Suped

Why did BIMI disappear from Gmail and when will it be restored?

Published 6 Jun 2025
Updated 28 Jul 2026
10 min read
Summarize with
Gmail inbox with a missing BIMI logo and verified checkmark.
Updated on 28 Jul 2026: We updated this guide for Gmail's current certificate rules and RFC 9989, with clearer BIMI restoration checks.
During the June 6-7, 2023 incident, Gmail temporarily stopped showing BIMI logos and verified checkmarks on some newly received messages. Older messages from the same domains often kept both. Gmail did not publish a detailed root cause, but the cross-brand pattern showed a receiver-side display problem rather than simultaneous authentication failures at every affected sender. Recovery began late on June 6, and many affected senders reported normal display again on June 7.
That historical timeline is not a restoration promise for a current incident. If BIMI disappears across several unrelated brands at the same time, investigate a Gmail-side display issue. If it disappears only for your domain, verify DMARC alignment, DKIM, the BIMI DNS record, the SVG logo, and the VMC or CMC certificate path before waiting for Gmail.
  1. Gmail did not publish a root cause for the June 2023 incident; the shared timing across brands identified it as a receiver-side display problem.
  2. Gmail restores visibility when its checks accept a new message again, and a sender cannot force that display decision.
  3. Confirm that authentication and BIMI assets are clean, keep normal mail flowing, and avoid unnecessary DNS changes.

What likely happened inside Gmail

Gmail does not show a BIMI logo just because a sender publishes a BIMI record. Gmail receives the message, evaluates SPF and DKIM, checks DMARC alignment and policy, looks up the BIMI record, validates the logo and certificate, then decides whether to show the logo and any associated checkmark in its interface.
The June 2023 pattern differed from a normal sender misconfiguration. Old messages still had the logo and checkmark while new messages from unrelated domains did not. Reports covered messages with multiple DKIM signatures and messages with a single signature. That evidence supports a temporary receiver-side display failure, but it does not establish Gmail's internal root cause.
Authentication and display are separate results
A message can pass DMARC and still lose the visible Gmail logo because Gmail controls the final BIMI display. Check authentication first, then compare old and new messages from the same brand.
Gmail BIMI display flow through authentication, DMARC, logo, and certificate checks.
Gmail BIMI display flow through authentication, DMARC, logo, and certificate checks.

Why multiple DKIM signatures were a clue

A message with multiple DKIM signatures has more than one DKIM-Signature header. That often happens when an email platform signs with its domain and the brand also signs with an aligned sending domain. Multiple DKIM signatures are valid. For DMARC, one passing signature with an aligned signing domain can provide the required DKIM result.
Community reports during the June 2023 incident often mentioned double-signed mail, so it was a useful diagnostic clue. Single-signed messages also lost BIMI display. The number of signatures did not establish the cause, and removing a valid signature is not a BIMI fix.
Normal BIMI path
  1. The message passes DMARC through an aligned SPF or DKIM result.
  2. The domain publishes an enforcing DMARC policy of quarantine or reject.
  3. Gmail accepts the BIMI logo, certificate, and sender eligibility.
Observed incident path
  1. The message continued to pass normal authentication checks.
  2. Reports often noted multiple signatures, but single-signed mail was affected too.
  3. Gmail suppressed the logo on some newly received messages.
Gmail message passing SPF, DKIM, and DMARC without a BIMI logo.
Gmail message passing SPF, DKIM, and DMARC without a BIMI logo.

VMC, CMC and Gmail's verified checkmark

Gmail has accepted Common Mark Certificates (CMCs) since September 2024, alongside Verified Mark Certificates (VMCs). A valid VMC makes an eligible sender's logo and verified checkmark available in Gmail. A valid CMC makes the logo available without the checkmark. A CMC sender whose logo appears without a checkmark is seeing the expected result, not a BIMI outage.

Certificate

Logo eligibility

Verified checkmark

Logo basis

VMC
Yes
Eligible
Registered trademark accepted by the issuer
CMC
Yes
No
Eligible non-trademarked mark accepted by the issuer
Current Gmail display differences
Gmail supports the VMC checkmark on the web and in its Android and iOS apps. A different mail app connected to a Gmail account has its own interface behavior. Certificate eligibility also does not guarantee display on every message because Gmail still applies sender eligibility and abuse controls.

How to tell if it is Gmail or your domain

Start by separating broad receiver behavior from a domain-specific failure. If unrelated brands lose BIMI in Gmail at the same time and older messages still show their logos, the evidence points to Gmail. If only one brand loses it, check that domain's authentication and certificate path, including its hosted BIMI assets.
Suped's DMARC monitoring keeps authentication evidence separate from the inbox logo. Use it to confirm whether DMARC alignment or an approved sending source changed before treating the problem as a Gmail interface event.
  1. Compare old and newly received mail from the same sender in Gmail.
  2. Inspect the headers and confirm that DMARC passes for the visible From domain.
  3. Validate the BIMI TXT record, both hosted URLs, and the certificate status.
  4. Check whether unrelated senders show the same disappearance in the same Gmail interface.
?

What's your domain score?

Deep-scan SPF, DKIM & DMARC records for email deliverability and security issues.

For a quick authentication check, use the domain health check to confirm that SPF or DKIM produces an aligned DMARC pass. If that result is clean, a focused DMARC checker confirms the policy and reporting record.

