• BIMI 2.0: What’s New in the BIMI Specification and What It Means for Senders

BIMI 2.0: What’s New in the BIMI Specification and What It Means for Senders

by

Last Updated:
6 min read
BIMI 2.0: What’s New in the BIMI Specification and What It Means for Senders

Key Takeaways

  • There is no official “BIMI 2.0.” The term informally refers to newer revisions of the evolving BIMI IETF draft, which introduce additional capabilities and security rules.
  • New tags add more control over branding. The avp= tag lets senders prioritize brand logos or personal avatars, while lps= enables different logos based on the sender’s local part.
  • VMCs and CMCs are now formally recognized. Common Mark Certificates provide a more accessible alternative for organizations that don’t have a registered trademark required for a VMC.
  • Existing BIMI records remain valid. The new tags are optional, so organizations don’t need to change working BIMI configurations unless they want the added functionality.
  • DMARC enforcement is still essential. BIMI continues to depend on DMARC with a quarantine or reject policy, along with compliant logo files and other existing requirements.
  • BIMI is still evolving. Provider support for newer features such as avp= and lps= remains uneven, while the underlying IETF specification and certificate standards continue to develop.

“BIMI 2.0” is a term you might have heard recently in webinars or vendor blogs, but it is not an official release. The BIMI specification is not versioned using numbers like 2.0. However, the underlying documents have changed significantly. If you published a BIMI record a couple of years ago, you need to be aware of new tags and a new certificate type.

This article covers the current state of the BIMI specification and what it means for senders. Before diving into the updates, you can always review the fundamentals in our complete guide to BIMI.

Is There Actually a BIMI 2.0?

No. The versioning numbers people cite are often misunderstood. For instance, the commonly referenced document draft-blank-ietf-bimi-02 from 2021 is simply the second revision of an early draft, not a version 2.0 release. That specific document has since been replaced and archived.

The live document guiding the industry is the draft-brand-indicators-for-message-identification, which is currently at revision -14 as of May 1, 2026. The confusion exists because vendors sometimes use “BIMI 2.0” informally to describe the newer specifications and capabilities added to this active draft.

The Current BIMI Specification: Status, Authors, and Where It Sits

Despite being implemented by major providers like Gmail, Yahoo, and Fastmail, BIMI is still an individual Internet-Draft. It is not an RFC and is not an official working-group document. It currently holds no formal standing in the IETF standards process.

This gap between widespread industry adoption and formal status is common for email protocols. The real signal of legitimacy comes from the authors drafting the document. The current draft-brand-indicators-for-message-identification is maintained by industry experts: Seth Blank and Peter Goldstein from Valimail, Thede Loder from Skye Logicworks, Terry Zink, Jemma Bradshaw from Fastmail, Alex Brotman from Comcast, and Wei Chuang from Google.

What’s Actually New in the BIMI Specification

The latest revisions introduce new optional tags, formalize certificate types, and tighten security handling.

TagWhat it doesIs it new?
v=Version indicatorNo
l=Logo file locationNo
a=Evidence document locationNo
avp=Avatar PreferenceYes
lps=Local-part SelectorYes

The avp= Tag

The avp tag stands for Avatar Preference. It allows domain owners to tell mailbox providers whether to display the brand logo (avp=brand) or an individual sender’s personal avatar (avp=personal). By explicitly defining this preference, senders remove the guesswork for email clients that support both imagery types. You can read the full breakdown in our guide to the BIMI avp tag.

The lps= Tag

The lps tag stands for Local-part Selector. This addition deserves attention because it solves a major branding challenge. Previously, displaying different logos for different departments required setting up a BIMI-Selector header on outbound mail. The lps tag changes this by allowing the local part of the sending address (the portion before the @ symbol) to dictate the logo choice directly from the DNS record.

For example, you could configure your default BIMI record to point to your primary logo while including an lps tag that specifies distinct selectors for news and payments. When a message arrives from [email protected], the receiving server detects the local part, finds the matching prefix in the lps list, and performs a secondary lookup for that specific selector. This means you can show your main logo for support emails, a different logo for newsletters, and suppress the logo entirely for transactional alerts. Provider support for this tag is still unconfirmed, but it offers a powerful mechanism for multi-logo management.

