Siftsmith
← All email error fixes

BIMI logo not showing in Gmail, Yahoo or Apple Mail: how to fix

A BIMI logo appears only when four things line up: a valid BIMI record in DNS, an enforced DMARC policy, a logo file in the right SVG format, and, for Gmail and Apple Mail, a mark certificate. Check the DNS half for your domain below, then work through what each mailbox provider needs.

Last verified 2 October 2026.

Check your BIMI record and DMARC policy

Enter the domain in your From: address. The checker looks up default._bimi.your domain (or the selector you enter) and, if there is no BIMI record there, the Organizational Domain’s, the way receivers do. It then checks the record’s syntax and whether your DMARC policy meets BIMI’s requirements. The lookups run in your browser against public DNS.

What this can and can’t tell you: it reads DNS right now, through Cloudflare’s public resolver (Google’s when Cloudflare’s fails). A failed lookup is shown as unknown, never as a missing record. It finds the Organizational Domain with a built-in list of common public suffixes rather than the full Public Suffix List. It can’t see whether a given message passed DMARC, your sending reputation, or a mailbox provider’s own display rules. For the full A–F grade with SPF, DKIM, MTA-STS and DNSSEC, use the DMARC checker.

What Gmail, Yahoo and Apple Mail each need

The BIMI standard leaves the final call to the mailbox provider: “MUAs have final control over the user interface published to their end users, and MAY use alternate Indicators than those specified in the BIMI assertion record or no Indicator at all” (BIMI draft §4.1). Here is what each provider says it requires, in its own words.

Gmail

Yahoo and AOL

Yahoo’s Sender Hub lists when it shows a logo: “We will display a logo if”

On certificates: “We currently do not require VMCs to be set up for BIMI logos to appear in Yahoo applications. However if a BIMI record includes a VMC, we will use it to inform the overall BIMI eligibility.” On subdomains: “We honor BIMI records on sub domains, but prefer BIMI and DMARC to be set up at the organizational domain level.” So a one-off test message to a Yahoo address may show no logo, however correct your records are.

Apple Mail

Apple’s support page says: “In iOS 16, iPadOS 16, and macOS Ventura 13 or later, and on iCloud.com, Apple Mail supports BIMI (Brand Indicators for Message Identification), an email specification that allows brand-controlled logos to be displayed.” and “BIMI also works with VMCs (Verified Mark Certificates) and other forms of BIMI Evidence Documents to verify the ownership and authenticity of a logo and the logo’s connection to that domain.” Apple’s page doesn’t list which certificate types it accepts. The BIMI Group’s FAQ says: “Other mailbox providers (e.g. Gmail, Apple) require that BIMI logos be verified with a Verified Mark Certificate.” (For Gmail, Google’s own page, quoted above, now accepts a CMC as well.) To be shown in Apple Mail, plan on a VMC.

GmailVMC or CMC, referenced by a= as a PEM file. DMARC p=quarantine or p=reject, pct=100.
Yahoo, AOLNo certificate required. Valid SVG logo, DMARC p=quarantine or p=reject, bulk mail, and enough reputation and engagement.
Apple MailApple doesn’t publish its certificate rules; the BIMI Group says Apple requires a VMC. Enforced DMARC.

Sources: Google Workspace Admin Help, Set up BIMI and Add a BIMI TXT record to your domain (both last updated 1 October 2026); Yahoo Sender Hub, BIMI (undated, read 2 October 2026); Apple Support, About BIMI support in Apple Mail (published 7 February 2024); BIMI Group, FAQs for Marketers and ESPs (updated 6 February 2026); draft-brand-indicators-for-message-identification-14 (1 May 2026). All checked 2 October 2026.

The BIMI record

BIMI is defined in an IETF Internet-Draft, draft-brand-indicators-for-message-identification-14 (1 May 2026). The record is a TXT record at selector._bimi.domain; the selector is default unless the message carries a BIMI-Selector header naming another one. A typical record:

default._bimi.example.com.  TXT  "v=BIMI1; l=https://images.example.com/brand/logo.svg; a=https://images.example.com/brand/vmc.pem"
v=BIMI1Required, and it must be the first tag. The draft: “The value of this tag MUST match precisely”. Records that don’t start with it are discarded.
l=The logo URL. Required. “The only supported transport is HTTPS.” Use a URL ending in .svg (the draft also accepts .svgz), never another image format: “If an l= tag URI ends with any other image format suffix, or if the document retrievable from the location(s) in the l= tag are of any other format, the evaluation of the record MUST be treated as a permanent error.”
a=The certificate (“Authority Evidence”) URL. Optional in the draft, needed by Gmail. It “MUST specify HTTPS as the URI scheme”. Your certificate authority gives you a .pem file to host.
avp=Optional: brand (the default) or personal, for providers that also show personal avatars.

