cPanel Exim BIMI Implementation: SVG Tiny P/S & VMC Certificate Verification

Display verified brand logos and authentication checkmarks in Gmail, Yahoo, and Apple Mail inboxes by pairing strict DMARC with BIMI and VMC certificates in cPanel.

cPanel Exim BIMI Implementation: SVG Tiny P/S & VMC Certificate Verification

In the modern corporate communications landscape, getting promotional or transactional emails delivered to the inbox is only half the battle. With sophisticated spear-phishing attacks on the rise, enterprise brands and fintech platforms in Pakistan (such as microfinance banks, eCommerce marketplaces, and SaaS providers) face continuous brand impersonation risks.

BIMI (Brand Indicators for Message Identification) elevates email security into an unmistakable trust signal. When implemented, participating email clients—including Gmail, Yahoo Mail, and Apple Mail—display your verified, full-color corporate logo and an authenticated checkmark directly alongside your messages in the recipient’s inbox.

Beyond branding, BIMI provides substantial deliverability advantages: inboxes that display BIMI logos experience up to a 38% increase in open rates and an 80% reduction in spam complaints.

However, implementing BIMI requires strict adherence to cryptographic standards: a 100% aligned DMARC enforcement policy, an XML-compliant SVG Tiny Portable/Secure (SVG Tiny P/S) logo file, and a Verified Mark Certificate (VMC).

In this comprehensive technical guide, we demonstrate how to configure and validate BIMI across your cPanel and Exim hosting infrastructure.


The BIMI Verification Pipeline

Before a mailbox provider renders your brand logo, it evaluates four strict layers of cryptographic validation:

[Inbound Email Received by Gmail / Apple Mail]
                      │
                      ▼
        ┌───────────────────────────┐
        │  Layer 1: SPF & DKIM      │
        │  Alignment with From:     │
        └─────────────┬─────────────┘
                      │
             Authentication PASS?
                      │
                      ▼
        ┌───────────────────────────┐
        │  Layer 2: DMARC Policy    │
        │  p=reject or p=quarantine │
        │  (pct=100 Mandatory!)     │
        └─────────────┬─────────────┘
                      │
             DMARC Enforcement PASS?
                      │
                      ▼
        ┌───────────────────────────┐
        │  Layer 3: Query DNS       │
        │  default._bimi.domain.pk  │
        │  Fetch SVG & VMC Cert     │
        └─────────────┬─────────────┘
                      │
             VMC Validated & Matches?
                      │
                      ▼
       [Render Corporate Logo in Inbox]
     [Verified Blue Checkmark Displayed]

If any single link in this chain fails—such as DMARC being set to p=none, or an SVG containing unauthorized XML tags—the mail client silently falls back to displaying generic sender initials.


Step 1: Enforcing Strict DMARC Policy on cPanel

BIMI strictly disqualifies domains running advisory DMARC policies (p=none or pct less than 100). Your domain must actively instruct receiving servers to block unauthorized mail.

Verify or update your domain’s DMARC TXT record in cPanel Zone Editor:

_dmarc.enterprise.pk.  3600  IN  TXT  "v=DMARC1; p=reject; pct=100; rua=mailto:[email protected]; ruf=mailto:[email protected]; fo=1; aspf=s; adkim=s"

Key DMARC Flags Required for BIMI:

  • p=reject: Strictly rejects unauthenticated spoofed emails. Alternatively, p=quarantine; pct=100 is accepted, but p=reject provides superior protection.
  • pct=100: Must be applied to 100% of outbound messages.
  • aspf=s and adkim=s: Strict alignment ensures the header From: domain matches the envelope sender domain exactly without subdomain inheritance loopholes.

Deploying high-reputation corporate mail systems on dedicated infrastructure like our Dedicated Servers ensures that your sending IPs maintain flawless IP reputation and zero multi-tenant noisy-neighbor interference.


Standard SVG files generated by Adobe Illustrator, Figma, or Inkscape are rejected by BIMI validators. The BIMI working group mandates the SVG Tiny Portable/Secure (SVG Tiny P/S) format (RFC compliant subset) to eliminate security vulnerabilities such as external entity injection, CSS keyframe animations, or embedded scripts.

Strict SVG Tiny P/S Requirements:

  1. Dimensions: Must be a square 1:1 aspect ratio (viewBox="0 0 512 512").
  2. Size: Under 32KB.
  3. No Embedded Fonts: All text characters must be converted to vector vector outlines (<path>).
  4. No External Dependencies: Zero external image URLs or stylesheets.
  5. No Raster Images: Must not embed PNG, JPEG, or Base64 bitmaps.

