Table of Contents
BIMI (Brand Indicators for Message Identification)
BIMI (Brand Indicators for Message Identification) is an email specification that allows domain owners who have implemented strong email authentication (SPF, DKIM, and DMARC) to display their official brand logo next to incoming emails in supported inbox clients (such as Gmail, Yahoo, Apple Mail, and Fastmail).
Beyond visual recognition, BIMI serves as a powerful security incentive: it encourages organizations to enforce strict DMARC policies to prevent domain spoofing and phishing.
How BIMI Works
When an email is delivered to a recipient's mail server, the receiving system executes the following validation steps:
# **Authentication Verification:** Validates that the message passes [[email:dns-configuration:spf|SPF]] and/or [[email:dns-configuration:dkim|DKIM]] checks, and that domain alignment is satisfied. # **DMARC Policy Enforcement:** Checks the domain's [[email:dns-configuration:dmarc|DMARC]] record to ensure a quarantine or reject policy (e.g., ''p=quarantine'' or ''p=reject'') is actively enforced. # **BIMI DNS Lookup:** Queries DNS for a TXT record located at ''default._bimi.yourdomain.com''. # **Logo & Certificate Fetching:** Retrieves the SVG image specified in the BIMI record and checks for an optional **VMC** (Verified Mark Certificate). # **Inbox Rendering:** If all checks pass, the inbox provider renders the brand logo in the user's inbox list and message header.
BIMI Record Structure & Syntax
A BIMI TXT record must be created at the host location default._bimi.yourdomain.com.
| Tag | Required / Optional | Description | Example |
|---|---|---|---|
| v | Required | Protocol version. Must be BIMI1. | v=BIMI1; |
| l | Required | HTTPS URL pointing to the official logo in SVG format. | l=https://telenegar.ir/logo.svg; |
| a | Optional | HTTPS URL pointing to the Verified Mark Certificate (VMC) PEM file. | a=https://telenegar.ir/cert.pem; |
Basic BIMI Record Example (No VMC)
v=BIMI1; l=https://telenegar.ir/assets/logo.svg;
Standard Enterprise BIMI Record Example (With VMC)
v=BIMI1; l=https://telenegar.ir/assets/logo.svg; a=https://telenegar.ir/assets/bimi-cert.pem;
Prerequisites for Implementing BIMI
To successfully enable BIMI, your domain must meet all four of the following technical requirements:
1. Enforce DMARC
Your domain must have a published DMARC policy with enforcement enabled. The policy percentage tag must be 100% (pct=100 or omitted):
- Allowed:
p=quarantineorp=reject - Not Allowed:
p=none(BIMI will be ignored by mailbox providers if DMARC is set tonone).
2. Vector SVG Logo Requirements
The logo specified in the l= tag must comply with strict SVG formatting guidelines:
- Must be an SVG Tiny Portable P/S (SVG Tiny PS) formatted file.
- Must be square (1:1 aspect ratio) with a centered design.
- Must be hosted over secure HTTPS.
- Must not contain embedded scripts, external links, or relative paths.
3. Verified Mark Certificate (VMC)
While some inbox providers display logos without a certificate, major providers (such as Gmail and Apple Mail) require a Verified Mark Certificate (VMC) issued by a recognized Certificate Authority (e.g., DigiCert, Entrust). A VMC verifies legal ownership of your registered trademark logo.
4. Positive Domain Reputation
Even with valid records, mailbox providers evaluate sender reputation before displaying logos to users.
Common Pitfalls & Troubleshooting
1. DMARC Set to "none"
If your DMARC record contains p=none, mailbox providers will reject the BIMI record completely. Change your policy to quarantine or reject.
2. Invalid SVG Format
Standard SVG files (SVG 1.1 or SVG 2.0) will fail validation. Use specialized converters to ensure the SVG adheres strictly to the SVG Tiny PS profile.
3. Missing or Inaccessible File
Ensure the logo URL and VMC URL respond with HTTP status 200 OK and are publicly accessible over HTTPS without basic auth or IP restrictions.
Verification & Testing
You can verify your BIMI DNS record and broader email authentication parameters using Telenegar Tools or terminal commands:
Using Telenegar Tools
- BIMI & Email DNS Verification: Validate TXT records and MX resolution with the Telenegar DNS Check Tool.
- Full Authentication Diagnostics: Audit your domain's SPF, DKIM, and DMARC alignment using the Telenegar Mail Check Tool.
Using Terminal Commands
dig (Linux / macOS)
bash dig +short TXT default._bimi.example.com
nslookup (Windows / Cross-platform)
cmd nslookup -type=TXT default._bimi.example.com
Related Documentation
- Telenegar DNS Check Tool — Diagnostic tool for DNS record lookup and propagation.
- Telenegar Mail Check Tool — Diagnostic tool for email authentication and security alignment.
- DMARC — Essential policy requirement for BIMI support.
- SPF (Sender Policy Framework) — Core email authentication protocol.
- DKIM (DomainKeys Identified Mail) — Cryptographic signature mechanism.
- MTA-STS — Enforce TLS encryption for inbound emails.
