Skip to main content
bimi PROTOCOLHost: Cloudflare DNSStandard: RFC 9495

How to Configure Brand Indicators for Message Identification (BIMI) on Cloudflare DNS

Displays authenticated brand logos next to incoming messages in supporting inboxes (Apple Mail, Gmail) after strict DMARC enforcement. Follow this verified implementation guide to deploy standard compliant BIMI DNS records in Cloudflare DNS.

Default BIMI Record Syntax

// Authoritative RFC Example
v=BIMI1; l=https://www.yourcompany.com/logo.svg; a=https://www.yourcompany.com/cert.pem

Configuration Steps in Cloudflare DNS

  1. 1Log in to the Cloudflare Dashboard and select your domain.
  2. 2Navigate to the "DNS" -> "Records" management panel.
  3. 3Locate the dangling CNAME/record for the orphaned subdomain.
  4. 4Click "Edit" and either update the target to an active resource or click "Delete" to remove it.
  5. 5Verify that Cloudflare Proxy (Orange Cloud) is enabled if HTTP proxying is required.

Verification Checklist (RFC 9495)

Verify DMARC enforcement on the root domain (p=quarantine pct=100 or p=reject).
Publish BIMI TXT record at default._bimi.yourcompany.com.
Ensure logo URL points to an SVG Tiny P/S compliant vector graphic.
Attach a Verified Mark Certificate (VMC) from DigiCert or Entrust for full mailbox provider display.
Live Validation Engine

Validate Your Cloudflare DNS BIMI Record

Verify propagation, check syntax formatting, and audit recursive lookups in 60 seconds with SubDomainWatch.

Run Free DNS Validator