Configuration checks that still matter

A Gmail-side display problem does not remove the need for a correct BIMI setup. Gmail will not restore a logo for a domain that fails its underlying requirements. Work through these checks before changing a record.

Area

Check

Result

DMARC
Enforced
Policy is quarantine or reject, with no testing mode.
DKIM
Aligned
At least one signature passes and aligns; no DKIM body-length tag is used.
BIMI
Published
The default selector points to the intended logo and PEM files.
Logo
Valid
SVG Tiny PS uses absolute dimensions of at least 96 by 96 pixels.
Certificate
Current
The VMC or CMC is valid, and its PEM file includes the required chain.
Hosting
Reachable
HTTPS serves the files from the same domain as the BIMI record.
Core checks before blaming Gmail
Example DMARC record for BIMI eligibilitydns
_dmarc TXT "v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com;"
Self-asserted BIMI record not supported by Gmaildns
default._bimi TXT "v=BIMI1; l=https://assets.example.com/bimi.svg; a="
Gmail BIMI record with a VMC or CMCdns
default._bimi TXT "v=BIMI1; l=https://assets.example.com/bimi.svg;" " a=https://assets.example.com/mark.pem"
A domain at p=none is not eligible for BIMI in Gmail. RFC 9989 removed the former pct tag, so current DMARC records should omit it and apply the published policy in full. Gmail's help still describes this legacy requirement as pct=100; under the older specification, omitting the tag also meant 100 percent. If policy staging is the blocker, Suped's hosted DMARC helps review authentication evidence before moving the policy to enforcement.
Avoid changing records too quickly
When Gmail has a display issue, rapid DNS edits create noise. Change a record only when a check fails. A clean setup that lost display during a Gmail event usually needs fresh-message testing and time for receiver rechecks, not a new selector or logo path.

What to do while waiting

There is no sender-side switch that tells Gmail to restore BIMI immediately. Keep the domain stable, send normal mail, and monitor for real authentication changes. Suped's product keeps DMARC sources and authentication results together while you compare newly received Gmail messages. Its issue workflow helps distinguish a Gmail display problem from a sender-side failure.
Issue steps to fix dialog showing the issue overview, tailored fix steps, and verification action
Issue steps to fix dialog showing the issue overview, tailored fix steps, and verification action
A missing Gmail logo can trigger rushed changes to DNS and brand assets. Use the evidence to determine whether anything actually broke. If the domain still passes authentication and its BIMI files remain valid, the response differs from a real alignment failure or expired certificate.
Do this
  1. Save full headers and screenshots of old and newly received messages.
  2. Track DMARC pass rates and approved source changes.
  3. Send one clean campaign or transactional test after each confirmed fix.
Avoid this
  1. Do not rotate DNS records without a failing check.
  2. Do not replace the SVG only because Gmail hid it.
  3. Do not move DMARC back to monitoring mode.

When Gmail restores BIMI

For a Gmail-side incident, restoration happens when Gmail re-enables or adjusts the affected display check. Gmail does not publish a per-domain timer, and recovery can appear gradually as new messages arrive. During the June 2023 incident, community reports described double-signed messages regaining their logos and checkmarks late on June 6, followed by broader recovery on June 7.
BIMI restoration expectations
Use the cause of the disappearance to set the right expectation.
Gmail display incident
Receiver controlled
No sender-side control exists. Watch newly received messages and compare unrelated brands.
DNS or asset change
TTL plus recheck
Gmail must retrieve the current record and revalidate its hosted files.
Domain failure
Until fixed
BIMI remains hidden until the failed authentication or certificate requirement is corrected.
For a domain-specific issue, restoration begins only after the failed requirement is fixed and Gmail receives a new message that passes its checks. DNS TTL and receiver caching affect timing. Gmail must also retrieve the hosted files and validate the certificate again, so a corrected record does not update every inbox immediately.
If the logo remains missing after authentication is clean, compare the issue with common Gmail-specific BIMI cases such as a BIMI logo missing despite a certificate, or normal BIMI setup time after a fresh implementation.

Views from the trenches

Best practices
Compare old and new Gmail messages before changing BIMI or email authentication records.
Keep a clean test sender ready so you can verify Gmail display changes without campaign noise.
Use DMARC evidence first, then treat the Gmail logo as a receiver display signal only.
Common pitfalls
Changing the SVG path during a Gmail pause can create cache noise and delay diagnosis.
Assuming double DKIM is always broken misses cases where single-signed mail is affected.
Rolling DMARC back to monitoring mode removes a core BIMI requirement and hides the cause.
Expert tips
Save full headers when the logo disappears so you can separate authentication from display.
Check multiple unrelated senders in Gmail to confirm whether the behavior is receiver-wide.
Wait for fresh inbound mail after fixes, since old messages do not prove current behavior.
Marketer from Email Geeks says Gmail appeared to pause BIMI checks for new inbound mail when the same senders had logos and checkmarks on older messages.
2023-06-06 - Email Geeks
Marketer from Email Geeks says the issue was highly visible on double DKIM signed messages, but later evidence showed it was not limited to them.
2023-06-06 - Email Geeks

Frequently asked questions

DMARC monitoring

Start monitoring your DMARC reports today

Suped DMARC platform dashboard
What you'll get with Suped
Real-time DMARC report monitoring and analysis
Automated alerts for authentication failures
Clear recommendations to improve email deliverability
Protection against phishing and domain spoofing