Dmarc Overview

What is BIMI?

BIMI (Brand Indicators for Message Identification) lets a domain publish a brand logo that some mailbox providers may display next to authenticated messages. It is optional and it builds on DMARC.

Prerequisites

Requirement Detail
DMARC at enforcement The domain must publish p=quarantine or p=reject. A none policy is not enough.
A logo Square, in SVG format, meeting the SVG profile that BIMI defines
Optional certificate Some providers require a verified certificate for the logo. Check each provider's current requirements.

Note: which mailbox providers display the logo, and what they require, is decided by those providers and changes over time. Check their published documentation before planning a rollout.

The BIMI record

BIMI is a TXT record at default._bimi.<domain>:

v=BIMI1; l=https://example.com/logo.svg; a=https://example.com/cert.pem
Tag Meaning
v Version, BIMI1
l HTTPS location of the SVG logo
a HTTPS location of the certificate, if used

Publish BIMI with DMARC+

  1. Confirm the domain is enforced. See From monitoring to enforcement.
  2. Open DMARC+ > Manage > Managed BIMI.
  3. Fill in the generator: trust authority, logo URL and location fields.
  4. Copy the generated record and publish it at default._bimi.<domain> as the tool instructs.
  5. Check it under DMARC+ > Tools > BIMI.

See Managed record tools for how managed records work.

Next steps