A verified logo increases open rates and trust, and the DMARC prerequisite forces a domain to finish its authentication work. It is also a visible signal that a message is not a phish.
Mistake 1: Publishing BIMI while DMARC is still at p=none; providers ignore the record#
Why it hurts: this undermines BIMI at the point where mailbox providers make their decision, and it is rarely surfaced by your own tooling until placement drops.
Fix: Reach DMARC p=quarantine (pct=100) or p=reject on the sending domain.
Mistake 2: Uploading a standard SVG exported from a design tool; it must be the Tiny PS profile with no scripts or external references#
Why it hurts: this undermines BIMI at the point where mailbox providers make their decision, and it is rarely surfaced by your own tooling until placement drops.
Fix: Produce your logo as an SVG Tiny 1.2 Portable/Secure file, square, centered, with a solid background.
Mistake 3: Hosting the logo on a non-HTTPS URL or behind a redirect#
Why it hurts: this undermines BIMI at the point where mailbox providers make their decision, and it is rarely surfaced by your own tooling until placement drops.
Fix: Obtain a VMC or CMC from an approved certificate authority if you want display in Gmail and Apple Mail.
Frequently asked questions#
Does BIMI work without a VMC?
Yahoo and Fastmail display BIMI logos with DMARC enforcement alone. Gmail and Apple require a VMC or CMC.
What image format does BIMI require?
SVG Tiny 1.2 Portable/Secure. No PNG, JPG, or standard SVG.
Does BIMI improve deliverability?
Not directly. Its prerequisite, DMARC enforcement, does. The logo mainly lifts engagement and trust.