BIMI implementation sequence
BIMI deployment has dependencies. Start with authentication and enforcement, then prepare the logo, decide the certificate path, publish DNS, and verify receiver-specific results.
Start a BIMI review1. Establish DMARC enforcement
DMARC policy at p=quarantine or p=reject is a BIMI prerequisite. It is not, by itself, a trigger for logo display. Confirm that legitimate mail streams pass alignment before moving to enforcement.
2. Prepare a strict SVG Tiny P/S logo
A BIMI logo must be a static SVG Tiny P/S file. Standard SVG artwork often contains unsupported elements, external references, metadata, animation, or profile attributes that must be resolved before publication.
3. Determine the certificate path
A VMC or, where available and applicable, a CMC may be required by a receiver. Certificate availability, validation criteria, and receiver acceptance are receiver- and authority-specific. DigiCert and Entrust are the active VMC issuers identified by the BIMI Group at publication time.
4. Publish the BIMI record
Publish the TXT record at default._bimi.<domain> with the logo location and certificate location where used. The record, logo, and referenced certificate must remain publicly resolvable.
5. Verify by receiver
Mailbox-provider and client support is not uniform. BIMI implementation does not guarantee display, inbox placement, or rendering in every recipient environment.
Deployment evidence
| Phase | Deliverable | Validation boundary |
|---|---|---|
| Authenticate | Aligned SPF, DKIM, and DMARC enforcement | DMARC enforcement is necessary but does not itself display a logo |
| Prepare logo | Static SVG Tiny P/S file | Profile conformance does not guarantee receiver display |
| Certificate | VMC or CMC where applicable | Availability and acceptance vary by receiver and authority |
| Publish DNS | default._bimi TXT record | Records and referenced assets must resolve publicly |