Skip to content
Free email tool

BIMI readiness checker.

Validate a BIMI record. The check reads the public DNS record, the DMARC enforcement behind it, the SVG Tiny PS logo, and the mark certificate, so you can fix gaps before a mailbox provider looks.

What this check can tell you

The result reads the BIMI record at default._bimi, the effective DMARC policy, the logo at l=, and the certificate at a=. It reports ready, incomplete, or invalid and lists what to fix. BIMI needs DMARC enforcement first. Run the DMARC checker to see that policy on its own. DMARC passes through aligned SPF or DKIM, so inspect the SPF record and the DKIM key too.

Limit: This cannot prove an email aligned, that a certificate is trusted, or that a mailbox provider will display your logo or checkmark.

How to read the BIMI result

The headline status summarizes the evidence. The findings below it say which piece to fix.

Ready
The DNS record and declared assets are ready for a mailbox provider to evaluate. That is not a promise the provider will display the logo.
Incomplete
A piece is missing or weak: no logo, no certificate, or DMARC that does not enforce.
Invalid
A structural error: a malformed record, a logo or certificate URL that cannot be fetched or parsed, an expired certificate, or a chain out of order.
Effective DMARC
The policy and pct found on the domain or its organizational domain. Eligible means quarantine or reject at 100 percent.
Logo
The l= URL must serve image/svg+xml. The checker parses the file as data, without rendering it, and tests it against SVG Tiny PS.
Mark certificate
The a= URL is parsed as a PEM chain. The result shows VMC or CMC when the certificate says which, its validity dates, and whether the chain is in order.

What BIMI needs, in order

Enforce DMARC. Make sure real mail passes it with aligned SPF or DKIM. Prepare an SVG Tiny PS logo and, for Gmail, a VMC or CMC. Host both over public HTTPS. Then publish the TXT record. Skipping ahead is the usual cause of a failing check: the record can be perfect while DMARC is still at p=none.

Gmail shows its verified checkmark only for senders verified with a VMC. A CMC can support the logo without it. The Gmail BIMI guide covers certificates, logo preparation, and why a valid setup may still not display.

An annotated BIMI record

A record that declares a logo and a certificate chain.

Example BIMI record
default._bimi.example.com.  TXT  "v=BIMI1; l=https://example.com/bimi/logo.svg; a=https://example.com/bimi/certificate.pem"

What each part does

default._bimi
The record name. default is the selector BIMI uses when mail does not name another.
v=BIMI1
The version tag. Publish exactly one record that starts with it.
l=
The HTTPS URL of the SVG Tiny PS logo.
a=
The HTTPS URL of the PEM certificate chain, entity certificate first.

Common BIMI problems and fixes

DMARC is not enforcing
Use quarantine or reject at pct=100, and do not weaken subdomains with sp=none. Confirm the policy with the DMARC checker.
Logo is not valid SVG Tiny PS
Export a well-formed SVG 1.2 Tiny PS file with baseProfile="tiny-ps", a title element, no scripts, animation, or external references, and no x or y on the root.
Logo or certificate cannot be fetched
Serve both over public HTTPS with no login, bot challenge, or private-address redirect. The logo needs image/svg+xml. The certificate needs a PEM content type.
Certificate is not current or not in order
Replace an expired certificate. Serve the PEM chain in entity-to-root order, with the intermediates and root after the entity certificate.
No certificate declared
Self-asserted BIMI has limited receiver support, and Gmail needs a VMC or CMC. Get one from a certificate issuer and add its URL to a=.
Everything is ready and no logo shows
Each mailbox provider decides what to display, and a certificate type can affect what it shows. Send a real message and read its Authentication-Results to confirm alignment.

BIMI questions

Related Resources