← Back to blog

BIMI Requirements: SPF, DKIM, DMARC, Logo, and Certificate

August 30, 2026

BIMI can allow a verified brand logo to appear beside messages in supporting inboxes, but it is not a simple image upload. It depends on mature email authentication, a correctly prepared logo, and—in many cases—a verified mark certificate. Treat BIMI as a brand and security project after your core mail controls are reliable.

The non-negotiable DMARC requirement

For Gmail BIMI, DMARC must be at enforcement: p=quarantine or p=reject, with pct=100. p=none does not qualify. Legitimate mail also has to pass DMARC through aligned SPF or DKIM. Other providers set their own display rules, so confirm the current receiver requirements before buying a certificate.

VMC versus CMC

A Verified Mark Certificate (VMC) connects the domain to a trademarked logo and gives Gmail’s verified senders its checkmark treatment. A Common Mark Certificate (CMC) can cover an established logo that is not registered as a trademark; Gmail now accepts either for BIMI logo display, but a CMC does not receive Gmail’s VMC checkmark. Apple describes support for VMCs and other valid BIMI evidence documents rather than requiring only VMCs. Certificate support is provider-specific, so do not claim one certificate works everywhere.

The logo format

The logo must be SVG Tiny Portable/Secure, commonly written SVG Tiny PS, with baseProfile="tiny-ps" and version="1.2". It cannot contain scripts, animations, or external references. Gmail additionally requires absolute pixel dimensions of at least 96 by 96 and recommends a file no larger than 32 KB. Host the BIMI assets over HTTPS.

See Google’s current BIMI setup documentation and Apple’s BIMI support page for provider details.

Use the DMARC policy comparison and the DMARC lookup guide to confirm readiness before purchasing a certificate.

Prepare the brand assets

The logo format and hosting requirements are specific. Legal trademark status can also matter for certificate eligibility. Use the current BIMI and certificate-authority documentation rather than converting a normal website logo and assuming it will qualify.

Verify and maintain

Publish the BIMI record only after the underlying controls are stable, then test at supporting providers. Keep certificate renewals, logo hosting, and DNS ownership documented. Run Beacon’s free check to review public email-authentication signals first.

A readiness checklist

If any of these points is uncertain, fix the underlying issue first. A logo beside messages has little value if customers receive spoofed mail or legitimate billing messages are failing authentication.

Set realistic expectations

BIMI display is controlled by each receiving mailbox provider. Publishing a valid record does not guarantee every recipient will see the mark. Treat the investment as a potential brand-trust enhancement, not a deliverability fix or a substitute for permission-based sending. It should never be the reason to rush DMARC enforcement.

Maintain the chain

Review the logo host, certificate status, DNS record, and DMARC policy after brand changes, domain changes, and sender migrations. Assign a business owner as well as a technical owner, because the logo, trademark, and customer experience span both functions.

Common implementation mistakes

Teams sometimes publish BIMI before moving DMARC beyond monitoring, host an unsupported logo variant, or forget that a logo certificate can have renewal and legal requirements. Another mistake is changing several email controls at once, which makes it difficult to tell whether a display or delivery issue came from BIMI, DNS, DMARC, or the sending provider. Stage the work and record the test result at each step.

Decision summary

Choose BIMI when brand visibility is valuable and the organization can maintain the authentication and asset requirements. If the goal is simply better inbox placement, improve consent, sender reputation, SPF, DKIM, and DMARC first; those controls deliver the core operational value.

Before you publish

Confirm the DMARC policy is enforced, the selected sending domain is aligned, and the logo assets meet the latest published specifications. Test without changing unrelated DNS records, and document who renews the certificate and maintains the logo host.

Keep the launch accountable

Record the publication date, test inboxes, observed display behavior, and the people responsible for domain authentication and brand assets. Review these details when a sender, logo, certificate, or mail provider changes. A maintained implementation is more valuable than a one-time visual win.

For a practical brand-protection sequence, see how to prevent email spoofing.

Want a free deliverability check for your domain?
Run a free check →