If you've set up BIMI (Brand Indicators for Message Identification) but your logo still isn't appearing next to your emails, you're not alone. BIMI is a great tool for building brand trust in the inbox, but it depends on several moving pieces. Your DNS records, your DMARC policy, your certificate (if required), and the specific rules of the mailbox provider your recipient uses. If any one of these isn't in place, the logo simply won't render, usually with no error message at all.
This guide breaks down the universal requirements, then walks through what's different at Yahoo/AOL, Gmail/Google Workspace, and Apple Mail, the three most common places people get tripped up.
The Basics: What BIMI Needs to Work at All
No matter which mailbox provider your recipient uses, these four things must all be true:
DMARC must be enforced, not just monitoring. Your domain's DMARC policy (p=) must be set to quarantine or reject. A policy of p=none or sp=none (subdomain policy) will not qualify for BIMI at any provider. BIMI is a reward for enforcing authentication, not just having a DMARC record.
SPF and/or DKIM must be properly aligned with the domain in your "From" address, since DMARC depends on that alignment passing.
A valid BIMI DNS TXT record must exist at default._bimi.yourdomain.com, pointing to a properly formatted logo file.
Your logo must be a compliant SVG file, specifically SVG Tiny Portable/Secure (SVG Tiny PS) format, not a regular SVG exported from a design tool. Logos that don't meet this technical spec (wrong version, wrong baseProfile, scripts/animations included, transparent background, etc.) will be silently rejected. Read more about the SVG file requirements here.
Even with all of this correct, it can take up to 48 hours for a logo to start appearing after you publish or update your BIMI record, so don't assume something's broken if it hasn't shown up yet.
Beyond these basics, each mailbox provider adds its own extra requirements. Here's where it gets specific.
Tip: Before you publish anything, it's worth running your logo through Valimail's free BIMI checker. You upload your SVG file, and it tells you in plain language, no DNS digging required, whether the file actually meets the technical BIMI spec (correct SVG Tiny PS format, sizing, etc.) before you submit it for a VMC/CMC or publish your BIMI DNS record. It's a fast way to rule out "the logo file itself is the problem" early on.
Yahoo & AOL Mail
Yahoo (which also powers AOL Mail) has its own set of conditions on top of the DMARC/SVG basics, and this is the one people most often overlook:
A valid BIMI record pointing to a properly formatted SVG logo.
A DMARC policy of quarantine or reject.
The email must be sent as bulk mail to a large number of recipients. Yahoo explicitly does not display brand logos on personal, one-to-one emails.
Yahoo must see sufficient reputation and engagement for the sending email address.
That last point is the one that catches marketers off guard. Even if your authentication and BIMI record are flawless, Yahoo will withhold the logo if your sender reputation is poor or your engagement is low (high spam complaints, low opens/clicks, inconsistent sending patterns, etc.). This isn't a technical misconfiguration you can fix in DNS, it's a trust signal that Yahoo builds up over time based on how recipients actually interact with your mail. If your logo isn't showing in Yahoo/AOL inboxes despite correct setup, check your sending reputation before you check your DNS records again.
Yahoo does not currently require a paid certificate (VMC/CMC); a self-asserted SVG logo can qualify, though a certificate strengthens trust.
Gmail & Google Workspace
Gmail takes the strictest approach of the major providers: a VMC or CMC is mandatory. A self-asserted logo (just an SVG file with no certificate) will not display in Gmail, full stop.
Google Workspace's own requirements:
A Verified Mark Certificate (VMC) or Common Mark Certificate (CMC) issued by an approved Certificate Authority.
A VMC requires your logo to be trademarked with a recognized IP office; this process can take 6–12 months, so plan ahead.
A CMC is available if your logo isn't trademarked, issued by CAs that support that option.
DMARC policy
p=quarantineorp=reject, withpct=100(applied to 100% of your mail — Gmail will not honor partial rollout)An SVG file meeting Gmail's specific formatting rules: minimum 96x96px, absolute (not relative) dimensions, ideally under 32KB, centered on a solid background
The certificate and logo get bundled into a PEM file hosted on your domain's public web server, referenced in your BIMI DNS record
One extra nuance: Gmail shows a checkmark badge next to the sender name specifically for senders verified with a VMC. If you're using a CMC instead of a VMC, your logo can still appear, but you won't get that checkmark; it's reserved for the VMC.
Apple Mail (iOS, iPadOS, macOS)
Apple Mail is a special case, and it's a common source of confusion because Apple itself doesn't decide whether your logo shows, the recipient's mailbox provider does.
A few important things to understand:
BIMI display in the native Apple Mail app requires macOS Ventura 13, iOS 16, iPadOS 16, or later. Older OS versions won't render BIMI logos regardless of anything else being correct.
The mailbox provider hosting the recipient's email is responsible for BIMI compliance. Meaning they must be on the BIMI Group's list of supporting providers and have been separately verified by Apple, properly authenticate the message per the BIMI spec, verify the BIMI evidence document (like a VMC), and add the required headers.
Apple Mail itself doesn't validate anything, it trusts the headers passed to it by the mail provider. If the recipient's mailbox provider hasn't done its part, no logo will appear in Apple Mail, even if your domain's BIMI setup is perfect.
This is the key point to remember: your logo will only appear in Apple Mail when the recipient is checking mail through an Apple mailbox (e.g., icloud.com, me.com) on an Apple Mail app. If your recipient uses Gmail's app on their iPhone, for example, that's governed by Gmail's BIMI rules (see above), not Apple's. The Apple Mail requirements only apply when the native Mail app itself is rendering the message.
Quick Reference: VMC/CMC Requirements by Provider
Mailbox Provider | Supports BIMI | VMC or CMC Required? | Notable Extra Requirement |
Gmail / Google Workspace | Yes | Yes, mandatory |
|
Yahoo / AOL | Yes | No (self-asserted SVG accepted) | Sufficient sender reputation and engagement; bulk mail only |
Apple Mail | Yes (native app, iOS 16+/macOS Ventura+) | Depends on the recipient's underlying mail provider's rules | Compliance is enforced by the mailbox provider, not by Apple directly |
Fastmail | Yes | No | — |
Comcast / Xfinity | Yes | No | — |
La Poste, GMX, WEB.DE, Zoho Mail, NTT Docomo, KDDI (au) | Yes | No | Check each provider's own BIMI documentation |
Microsoft (Outlook.com / Microsoft 365) | No | N/A | Microsoft does not currently support BIMI logo display |
For providers not listed above or to confirm current status, check the BIMI Group's mailbox provider list, which is the most current cross-provider reference.
A Quick Troubleshooting Checklist
If your logo still isn't showing, work through this in order:
Is your DMARC policy p=quarantine or p=reject? (p=none or sp=none will never show a logo, anywhere.)
Does your DMARC record have pct=100? (Required for Gmail.)
Is your logo a valid SVG Tiny PS file (not a standard SVG export)?
Is your BIMI DNS TXT record published correctly at default._bimi.yourdomain.com?
Has it been at least 48 hours since you published or updated the record?
If targeting Gmail: Do you have a valid VMC or CMC? A logo with no certificate will never show in Gmail.
If targeting Yahoo/AOL: Is this bulk mail (not a 1:1 personal email), and is your sending reputation/engagement healthy?
If targeting Apple Mail: Is the recipient on a supported OS version, and does their mailbox provider actually support and enforce BIMI?
Is the recipient's provider one that supports BIMI at all? (Microsoft/Outlook, for example, currently does not.)
Working through DNS and certificate issues is usually the easy part; reputation, engagement, and provider-specific rollout status are the pieces that take ongoing attention.