Example of a valid, secure logo.svg header structure:

<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
<svg version="1.1" id="bimi-logo" xmlns="http://www.w3.org/2000/svg" 
     xmlns:xlink="http://www.w3.org/1999/xlink" 
     x="0px" y="0px" viewBox="0 0 512 512" 
     style="enable-background:new 0 0 512 512;" xml:space="preserve">
  <title>NextGen Enterprise Logo</title>
  <defs></defs>
  <!-- Vector paths only -->
  <circle cx="256" cy="256" r="240" fill="#0d3691" />
  <path fill="#00d4ff" d="M180,140 L332,140 L256,380 Z" />
</svg>

Sanitizing the SVG with Python

You can validate and strip forbidden elements using a lightweight Python script:

import xml.etree.ElementTree as ET

def sanitize_svg(file_path):
    tree = ET.parse(file_path)
    root = tree.getroot()
    # Remove script and style tags
    for elem in list(root.iter()):
        if any(tag in elem.tag.lower() for tag in ['script', 'style', 'foreignobject']):
            root.remove(elem)
    tree.write('sanitized_bimi.svg', encoding='utf-8', xml_declaration=True)

sanitize_svg('raw_logo.svg')

Upload the sanitized file to a public, SSL-secured HTTPS endpoint:

https://enterprise.pk/brand/bimi-logo.svg

Step 3: Verified Mark Certificate (VMC) Integration

While some mail providers (such as Fastmail) support self-asserted BIMI without a certificate, major providers—specifically Google Workspace / Gmail and Apple Mail—require a Verified Mark Certificate (VMC) or Common Mark Certificate (CMC) issued by an authorized CA (such as DigiCert or Entrust).

A VMC cryptographically binds your registered trademark to your domain name and SVG logo.

Once issued, your CA delivers a Privacy-Enhanced Mail (.pem) certificate chain containing:

  1. Your domain ownership validation.
  2. The embedded, cryptographic hash of your SVG logo.
  3. The CA root trust chain.

Upload this bundle to your public web server:

https://enterprise.pk/brand/bimi-cert.pem

Step 4: Publishing the Authoritative BIMI DNS Record

Once your DMARC, SVG, and VMC files are live, publish the authoritative BIMI record in DNS.

Navigate to cPanel -> Zone Editor, and add a TXT record for the sub-domain default._bimi:

default._bimi.enterprise.pk.  3600  IN  TXT  "v=BIMI1; l=https://enterprise.pk/brand/bimi-logo.svg; a=https://enterprise.pk/brand/bimi-cert.pem"

Record Breakdown:

  • v=BIMI1: Specifies the BIMI protocol version.
  • l=https://...: Direct URL to your SVG Tiny P/S logo file.
  • a=https://...: Direct URL to your Verified Mark Certificate (.pem). If deploying without a VMC (self-asserted testing), leave this attribute empty (a=;).

Step 5: Testing & Validating BIMI Alignment

After publishing your DNS record, verify syntax and reachability using dig and curl:

# Query the live BIMI TXT record
dig +short TXT default._bimi.enterprise.pk

# Verify that the SVG serves over HTTPS with clean headers
curl -ILs https://enterprise.pk/brand/bimi-logo.svg | grep -E "HTTP/|content-type"

Ensure the web server returns Content-Type: image/svg+xml.

Next, send an authenticated test email from your cPanel webmail or application to a Gmail inbox. Inspect the email headers:

Authentication-Results: mx.google.com;
  dkim=pass [email protected] header.s=default;
  spf=pass (google.com: domain of [email protected] designates 192.0.2.10 as permitted sender);
  dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=enterprise.pk;
  bimi=pass (bimi=opt-in) header.d=enterprise.pk

Notice the status: bimi=pass. Gmail confirms that your logo and VMC certificate have successfully authenticated, displaying your verified brand logo in the user’s inbox list.

For organizations running multi-tenant mail gateways, high-volume transactional relays, and enterprise hosting environments in Pakistan, evaluate our locally hosted Dedicated Servers in Pakistan.

Elevate Enterprise Email Security with NextGen Dedicated Servers

Protect your brand against phishing while maximizing inbox open rates. NextGen provides high-reputation dedicated IP pools, custom rDNS tuning, and 24/7 technical engineering for corporate mail infrastructures.

Deploy In-Country Dedicated Servers