookup result for hdfcbank.bank.in showing record found, the HDFC logo rendered, and a Verified Mark Certificate
Behind that badge is real security. HDFC Bank publishes a BIMI record and a Verified Mark Certificate - independent proof it truly owns its logo - so no imposter can wear the HDFC identity (certificate hosted via ProGist).
BIMI Lookup result for sbi.co.in showing record found, the SBI logo rendered, and a Verified Mark Certificate issued by GlobalSign
SBI has taken the same careful step - a Verified Mark Certificate from GlobalSign vouches that the logo is genuinely theirs. The l= tag points to the logo and the a= tag to the certificate: a small piece of DNS that earns a big signal of trust.

The gate: what you must already have

  • SPF and DKIM set up, with at least one aligned to your From domain.
  • DMARC at enforcement: p=quarantine or p=reject. p=none disqualifies you, full stop.
  • No watered-down policy: pct must be 100 (the default - just do not set it lower), and your subdomain policy must not relax to sp=none.
  • Sender reputation: providers - Yahoo especially - only show logos for senders with established good reputation. BIMI is not a trust bootstrap; it is a trust decoration.

Not sure where your DMARC actually stands? A free Spoof Check reads your live SPF, DKIM and DMARC posture in seconds, and free DMARC monitoring shows you every sender that would break if you moved to quarantine - which is exactly the homework BIMI forces.

Who shows what in 2026

ProviderShows BIMI logo?Certificate neededBlue checkmark
GmailYesVMC or CMCVMC only
Apple Mail (recent iOS & macOS)YesVMC onlyn/a
Yahoo Mail (incl. AOL)YesNone requiredn/a
FastmailYesCert-basedn/a
La Poste, AU (KDDI), ZoneYesvariesn/a
Outlook / Microsoft 365No--

The BIMI Group maintains the authoritative list of participating providers (Apple, Gmail, Yahoo, Fastmail, La Poste, AU/KDDI and Zone at time of writing). Two things jump out. First, Microsoft does not participate - if your audience lives in Outlook, BIMI buys you nothing there. Second, Yahoo will show your logo without any certificate once DMARC is at enforcement and your reputation is decent - the cheapest way to see BIMI working before you spend a rupee on certificates.

Where the logo actually appears (test in the right place)

Which surface shows the logo varies by client, and this trips people up constantly. In practice: the mobile apps (Gmail, Apple Mail, Yahoo) show it in both the inbox list and the open message; on desktop, you will reliably see it in the open-message header, but some desktop webmail - Gmail's included - does not render the logo in the inbox list at all, regardless of display density. So if you are checking your own setup and see nothing in the desktop list, that is not a broken BIMI record - open a message, or check the mobile app.

Desktop Gmail in Chrome showing an open SBI email with the SBI logo and a blue verified checkmark beside the sender name
The reward follows customers everywhere - SBI's logo and blue checkmark on desktop Gmail too, right inside the open message. World-class email security that quietly reassures every recipient, on every screen (Chrome, desktop).

VMC vs CMC: the certificate decision

The certificate landscape split in 2025, and this is where most older articles are now wrong:

  • VMC (Verified Mark Certificate): requires a registered trademark for your logo. Issued by DigiCert, Entrust, GlobalSign, Sectigo or SSL.com. Pricing runs from roughly $750/year through authorized resellers up to about $1,350-1,550/year direct from the CA. Unlocks everything: Gmail logo plus blue checkmark, and Apple Mail.
  • CMC (Common Mark Certificate): the newer, cheaper path - no trademark needed. You instead prove the logo has been in genuine public use on your domain for at least 12 months (validated against web archives). Now issued by several CAs including DigiCert, Sectigo and SSL.com, roughly $650-1,150/year - cheaper than a VMC across the board. Gets you the Gmail logo, but no blue checkmark and no Apple Mail.

The BIMI Group maintains the authoritative list of qualified certificate issuers - check it before buying, since the issuer set can grow. The decision tree is short: trademark and budget then VMC, everything everywhere. No trademark then CMC for Gmail, free Yahoo either way, and accept that Apple shows nothing. No certificate at all then Yahoo only.

The SVG that keeps getting rejected

The logo file is not "an SVG" - it is SVG Tiny 1.2 Portable/Secure, a deliberately restricted profile:

  • Root element must declare baseProfile="tiny-ps".
  • Square aspect ratio, centered artwork (it will be cropped into circles by some clients).
  • A <title> element naming your brand.
  • No scripts, no external references, no embedded raster images.
  • Served over HTTPS from a URL that stays up forever.

Illustrator, Figma and friends do not export this profile - their standard SVG output fails validation. Export normally, then convert (the BIMI Group publishes tooling and validators for exactly this step).