Where receivers look

A receiver queries the selector at the exact From: domain first. If no v=BIMI1 record is there, it tries the Organizational Domain: “A custom selector that does not exist falls back to <selector>._bimi.<organizationalDomain>.” (§7.2). So a BIMI record on example.com also covers mail from news.example.com, unless news.example.com publishes its own. Two records at one name stop BIMI entirely: “If the remaining set contains multiple records or no records, Assertion Record Discovery terminates and BIMI processing MUST NOT be performed for this message.”

The declination record

v=BIMI1; l=; a=; switches BIMI off: “If both the "l=" and "a=" tags are empty, it is an explicit refusal to participate in BIMI. This is distinct from not publishing a BIMI record.” (§4.3.1). It is useful on a subdomain that shouldn’t inherit the parent’s logo, and a common reason for a missing logo when it is published by mistake.

Gmail’s l=-empty form

Google’s example for a PEM file leaves l= empty, because the logo is inside the certificate: v=BIMI1;l=;a=https://images.solarmora.com/brand/certificate.pem. The draft’s receiver steps, though, start with “If the retrieved Assertion Record does not include a valid bimi-location in the l= tag, then Indicator Discovery has failed, and the Indicator MUST NOT be displayed.” (§7.3). Many senders publish both URLs, and the BIMI Group’s FAQ example record has both an l= logo URL and an a= certificate URL. The checker flags the empty form as a warning.

Source: draft-brand-indicators-for-message-identification-14 §4.3, §4.3.1, §4.3.2, §7.2, §7.3 (an Internet-Draft, a work in progress, dated 1 May 2026); Google Workspace Admin Help, Set up BIMI (checked 2 October 2026).

The DMARC policy BIMI needs

A logo is only shown on mail that passes DMARC, and only when your policy is enforced. The draft’s receiver rules (§7.1):

Google goes further on pct: “BIMI doesn’t support DMARC policies that have a pct value other than 100.” with either policy. Note the sp=none rule: a record like v=DMARC1; p=reject; sp=none on your main domain blocks BIMI for the main domain too, not just its subdomains. And the Organizational Domain’s policy counts even when a subdomain has its own record: p=reject on news.example.com doesn’t help if example.com is still at p=none.

The working record for BIMI is simply:

_dmarc.example.com.  TXT  "v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com"

with p=reject once your reports show every legitimate sender passing. Before you move off p=none, make sure every service that sends as your domain is aligned, or its mail goes to spam: see fixing DMARC alignment. If your record uses RFC 9989’s test mode (t=y), receivers that follow RFC 9989 apply one level less: “if the policy is "quarantine" and the value of the "t" tag is "y", a policy of "none" will be applied to failing messages”. The BIMI draft and Google’s page don’t mention t=; the checker flags it so you can remove it once you’re ready.

Sources: BIMI draft §7.1; Google Workspace Admin Help, Troubleshoot BIMI issues (last updated 1 October 2026); RFC 9989 §4.7 (t tag) (checked 2 October 2026).

The logo file: SVG Tiny PS

A plain SVG exported from a design tool usually isn’t accepted. BIMI uses a restricted profile, SVG Tiny Portable/Secure (SVG Tiny PS). Google’s summary of the standard’s requirements: the root <svg> element has baseProfile="tiny-ps" and version="1.2", and the file should not include:

Gmail adds its own: “The image size must be a minimum height and width of 96 pixels.” and “The image size must be specified in absolute pixels.” Google recommends that “The logo image should be centered in a square.”, that “The logo image should appear on a solid color background. Transparent backgrounds might not display as expected.”, and that “The SVG file size should be 32 KB or smaller.” The BIMI Group’s FAQ says to “Use a clean, square SVG Tiny-ps file (no external resources, no scripts, no embedded rasters)” and to “ensure the server sends Content-Type: image/svg+xml.”

If you have a certificate, the SVG is embedded in it, so the logo in l= should be the same file you submitted to the certificate authority.

Sources: Google Workspace Admin Help, Set up BIMI, Step 1 (last updated 1 October 2026); BIMI Group, FAQs for Marketers and ESPs (updated 6 February 2026) (checked 2 October 2026).

