How to Set Up BIMI in 2026: CMC vs VMC for Gmail
How to set up BIMI in 2026 is not a marketing plugin. In Gmail, Brand Indicators for Message Identification only show a logo on mail that already passes DMARC — and p=none still blocks the logo. Gmail wants a third-party VMC or CMC, not a standalone SVG. This field guide is the implementation path: CMC vs VMC, SVG Tiny PS, default._bimi DNS, and when to wait. If you are still deciding whether the logo layer is worth doing, start with when BIMI makes sense.
Grounding: Google Workspace — Set up BIMI (last updated 26 August 2026). BIMI itself is still an IETF Internet-Draft, not an RFC.
What is BIMI
BIMI (Brand Indicators for Message Identification) lets a domain publish a DNS record so participating mailbox providers can display an approved logo next to authenticated mail.
The logo is a trust signal on top of SPF, DKIM, and DMARC. It does not authenticate mail by itself. Receivers that support BIMI still decide whether to show it.
A public DNS check can confirm the TXT exists — free tools are DNS only. This article is certificate and DNS guidance, not a hosted-logo service. A scan does not make a logo appear in Gmail.
Why p=none blocks BIMI
Gmail documents that BIMI needs DMARC p=quarantine or p=reject, with pct=100. BIMI does not support p=none. Monitoring-only policy is why many teams publish a logo record and see nothing.
p=none is a phase, not protection — p=none is not protection. Raise policy on the enforcement path before you pay a certificate authority.
CMC vs VMC
Gmail BIMI requires a third-party Verified Mark Certificate (VMC) or Common Mark Certificate (CMC). Issuers are listed by the BIMI Group at Mark Certificate Issuers. Google recommends a VMC when possible.
| VMC | CMC | |
|---|---|---|
| Eligibility | Logo trademarked at an IP office recognised by VMC issuers | Logo is not trademarked |
| Gmail logo | Supported (Gmail accepts a VMC or CMC) | Supported (Gmail accepts a VMC or CMC) |
| Gmail checkmark | Documented for senders verified with a VMC | Do not assume CMC gets the check |
| Typical path | Trademark can take 6–12 months; Google’s preferred path | Option when you cannot wait on a trademark |
Do not treat CMC as a VMC with the same checkmark. Google documents the Gmail checkmark for VMC-verified senders; it is a Gmail UI feature, not a BIMI-wide badge. Issuer fees vary — this page does not invent a Rand price.
How to set up BIMI (operator sequence)
- Reach DMARC
p=quarantineorp=rejectwithpct=100on the From domain. - Confirm every sender is aligned (usually brand-domain DKIM).
- Produce an SVG Tiny PS logo that meets Gmail’s extras (below).
- Get a VMC or CMC from a BIMI Group issuer; receive the PEM (logo + certificate chain).
- Host the PEM on HTTPS. Append intermediate and root CA certs in the order the CA issued them (typically entity, then intermediates, then root).
- Publish
default._bimiwith emptyl=anda=pointing at that PEM. Wait up to 48 hours.
Skip to when to wait if step 1 or 2 is still in progress.
What must be true first
Before SVG and certificates:
- DMARC at quarantine or reject,
pct=100— DMARC setup, then the path from p=none to p=reject. - Alignment on the From domain — usually brand DKIM, not only the vendor bounce domain. Auth pass is not enough; see DMARC alignment (SPF / DKIM).
- All senders inventory — every platform that sends as the brand must pass aligned authentication. A new SaaS that signs only with its own domain will fail BIMI on that mail even if the apex record looks perfect.
If those are not boringly true, wait.
Logo file (SVG Tiny PS + Gmail extras)
The BIMI logo is SVG Tiny Portable/Secure — not ordinary SVG, and not RFC 6170 (that RFC is a different SVG profile; do not copy the mistaken pointer).
Required on the root <svg>:
baseProfile="tiny-ps"version="1.2"
Must not include scripts, animations or other interactive elements, external links or references (other than specified XML namespaces), or x= / y= on the root <svg>.
Host the files over HTTPS. Google recommends TLS 1.2 or later.
Gmail extras on top of the BIMI profile:
- Minimum 96×96 absolute pixels (
width="96" height="96") — not percentages - Square; logo centred
- Solid colour background (transparent may not display as expected)
- File ≤32 KB
- Include a
<desc>element for accessibility
DNS: default._bimi (PEM vs SVG-only)
Publish a TXT at default._bimi.<your-domain>. After you add it, Gmail says the logo can take up to 48 hours.
Gmail and other major clients want a PEM file: the CA embeds the SVG plus the certificate chain. The assertion uses an empty l= and points a= at the PEM:
default._bimi.example.co.za. IN TXT "v=BIMI1;l=;a=https://images.example.co.za/brand/certificate.pem"
A standalone SVG assertion looks like this — not supported in Gmail (and Google says not in other major clients):
default._bimi.example.co.za. IN TXT "v=BIMI1;l=https://images.example.co.za/brand/logo.svg"
Upload the PEM to a public HTTPS host, then put that URL in a=. Confirm the TXT with free tools (DNS check only).
What BIMI does not do
BIMI does not stop lookalike domains. A neighbour zone (examp1e.co.za) is a different attack than spoofing example.co.za.
It does not fix spam placement. Inbox vs junk is still reputation, list hygiene, and engagement.
Provider support varies. A DNS scan does not make the logo appear, and there is no inbox-display promise on this page.
When to wait
Stay on the decision article — when BIMI makes sense — if:
- you are still at
p=none - senders are still being discovered
- the logo is not legally yours to put on a mark certificate
- customer-facing volume is too low for the logo to matter
Palisade’s State of DMARC 2026 scan of the Tranco top 100k (resolved 13 August 2026) found most domains already at enforcement have not published BIMI (~87% of eligible). Enforcement first is still the scarce step.
Takeaway
How to set up BIMI in 2026, for Gmail: enforce DMARC (p=quarantine or p=reject, pct=100), align every sender, prepare SVG Tiny PS, obtain a VMC or CMC, publish default._bimi with empty l= and a= pointing at the PEM. Do not expect a checkmark from CMC. Do not expect a standalone SVG to work in Gmail. p=none still blocks the logo.
Check the DMARC record on free tools, then finish the enforcement path before you buy a mark certificate.