The failures that keep logos from showing

1. DMARC is technically present but not enforcing. p=none, or p=quarantine; pct=10, or an sp=none escape hatch for subdomains. Providers read the policy strictly; any relaxation disqualifies the domain.

2. The SVG is the wrong profile. A designer's standard export - works in the browser, fails BIMI validation, and the logo silently never appears. Validate the file, not your eyes.

3. The record is on the wrong name. It lives at default._bimi on the exact From domain. Sending from mail.yourdomain.com? The lookup happens there, not at the apex (unless the receiver falls back). Match the record to the domain your readers see.

4. Certificate and logo disagree. The SVG served at l= must be the same artwork embedded in the VMC or CMC. Rebrand the logo file without reissuing the certificate and display stops.

5. Reputation is not there yet. Everything validates, and Gmail still declines to show the logo for weeks. This is normal for newer domains or recently-cleaned senders - BIMI rides on reputation, it does not create it.

Should you bother?

Honest answer, segmented:

  • Consumer brands sending volume to Gmail/Yahoo/Apple inboxes: yes. The impression lift is real, the anti-phishing signal is real, and you have the most to lose from lookalike spoofing.
  • B2B senders whose audience lives in Outlook: the logo will mostly never be seen. Do BIMI last - but note that everything BIMI would force you to do (DMARC enforcement) you should do anyway, for security rather than vanity.
  • Small senders without a trademark: the CMC route plus free Yahoo display makes BIMI genuinely reachable now - this was not true two years ago.

The real takeaway: even if you never buy a certificate, walking the BIMI checklist leaves your domain at DMARC enforcement with aligned SPF and DKIM - which is the actual prize. The logo is the bribe the industry invented to get senders there.

Who can help you implement BIMI

BIMI looks like one DNS record, but the work underneath it - taking SPF, DKIM and DMARC to enforcement without breaking legitimate mail, producing a compliant SVG, and choosing and validating the right VMC or CMC certificate - is exactly where most in-house attempts stall. If you would rather have it done right the first time, that is what we do.

Postbox Consultancy Services is an email deliverability and security consultancy based in India, working with senders in India and worldwide. We implement BIMI end to end: we take your domain to DMARC enforcement safely, guide the certificate process, validate the SVG logo, publish the record, and confirm the logo renders across Gmail, Yahoo and Apple Mail. If you are searching for a BIMI consultant in India - or anywhere - see our BIMI implementation service or talk to our team, or start with a free Spoof Check to see exactly where your domain stands today.

Check where you stand, free

In order: BIMI lookup (is your record and SVG resolvable?), then Spoof Check (is DMARC actually at enforcement?), then DMARC monitoring (which senders break if you enforce?), then Postbox Mailtester (full authentication audit on a real email).

Also worth reading: our step-by-step Microsoft 365 DKIM and Google Workspace DKIM guides - DKIM is part of the DMARC foundation BIMI depends on.

Frequently asked questions

Does BIMI improve deliverability?
Not directly - no provider ranks mail higher for having BIMI. Indirectly, yes: the DMARC enforcement it requires is a deliverability and security upgrade, and visible logos measurably lift opens, which feeds engagement signals.

Can I do BIMI without any certificate?
Yes, partially: Yahoo (and AOL) display logos from the DNS record alone once DMARC enforcement and reputation are in place. Gmail and Apple require a certificate.

What is the difference between VMC and CMC?
VMC needs a registered trademark and unlocks Gmail's blue checkmark plus Apple Mail. CMC needs no trademark - proof of 12 months' public logo use instead - and gets the Gmail logo only.

Why is my logo not showing even though everything validates?
Usually reputation or time - providers apply their own trust thresholds and caching. If the record, SVG profile and DMARC policy all check out, give it days to weeks, keep volume consistent, and re-test. Also confirm you are testing on a surface that displays it: the mobile app or an opened message, not the desktop inbox list.

Does Outlook support BIMI?
No. Microsoft has not adopted BIMI in Outlook or Microsoft 365 as of 2026.

Who can help us implement BIMI?
Implementing BIMI spans DNS, DMARC enforcement, certificate validation and SVG production, so it is usually handled by an email deliverability consultancy rather than a general web or IT provider. Postbox Consultancy Services implements BIMI end to end for senders in India and worldwide - from taking your domain to DMARC enforcement through to the logo rendering in the inbox. Get in touch to start.

Is there a BIMI consultant in India?
Yes. Postbox Consultancy Services is an India-based email deliverability and security consultancy that implements BIMI, DMARC and the supporting SPF and DKIM authentication for businesses in India and internationally.

Chat with us!