Knowledge Base

How to set up or update a BIMI record to display your organization's logo in email

Overview

By following this article, you will publish a Brand Indicators for Message Identification (BIMI) record that shows your organization's logo in supported email clients. When you bought your Verified Mark Certificate (VMC), you submitted a logo file in Scalable Vector Graphics (SVG) format and received a certificate file in Privacy-Enhanced Mail (PEM) format. This article explains how to host these two files, create a BIMI text (TXT) record in your Domain Name System (DNS), publish the record, and verify the setup. It also explains how to fix the two most common problems: a logo file that does not match the certificate, and files that are not available over HTTPS.

What is a BIMI record?

A Brand Indicators for Message Identification (BIMI) record is a text (TXT) entry in your domain's Domain Name System (DNS). The record tells email clients where to find two files:

  • Your logo, in Scalable Vector Graphics (SVG) format.
  • Your Verified Mark Certificate (VMC), in Privacy-Enhanced Mail (PEM) format.

To update an existing BIMI record, change the file addresses in the record and keep the same format.

Prerequisites

Before you set up a Brand Indicators for Message Identification (BIMI) record, make sure you have:

  • The Scalable Vector Graphics (SVG) logo file that you submitted when you bought your Verified Mark Certificate (VMC).
  • The VMC file in Privacy-Enhanced Mail (PEM) format that you received from Sectigo.
  • Access to your Domain Name System (DNS) provider's dashboard.
  • A public web server that serves files over HTTPS. You can host the files yourself, or Sectigo can host them for you.

Important: The SVG file in your BIMI record must exactly match the SVG file that Sectigo validated and that your VMC file references. If the files do not match, the BIMI logo does not display.

Steps to set up a BIMI record

Step 1 — Prepare and host your logo and certificate files

Make sure your logo meets these requirements:

  • The format is Scalable Vector Graphics (SVG) Tiny 1.2.
  • The logo is square and represents your brand.

Upload the SVG logo file and the Verified Mark Certificate (VMC) file in Privacy-Enhanced Mail (PEM) format to a public server. Keep the original file names. Each file must be available over HTTPS at a static web address (Uniform Resource Locator, or URL). A URL that starts with HTTP causes the setup to fail.

Step 2 — Create the BIMI DNS TXT record

Create a Brand Indicators for Message Identification (BIMI) text (TXT) record for your Domain Name System (DNS) with these values:

FieldValue
Record typeTXT
Namedefault._bimi.yourdomain.com
Valuevmc.pem

Replace yourdomain.com and each file path with your own domain and URLs. The record value uses these tags:

TagMeaning
v=BIMI1The BIMI version.
l=The URL of your SVG logo file.
a=The URL of your VMC file in PEM format.

Step 3 — Publish the record

Sign in to your Domain Name System (DNS) provider's dashboard. Add the BIMI text (TXT) record from Step 2 under the subdomain default._bimi.yourdomain.com, and then save the record.

How to verify success

To confirm that your Brand Indicators for Message Identification (BIMI) record is published and correctly formatted, check your domain with one of these tools:

  • MXToolbox BIMI Lookup(opens in new window)
  • BIMI Inspector by BIMI Group(opens in new window). This tool checks the record format only. It does not check your Scalable Vector Graphics (SVG) logo or your Verified Mark Certificate (VMC).
  • List of free BIMI record checker tools (GoDMARC)(opens in new window)

Troubleshooting

Issue: The logo does not display, although the BIMI record is published. Cause: The Scalable Vector Graphics (SVG) file in the Brand Indicators for Message Identification (BIMI) record does not exactly match the SVG file that your Verified Mark Certificate (VMC) references. Solution: Host the exact SVG file that Sectigo validated for your VMC, with its original file name. Then confirm that the l= tag points to that file.

Issue: The BIMI check fails because the logo or certificate file cannot be reached. Cause: The file address (Uniform Resource Locator, or URL) uses HTTP, or the file is not on a public server. Solution: Host both files on a public server that uses HTTPS. Then update the l= and a= tags in the BIMI record with the HTTPS URLs.

Important Update: Sectigo-Hosted Logo and Mark Certificate (MC) Assets for VMC and CMC Orders

Important: Sectigo now supports enhanced management of logo and Mark Certificate (MC) assets associated with Verified Mark Certificates (VMC) and Common Mark Certificates (CMC).

Key updates include:

  • Customer-Controlled Hosting Selection
    During the certificate ordering process, customers can choose whether Sectigo hosts their logo and MC assets or opt to manage hosting independently.

  • Hosted URL Delivery After Issuance
    For orders where Sectigo hosting is enabled, the hosted asset URLs are provided upon successful certificate issuance for use in BIMI implementations and related configurations.

  • Asset Replacement Without URL Changes
    When logo or MC assets are replaced, Sectigo updates the hosted content while maintaining the existing hosted URLs. This eliminates the need to update downstream configurations that reference those URLs.

  • Revocation and Hosting Impact
    The availability and behavior of Sectigo-hosted assets may be affected when a VMC or CMC certificate is revoked. Customers should review revocation implications to understand how hosted logo and MC assets are handled following certificate revocation.

This enhancement provides greater flexibility in asset hosting, simplifies asset lifecycle management, and helps maintain continuity for customers using Sectigo-hosted VMC and CMC assets.

Similar questions

  • How do I configure a BIMI record for my organization's logo?
  • How do I host my brand logo so that it is BIMI compliant?
  • What format should my logo be in for BIMI?
  • How do I set up my organization's logo in SVG format for BIMI?
  • How do I update my BIMI record with a new logo URL?

Need assistance?

Contact our team for help with your purchase or issuing your certificate.

Live chat

Call us today