BIMI readiness checker.
Validate a BIMI record. The check reads the public DNS record, the DMARC enforcement behind it, the SVG Tiny PS logo, and the mark certificate, so you can fix gaps before a mailbox provider looks.
What this check can tell you
The result reads the BIMI record at default._bimi, the effective DMARC policy, the logo at l=, and the certificate at a=. It reports ready, incomplete, or invalid and lists what to fix. BIMI needs DMARC enforcement first. Run the DMARC checker to see that policy on its own. DMARC passes through aligned SPF or DKIM, so inspect the SPF record and the DKIM key too.
Limit: This cannot prove an email aligned, that a certificate is trusted, or that a mailbox provider will display your logo or checkmark.
How to read the BIMI result
The headline status summarizes the evidence. The findings below it say which piece to fix.
- Ready
- The DNS record and declared assets are ready for a mailbox provider to evaluate. That is not a promise the provider will display the logo.
- Incomplete
- A piece is missing or weak: no logo, no certificate, or DMARC that does not enforce.
- Invalid
- A structural error: a malformed record, a logo or certificate URL that cannot be fetched or parsed, an expired certificate, or a chain out of order.
- Effective DMARC
- The policy and pct found on the domain or its organizational domain. Eligible means quarantine or reject at 100 percent.
- Logo
- The
l=URL must serveimage/svg+xml. The checker parses the file as data, without rendering it, and tests it against SVG Tiny PS. - Mark certificate
- The
a=URL is parsed as a PEM chain. The result shows VMC or CMC when the certificate says which, its validity dates, and whether the chain is in order.
What BIMI needs, in order
Enforce DMARC. Make sure real mail passes it with aligned SPF or DKIM. Prepare an SVG Tiny PS logo and, for Gmail, a VMC or CMC. Host both over public HTTPS. Then publish the TXT record. Skipping ahead is the usual cause of a failing check: the record can be perfect while DMARC is still at p=none.
Gmail shows its verified checkmark only for senders verified with a VMC. A CMC can support the logo without it. The Gmail BIMI guide covers certificates, logo preparation, and why a valid setup may still not display.
An annotated BIMI record
A record that declares a logo and a certificate chain.
default._bimi.example.com. TXT "v=BIMI1; l=https://example.com/bimi/logo.svg; a=https://example.com/bimi/certificate.pem"What each part does
default._bimi- The record name. default is the selector BIMI uses when mail does not name another.
v=BIMI1- The version tag. Publish exactly one record that starts with it.
l=- The HTTPS URL of the SVG Tiny PS logo.
a=- The HTTPS URL of the PEM certificate chain, entity certificate first.
Common BIMI problems and fixes
- DMARC is not enforcing
- Use quarantine or reject at pct=100, and do not weaken subdomains with
sp=none. Confirm the policy with the DMARC checker. - Logo is not valid SVG Tiny PS
- Export a well-formed SVG 1.2 Tiny PS file with
baseProfile="tiny-ps", a title element, no scripts, animation, or external references, and no x or y on the root. - Logo or certificate cannot be fetched
- Serve both over public HTTPS with no login, bot challenge, or private-address redirect. The logo needs
image/svg+xml. The certificate needs a PEM content type. - Certificate is not current or not in order
- Replace an expired certificate. Serve the PEM chain in entity-to-root order, with the intermediates and root after the entity certificate.
- No certificate declared
- Self-asserted BIMI has limited receiver support, and Gmail needs a VMC or CMC. Get one from a certificate issuer and add its URL to
a=. - Everything is ready and no logo shows
- Each mailbox provider decides what to display, and a certificate type can affect what it shows. Send a real message and read its Authentication-Results to confirm alignment.