Skip to main content
bimi PROTOCOLHost: Azure DNSStandard: RFC 9495

How to Configure Brand Indicators for Message Identification (BIMI) on Azure DNS

Displays authenticated brand logos next to incoming messages in supporting inboxes (Apple Mail, Gmail) after strict DMARC enforcement. Follow this verified implementation guide to deploy standard compliant BIMI DNS records in Azure DNS.

Default BIMI Record Syntax

// Authoritative RFC Example
v=BIMI1; l=https://www.yourcompany.com/logo.svg; a=https://www.yourcompany.com/cert.pem

Configuration Steps in Azure DNS

  1. 1Navigate to the Azure Portal and select "DNS zones".
  2. 2Select your authoritative domain zone.
  3. 3Find the record set corresponding to the dangling subdomain.
  4. 4Click "Delete" from the top command toolbar.
  5. 5Confirm deletion to release the DNS binding.

Verification Checklist (RFC 9495)

Verify DMARC enforcement on the root domain (p=quarantine pct=100 or p=reject).
Publish BIMI TXT record at default._bimi.yourcompany.com.
Ensure logo URL points to an SVG Tiny P/S compliant vector graphic.
Attach a Verified Mark Certificate (VMC) from DigiCert or Entrust for full mailbox provider display.
Live Validation Engine

Validate Your Azure DNS BIMI Record

Verify propagation, check syntax formatting, and audit recursive lookups in 60 seconds with SubDomainWatch.

Run Free DNS Validator