The certificate: VMC or CMC

The BIMI draft defines two kinds of Mark Certificate:

Google: “To be eligible for a VMC, your logo must be trademarked with an intellectual property office that’s recognized by VMC issuers.” and “If your logo isn’t trademarked, you can set up BIMI using a logo that has a CMC.” The BIMI Group keeps the list of Mark Certificate issuers. Certificates expire: “BIMI Mark Certificates currently have a maximum validity period of 398 days (roughly one year)” (BIMI Group FAQ), so a logo that used to show and stopped is worth checking against the certificate’s expiry date.

Host the PEM file with its full chain. Google: “Get any intermediate CA certificates and root CA certificates from the CA and append them to the PEM file in the order issued. Typically, the order is: Entity certificate, any intermediate CA certificate, root CA certificate.”

Sources: BIMI draft §3.5.1–3.5.2; Google Workspace Admin Help, Set up BIMI, Before you begin and Step 2; BIMI Group, FAQs for Marketers and ESPs (checked 2 October 2026).

Fix it: work through the causes in order

  1. Run the checker above and fix every failed check: a missing, duplicate or declination BIMI record, an http:// or non-SVG l=, a DMARC policy of p=none, sp=none or pct below 100.
  2. Check the recipient’s provider. Gmail and Apple Mail need a certificate; Yahoo shows logos only on bulk mail with enough reputation. Google’s troubleshooting page starts with: “Verify that the recipient is using an email client that supports BIMI.”
  3. Check that the message passes DMARC. Open a received message’s headers and look for dmarc=pass in Authentication-Results. A sender that fails alignment gets no logo; see DMARC alignment failed.
  4. Check the files. Open the l= and a= URLs in a browser: both must load publicly over HTTPS. The BIMI Group lists common blockers, including “Blocked user agents, geo/IP restrictions, or hotlink protection.” and “Redirect chains ending on the wrong file/host.” Google’s checklist: “Verify the status of your VMC or CMC.”, “If your VMC or CMC is approved, verify that the associated PEM file is accessible on your public web server.”, “Verify that you’ve appended any other issued files or certificates to your PEM file.”
  5. Check DKIM signing outside Google Workspace. Google: “If you’re setting up DKIM with an email system other than Google Workspace, do not use the DKIM length tag (l=) in your DKIM signature.”
  6. Wait. Google allows up to 48 hours after publishing, and providers cache logos, so judge by new messages.

Sources: Google Workspace Admin Help, Troubleshoot BIMI issues (last updated 1 October 2026); BIMI Group, FAQs for Marketers and ESPs (checked 2 October 2026).

FAQ

Why is my BIMI logo not showing in Gmail?

Gmail needs three things: a DMARC policy of p=quarantine or p=reject with pct=100, a Verified Mark Certificate (VMC) or Common Mark Certificate (CMC), and a BIMI record whose a= tag points to the certificate’s PEM file. Google says Gmail supports BIMI only with PEM files, so a record with just an SVG in l= shows no logo in Gmail. After you publish the record, Google says it can take up to 48 hours for the logo to show.

Do I need a VMC for BIMI?

It depends on the mailbox provider. Gmail accepts a VMC or a CMC. Yahoo says it does not currently require VMCs for BIMI logos to appear. The BIMI Group lists Apple among the providers that require a Verified Mark Certificate. A VMC needs a registered trademark; a CMC covers a logo you have used without a registered trademark.

Does BIMI work with DMARC p=none?

No. The BIMI draft says BIMI processing must not be performed when the DMARC policy for the From domain or its Organizational Domain is p=none, or when the record has sp=none. Google also requires pct=100. Move to p=quarantine or p=reject first.

What does v=BIMI1; l=; a=; mean?

It is a declination record: with both l= and a= empty, the domain explicitly refuses to participate in BIMI, and no logo is shown for mail that uses that selector. It is different from having no BIMI record at all, and can be used to stop a subdomain from inheriting its parent’s logo.

Checking many domains?

If you manage sending domains for clients or brands, Email Security Signals checks a whole list and returns one row per domain with BIMI, the DMARC policy, SPF, DKIM selectors found and an A–F grade, ready to export as CSV. $0.02 per graded domain ($20 per 1,000); invalid inputs, domains that don’t exist, DNS lookup failures and duplicates are free.

Check a list on the Apify Store →

Related: fixing “DMARC alignment failed”, fixing “multiple DMARC records found”, fixing the 550 5.7.509 DMARC reject bounce and Gmail, Yahoo and Microsoft bulk sender requirements.