Email Security BIMI_NO_VMC_ENFORCEMENT

The BIMI Bypass: Displaying a Fake Brand Logo Without a VMC

Published October 10, 2026 Updated October 10, 2026

The BIMI Bypass: Displaying a Fake Brand Logo Without a VMC

Summary

BIMI (Brand Indicators for Message Identification) was designed to let organizations display their verified logo next to authenticated email in a recipient's inbox. The trust signal it conveys depends entirely on two things happening correctly: DMARC enforcement at the sending domain, and a Verified Mark Certificate (VMC) proving legal ownership of the logo. Several major mail clients render BIMI logos under weaker conditions than the specification intends, or fail open when VMC validation cannot be completed. This gap lets an attacker register a lookalike domain, publish a bare BIMI record pointing to a scraped logo, and have that logo appear in a victim's inbox next to spoofed or phishing mail: no certificate, no legal attestation, no cost beyond domain registration and DNS hosting.

How BIMI is supposed to work

A domain publishes a BIMI record at default._bimi.<domain>:

default._bimi.acmebank.com. IN TXT "v=BIMI1; l=https://static.acmebank.com/logo.svg; a=https://static.acmebank.com/vmc.pem"

Two fields matter:

  • l=: the logo URL, which must be an SVG in the SVG Tiny Portable/Secure profile.
  • a=: the authority evidence field, pointing to a VMC (or CMC for some regions) issued by a CA such as DigiCert or Entrust, cryptographically binding the logo to a registered trademark and the sending organization.

BIMI itself has a hard prerequisite that many people gloss over: the domain must have a DMARC policy of p=quarantine or p=reject with 100% enforcement (pct=100), and mail must pass DMARC alignment. BIMI logo display is not a standalone feature: it's a reward layered on top of an already-enforced anti-spoofing posture. If DMARC isn't enforcing, BIMI has no business appearing at all.

The attack

The attack doesn't require breaking cryptography or compromising a legitimate domain. It abuses two independent weak points:

  1. Lookalike domain registration. The attacker registers something visually close to a trusted brand, such as acme-bank.com, acmebnk.com, or a homoglyph variant. This costs the price of a domain and takes minutes.

  2. Publishing BIMI without a VMC. The BIMI spec allows the a= field to be omitted entirely, or points to it and lets clients decide what to do when the certificate check fails. The attacker sets up:

default._bimi.acme-bank.com. IN TXT "v=BIMI1; l=https://cdn.attacker-host.net/acme-logo.svg"

The SVG at that URL is a byte-for-byte (or near-identical) copy of the real Acme Bank logo, scraped from the legitimate site's brand assets page or a press kit. No CA involvement, no domain-to-trademark binding, no vetting process.

  1. Minimum viable DMARC enforcement. Because DMARC alignment is the one gate several clients do check, the attacker sets up SPF and DKIM for the lookalike domain and publishes:
_dmarc.acme-bank.com. IN TXT "v=DMARC1; p=reject; pct=100; rua=mailto:[email protected]"

This is trivial: DMARC enforcement only requires the attacker to control their own DNS and mail-sending infrastructure, which they do, since it's their own domain. The "enforcement" is real from a protocol standpoint; it just enforces on a brand the attacker doesn't own.

  1. The client-side gap. Some mail clients render the BIMI logo as soon as DMARC alignment passes and a syntactically valid SVG resolves at l=, treating VMC validation as advisory, caching it asynchronously, or skipping the check client-side entirely and deferring to mailbox provider infrastructure that may not enforce it uniformly across delivery paths, mobile apps, or preview panes. Some webmail and mobile clients have historically shown the logo from l= without a strict, real-time VMC check, particularly outside the U.S./EU CA ecosystem, where VMC issuance is inconsistent.

The net effect: a phishing email from [email protected] arrives with Acme Bank's real logo rendered next to the sender name, increasing perceived legitimacy and click-through on credential-harvesting links.

