Setup checklist#
- ☐ Reach DMARC p=quarantine (pct=100) or p=reject on the sending domain.
- ☐ Produce your logo as an SVG Tiny 1.2 Portable/Secure file, square, centered, with a solid background.
- ☐ Obtain a VMC or CMC from an approved certificate authority if you want display in Gmail and Apple Mail.
- ☐ Publish default._bimi.yourdomain.com with l= (logo URL) and a= (certificate URL).
- ☐ Validate with a BIMI inspector and send a test to Gmail, Yahoo, and Apple seed accounts.
Audit checklist#
- ☐ Confirm you are not: publishing BIMI while DMARC is still at p=none; providers ignore the record.
- ☐ Confirm you are not: uploading a standard SVG exported from a design tool; it must be the Tiny PS profile with no scripts or external references.
- ☐ Confirm you are not: hosting the logo on a non-HTTPS URL or behind a redirect.
Ongoing monitoring#
- ☐ Weekly: review provider dashboards (Postmaster Tools, SNDS) and bounce logs
- ☐ Monthly: re-run the setup verification after any vendor or DNS change
- ☐ Quarterly: full audit against this checklist
Frequently asked questions#
Does BIMI work without a VMC?
Yahoo and Fastmail display BIMI logos with DMARC enforcement alone. Gmail and Apple require a VMC or CMC.
What image format does BIMI require?
SVG Tiny 1.2 Portable/Secure. No PNG, JPG, or standard SVG.
Does BIMI improve deliverability?
Not directly. Its prerequisite, DMARC enforcement, does. The logo mainly lifts engagement and trust.