BIMI Checker
Enter a domain to read its default._bimi record, test the DMARC prerequisite and fetch and analyse the SVG logo. Certificate validation and mailbox-provider display rules are outside the test.
Run BIMI check
No sign-up required. Public hosts and addresses only; results show what was observed, nothing is simulated.
What BIMI is
BIMI (Brand Indicators for Message Identification) is a way for a domain to publish a logo that participating mailbox providers may show next to authenticated messages. The domain publishes a TXT record at default._bimi.DOMAIN that starts v=BIMI1 and has an l= tag pointing to an SVG logo over HTTPS, and optionally an a= tag pointing to an evidence document such as a Verified Mark Certificate (VMC).
BIMI is purely a display feature. It does not authenticate mail by itself, and it depends on authentication that already works. Publishing a record never guarantees a logo will appear; that decision belongs to each mailbox provider.
What the tool checks
First, the record: absent (shown as informational because BIMI is optional), duplicated, or present. If the record is absent at the exact name the tool also looks at the organisational domain. Second, the DMARC prerequisite: BIMI needs DMARC at p=quarantine or p=reject with pct=100; the tool runs the same tree walk as the DMARC checker and compares the effective policy. Third, the logo: the tool fetches the l= URL over HTTPS (at most two redirects, each re-checked as a public HTTPS destination), and analyses the file as data without rendering it.
How to read the result
A DMARC finding of 'prerequisite not met' means providers will not show the logo regardless of the rest. A policy of p=none does not qualify, nor does enforcement applied to only part of the mail through a lower pct. When DMARC could not be read because DNS failed, the prerequisite is shown as unknown.
The logo analysis lists the size against a 32 KB limit, the Content-Type, the viewBox, and profile problems. The profile checks are those of SVG Tiny-PS: baseProfile="tiny-ps", version="1.2", a square viewBox, and a title element. Scripts, event handlers, external references, embedded rasters and CSS url() are reported as active content, which providers reject. An empty l= is read as a deliberate decline of BIMI.
Common problems
- DMARC not enforced. The most common reason a BIMI record has no visible effect.
- Logo not Tiny-PS. Logos exported from design tools usually carry the wrong profile, extra metadata or non-square canvas.
- Logo URL redirects or is not HTTPS. Providers fetch it under strict rules.
- Wrong content type. The file should be served as
image/svg+xml. - Duplicate BIMI records. Providers will not use them.
- Assuming the certificate is checked. This tool does not fetch or validate the
a=certificate.
How to approach BIMI safely
Prerequisites: enforced DMARC with all legitimate senders aligned, a finished brand logo, and, if the target mailbox providers require it, a Verified Mark Certificate from a certificate authority. Operational risk: the DMARC step is the dangerous one. Moving to quarantine or reject to enable a logo can block legitimate mail from forgotten senders, so never rush enforcement for a logo. The BIMI record itself is low risk. Rollback: delete the BIMI TXT record or set l= empty; the DMARC policy is a separate decision.
- Complete the staged DMARC rollout described in the DMARC checker and keep
pct=100at the end. - Prepare the logo as SVG Tiny-PS, square, under 32 KB, with no scripts or external references.
- Host it on an HTTPS URL that returns the file directly.
- Publish
v=BIMI1; l=https://example.com/logo.svgatdefault._bimi, addinga=if the providers you care about need a certificate. - Re-run this check. Whether the logo then appears depends on each provider.
What this tool cannot tell you
Verified Mark Certificates are not validated, and mailbox-provider display rules are not tested. A clean result here means the DNS record, DMARC enforcement and logo file meet the checks the tool can perform, not that any inbox will show the logo. Provider requirements, such as whether a VMC or other evidence is needed, differ and change, so confirm them with the providers you target.
Frequently asked questions
Do I need DMARC to use BIMI?
Yes, at an enforcing policy (quarantine or reject) applied to all mail (pct=100). With p=none the logo is not shown.
Does this tool validate my Verified Mark Certificate?
No. It reports whether an a= value exists and is an https URL, but it does not fetch or validate the certificate.
What logo format is needed?
A static SVG Tiny-PS file with a square viewBox, kept under 32 KB, with no scripts or external links.
Will a passing result make my logo appear?
Not necessarily. Providers decide independently, and some require a certificate.
Is BIMI a security control?
No. It is a display feature that rewards good authentication. Spoofing protection comes from SPF, DKIM and DMARC.
Can I opt out of BIMI?
Yes, by publishing the record with an empty l= tag or by not publishing a record.
Written by DNS Tools editorial · Last updated 2026-10-09