Paths and permitted shapes remain self-contained.
BIMI record
& logo checker
Follow the evidence behind an inbox logo: selector, assertion record, DMARC enforcement, SVG profile, and published certificate chain.
- Live selector and TXT resolution
- DMARC enforcement evidence
- Opt-in SVG and PEM inspection
default._bimi.emailbump.com TXTPlus an exact-domain DMARC TXT lookup. Asset URLs are not requested until you choose to inspect them.
DNS queries use Google Public DNS over encrypted HTTPS with EDNS client subnet disabled. Logo and certificate URLs are fetched only after a second, explicit click.
A DNS record can nominate a logo. The mailbox still decides.
BIMI sits after aligned authentication and enforcement. A valid assertion does not guarantee display, a checkmark, or inbox placement.
BIMI begins after authentication.
A mailbox provider considers BIMI only after the message passes authentication and the visible From domain is covered by an enforcing DMARC policy. It then discovers the selector’s DNS assertion, retrieves the indicator or evidence document, validates it, and applies local display policy.
One visible From identity
Pass + quarantine/reject
Selector + assertion
Evidence + reputation
The first tag and the empty values matter.
The default assertion lives at default._bimi.example.com. The version must be first and exactly v=BIMI1. The required l= tag identifies an HTTPS indicator location or can be empty. The optional a= tag points to HTTPS authority evidence such as a Mark Certificate. Empty l= and a= together are an explicit declination, not a broken record.
v=BIMI1; l=https://assets.example.com/mark.svg; a=https://assets.example.com/mark.pem;v Protocol version
l Indicator location
a Authority evidence
avp Avatar preference
A normal web SVG is not automatically a BIMI SVG.
The SVG Tiny Portable/Secure profile requires an SVG 1.2 document withbaseProfile="tiny-ps", the SVG namespace, and one non-empty direct<title>. It excludes scripting, links, animation, raster images, multimedia, and interactive behavior. The working-group guidance recommends an uncompressed file no larger than 32 KiB and at least two rendered colors.
No scripts, event handlers, links, animation, or remote resources.
A square mark should remain recognizable in a tiny inbox avatar.
A certificate link is not a validated certificate.
VMCs cover registered or government marks, while CMCs can support eligible prior-use marks or modifications under issuer rules. Publishing a PEM URL only says where the evidence can be retrieved. Full verification requires parsing the X.509 chain, checking issuer trust, validity, revocation, domain coverage, policy identifiers, and the embedded logo’s relationship to the separately published indicator.
Confirm an HTTPS URL, retrieve a CORS-readable PEM, count certificate blocks, and report response evidence.
Validate the Mark Certificate chain, mark rights, identity, embedded logo, and receiver-specific acceptance.
Passing the technical checklist does not promise a logo.
BIMI lets a domain nominate a brand indicator. The receiving mailbox owns the interface and can display another image or no image. Provider support, certificate requirements, reputation, authentication on the individual message, complaint history, user context, caching, and rollout policy can all affect display.
- 01Inspect a delivered message.
Confirm one visible From address and an actual DMARC pass at the final receiver.
- 02Verify enforcement.
Use p=quarantine or p=reject, pct=100 when present, and a compatible subdomain policy.
- 03Resolve the correct selector.
Check default unless a trusted, DKIM-covered BIMI-Selector header requests another selector.
- 04Validate both published assets.
Check HTTPS retrieval, redirects, content type, SVG profile, certificate chain, and logo match.
- 05Wait through caches and provider policy.
DNS success is necessary evidence, not an override of a mailbox provider’s display decision.
BIMI checker FAQ.
Does BIMI improve deliverability?+
BIMI is a brand-display mechanism layered on authentication. It does not route mail, repair reputation, or guarantee inbox placement.
Do I need a VMC or CMC?+
The core assertion can be self-asserted, but provider support is limited and some mailbox providers require accepted authority evidence. Check each target provider’s current policy.
Can I use a PNG or ordinary SVG?+
The indicator uses a supported BIMI format. Current practice centers on SVG or SVGZ with the more restrictive SVG Tiny Portable/Secure profile, not PNG and not arbitrary web SVG.
Why does the tool not automatically download my logo?+
The record controls the URL. A second click makes the outbound browser requests explicit and avoids silently contacting third-party asset hosts.
Does a green result guarantee Gmail’s blue checkmark?+
No. Gmail ties its checkmark to an accepted VMC and applies its own requirements. A CMC can support logo display but does not receive the same checkmark treatment.
Authenticate every sending stream.
Bring transactional and marketing email together with domain verification, activity evidence, and clear operational controls.
Start for free