BIMI record checker

Look up the BIMI record, test that the logo URL is served over HTTPS as an SVG (logos over 32 KB are flagged), and see whether the domain enforces DMARC, which BIMI depends on.

What BIMI is

BIMI (Brand Indicators for Message Identification) is a way to publish a brand logo for e-mail. The domain publishes a TXT record at default._bimi.<domain>, such as v=BIMI1; l=https://example.com/logo.svg; a=https://example.com/vmc.pem. The l tag is the logo, an SVG in the restricted "SVG Tiny PS" profile, and the optional a tag points to a mark certificate (VMC or CMC) that ties the logo to the organization.

A mailbox provider only considers the record for mail that passes DMARC, from a domain whose DMARC policy is enforced: p=quarantine or p=reject, applied to all mail. A domain with p=none does not qualify, whatever its BIMI record says.

What this tool checks

It reads the BIMI record for the selector you give (default when empty), checks that it starts with v=BIMI1 and has an l tag, requests the logo URL and reports whether it is HTTPS, answers with status 200 and the content type image/svg+xml, whether the file declares the tiny-ps base profile, and how large it is. It reports whether an a tag is present, and it looks up the DMARC record and tells you if the policy meets the precondition.

The mark certificate is not downloaded or validated here. Whether a certificate is required, and which kind, differs between mailbox providers.

What a passing check does not mean

A correct record is a request, not a switch. Each mailbox provider decides on its own whether to display a logo, based on its own rules about certificates, sender reputation and the message at hand. This tool reports whether the published pieces are in order; it cannot tell you that a logo is shown in any inbox.

How to use this tool

  1. Enter the domain. Type or paste a domain name such as example.com. A full URL works too: the scheme, path and a leading www are removed.
  2. Add a selector if you use one. Most domains use the selector "default". Leave the field empty to check it.
  3. Review record, logo and DMARC. The tool validates the record, requests the logo URL and reports the DMARC policy, which must be quarantine or reject.

Command line equivalent

The same check from a terminal. The commands use example.com: replace it with your own name.

  • BIMI recorddig default._bimi.example.com TXT +short
  • Content type of the logocurl -sI https://example.com/logo.svg | grep -i "^content-type"
  • DMARC policydig _dmarc.example.com TXT +short
  • Windowsnslookup -type=TXT default._bimi.example.com

FAQ

How do I check a BIMI record?

Enter the domain above. The tool queries default._bimi.<domain> (or the selector you enter), validates the record and tests the logo URL. From a terminal: dig +short TXT default._bimi.example.com.

Why does BIMI need DMARC?

A logo next to a message is a statement about who sent it, so providers only consider it when the visible From domain is authenticated and the domain tells receivers to quarantine or reject mail that fails. That is what an enforced DMARC policy is.

What are the requirements for the logo file?

An SVG in the SVG Tiny PS profile, square, served over HTTPS with the content type image/svg+xml. Keep it small; the BIMI Group recommends staying under 32 KB.

Do I need a VMC?

It depends on the mailbox providers you care about. Several large providers only consider BIMI with a mark certificate referenced in the a tag; some accept a record without one. Check the current documentation of each provider.

My record passes here. Why is no logo displayed?

Display is each provider's decision and depends on more than the record: certificate requirements, sending reputation, volume and the client. A valid record is necessary, not sufficient.