VMCs and CMCs Formalised

The draft now officially references both Verified Mark Certificates (VMCs) and Common Mark Certificates (CMCs) as optional evidence mechanisms. The detailed specifications for these certificates are deferred to separate documents. The practical difference is substantial for most senders. CMCs do not require a registered trademark, offering a much more accessible path to logo display.
You can learn more by reading about Common Mark Certificates and VMC for BIMI.

Tighter Header Handling

The specification now defines clearer rules for how Mail Transfer Agents construct the BIMI-Location, BIMI-Indicator, and BIMI-Logo-Preference headers. It explicitly requires receiving servers to strip out any untrusted inbound versions of these headers. This is a critical security detail. Without this requirement, attackers could inject forged BIMI headers into messages as a spoofing vector to maliciously display another organization’s logo.

What Hasn’t Changed

While new tags have been added, the foundational rules remain identical. BIMI is not a standalone authentication protocol. It simply displays a visual result based on authentication that has already occurred. For a logo to appear, DMARC enforcement is still strictly required.

You must understand what a DMARC policy is and ensure your domain is set to quarantine or reject. Additionally, your logo image file must still meet the strict SVG Tiny P/S format requirements. You can review all the core requirements in our complete guide to BIMI.

Do You Need to Update Your BIMI Record?

Nothing you have already published is broken. Existing BIMI records remain completely valid under the current draft, and the new tags are entirely optional additions.

You should consider adding the avp tag if your organization has a strict preference regarding corporate brand logos versus personal sender avatars. You should deploy the lps tag only if you actively need to manage per-address logo variations. If you previously skipped BIMI because acquiring a VMC was too expensive or you lacked a registered trademark, the introduction of CMCs means you should definitely revisit your strategy.

The best immediate step is to review your current configuration. If you decide to add these new capabilities, you can build your updated DNS text with our BIMI record generator and read the step-by-step instructions on how to publish a BIMI record.

What’s Still Coming

The standard is still evolving. Separate specification documents detailing VMC and CMC operations remain pending. The IETF has not yet moved BIMI into an official working group.

Furthermore, provider support for the newer avp and lps tags is currently uneven across the industry. For the most accurate updates, monitor the IETF datatracker entry and announcements from the BIMI Group.

Frequently Asked Questions

Is there a BIMI 2.0?

No. The BIMI specification does not use software version numbers like 2.0. The term is informally used by vendors to describe the latest revisions of the IETF draft, which include new features like local-part selectors and avatar preferences.

Is BIMI an RFC or an official standard?

No. BIMI is an individual Internet-Draft. It has not been adopted by an IETF working group and holds no formal standing in the standards process, although major mailbox providers already implement its guidelines.

What is the latest version of the BIMI specification?

The current active specification is draft-brand-indicators-for-message-identification. As of May 1, 2026, the document is at revision -14.

What is the difference between the avp and lps tags?

The avp tag (Avatar Preference) instructs providers whether to display a brand logo or a personal avatar. The lps tag (Local-part Selector) allows you to display different brand logos based on the specific local part of the sending email address.

Do I need to update my BIMI record for the new specification?

No. Your existing BIMI records remain valid and will not break. The newly introduced tags are optional features that you can add if you want more granular control over logo display.

Does BIMI still require DMARC enforcement?

Yes. BIMI display strictly requires your domain to have a DMARC policy set to either quarantine or reject. Messages must pass DMARC authentication for the logo to appear.

Final Thoughts

There is no official BIMI 2.0, but there is a meaningfully updated specification. The latest drafts bring new optional tags, formalize a second certificate type, and tighten header security rules. Your existing published record has not broken, but the new features offer excellent reasons to enhance your setup.

Take a moment to verify your current configuration using our free BIMI record lookup tool to ensure your branding displays exactly as intended.

bimi 2.0