What it costs the organization

The impersonated brand bears the damage even though its own infrastructure was never touched. Logo presence is a strong, fast trust heuristic for users, and BIMI was built on that assumption, so the attack weaponizes it directly. Trademark misuse in a fraud campaign creates reputational harm and potential regulatory or notification obligations if credentials or personal data are harvested under the brand's visual identity. Once a lookalike domain successfully displays the logo, security teams and customers alike lose confidence in "verified logo = safe," undermining the return on the organization's own legitimate VMC investment. And because the lookalike domain is unrelated infrastructure, the brand owner typically only learns about it through customer reports or takedown requests, not through their own monitoring, unless third-party or lookalike-domain monitoring is already in place.

How validation and monitoring catch it

SetEnforce's BIMI check does not treat a syntactically valid BIMI TXT record as sufficient. Validation should verify, in order:

  1. DMARC prerequisite chain: confirm p=quarantine/p=reject at pct=100 on the domain actually presenting the BIMI record, not merely that a DMARC record exists somewhere.
  2. VMC presence and chain validity: fetch the a= certificate, verify it chains to a trusted CA root, confirm the certificate's Subject references the exact domain and organization, and check expiry and revocation.
  3. Logo-to-certificate binding: confirm the SVG hash embedded or referenced by the VMC matches the SVG actually served at l=, catching cases where a valid old certificate is paired with a swapped logo.
  4. Domain reputation and lookalike detection: cross-reference the registering domain against known trademarks and existing brand domains using edit-distance/homoglyph analysis, flagging domains that publish a BIMI logo visually matching a monitored brand while lacking a VMC issued to that brand's legal entity.
  5. Missing a= field as a hard fail, not a warning: for organizations opting into strict BIMI compliance scoring, absence of VMC evidence should downgrade the standard result to non-compliant/fail rather than "partial pass," since a logo without VMC provides zero brand assurance regardless of DMARC posture.

Continuous monitoring matters more than point-in-time checks here, because attackers rotate lookalike domains quickly. A daily or hourly sweep of DNS, certificate transparency logs, and newly registered domains against a brand's protected mark list catches new instances faster than customer complaints do.

Mitigation steps

For domain owners protecting a brand:

  • Obtain and correctly deploy a VMC for every domain that legitimately sends brand-identified mail, and confirm the certificate's Subject Organization matches exactly.
  • Enforce DMARC at p=reject; pct=100 before enabling BIMI. BIMI without DMARC enforcement is a misconfiguration on its own.
  • Register and monitor lookalike and homoglyph domains proactively (typosquat variants, hyphenated variants, alternate TLDs), and pursue takedown promptly when a BIMI record referencing your logo appears on unauthorized infrastructure.
  • Monitor Certificate Transparency logs for VMC issuance events referencing your organization name, to catch misissuance or unauthorized certificate requests early.
  • Audit BIMI records for subdomains and legacy domains you still control. An unmonitored subdomain with a stale or absent VMC is an internal instance of the same weakness.

For platforms and mail clients:

  • Never render a BIMI logo without successful, synchronous VMC chain validation at time of display, or at minimum at time of last DNS/cert refresh with a short TTL.
  • Fail closed: if VMC validation cannot complete (timeout, revoked, expired, mismatched Subject), suppress the logo rather than falling back to displaying it.
  • Log and expose validation failures to security teams via header annotations or admin consoles, rather than silently degrading to logo-blank.

Key takeaways

  • BIMI's trust guarantee lives entirely in the VMC and DMARC enforcement: the logo image itself proves nothing.
  • Attackers can exploit clients that render logos on DMARC-pass-only or best-effort VMC checks, bypassing certificate issuance entirely.
  • The financial and reputational cost lands on the impersonated brand, not the attacker's infrastructure.
  • Effective validation must check the full chain, DMARC enforcement, VMC validity, and logo-to-certificate binding, and fail closed on any gap.
  • Proactive lookalike-domain and Certificate Transparency monitoring closes the detection lag that lets this attack persist unnoticed.