BIMI Lookup
BIMI Lookup helps you check brand indicators for message identification, for email authentication analysis, policy checks, and delivery troubleshooting.
Advertisement · Anuncio
Advertisement · Anuncio
Technical Analysis & Guide
What It Does
The BIMI checker queries the TXT record at default._bimi.<domain>, keeps only strings beginning with v=BIMI1 and parses the l= (logo) and a= (authority evidence) tags. It verifies that the logo URL is HTTPS and ends in .svg, that the authority URL is HTTPS when present, and that only one BIMI record exists. It reads DNS only; the SVG file, the mark certificate and your DMARC policy are not downloaded or evaluated here.

Why It Matters
- →Inbox recognition: Gmail, Apple Mail and Yahoo can show your logo in the avatar slot, which makes legitimate messages easier to pick out from look-alike senders.
- →Proof of DMARC enforcement: Mailbox providers only honor BIMI for domains at quarantine or reject, so a working logo is visible evidence the domain cannot be trivially spoofed.
- →Certificate spend protection: A VMC or CMC costs money and weeks of validation; a broken TXT record or HTTP logo URL wastes that investment silently.
- →Phishing resistance for customers: Banks and retailers use the verified checkmark in Gmail as a cue that the message really came from them.
- →Brand consistency: The same SVG appears across clients, so a correctly sized square logo avoids cropped or distorted marks in the inbox.
How to Read Results
- WARN 'No BIMI record found': Nothing beginning with v=BIMI1 exists at default._bimi; lookupDomain shows the exact name we queried.
- FAIL 'Multiple BIMI records': More than one v=BIMI1 string at the same name; receivers cannot pick one, so the record list is shown for cleanup.
- logoUrl: The l= value. Missing or non-HTTPS is a critical issue; an HTTPS URL that does not end in .svg is a warning because the format must be SVG Tiny PS.
- authorityUrl: The a= value pointing to a PEM file with your VMC or CMC. Absent means a warning, since Gmail and Apple require evidence; a non-HTTPS URL is a critical issue.
- PASS: Version, logo and authority tags are all present and well-formed at the DNS level; it does not confirm the SVG validates or that the certificate matches the logo and domain.
Technical Background
Brand Indicators for Message Identification is published by the AuthIndicators Working Group and progressing as an IETF Internet-Draft, so it is not yet an RFC. A receiver looks up a TXT record at <selector>._bimi.<domain>, where the selector is default unless the message carries a BIMI-Selector header. A typical record reads: v=BIMI1; l=https://example.com/brand/logo.svg; a=https://example.com/brand/vmc.pem. If the exact From domain has no record, the receiver falls back to the organizational domain. A record of v=BIMI1; l=; a=; is a deliberate declination that tells receivers not to show any logo.
BIMI rides entirely on DMARC (RFC 7489). The message must pass DMARC, and the policy at the organizational domain must be p=quarantine or p=reject, with pct=100 (the default when pct is omitted). A subdomain policy of sp=none disqualifies the domain as well. A domain at p=none, or quarantining only 50 percent of failures, will not get a logo no matter how perfect the BIMI record is. This requirement is intentional: a logo should only appear when the sender has proven nobody else can send as that domain.
The logo must be an SVG in the SVG Tiny Portable/Secure profile: root element with version 1.2 and baseProfile tiny-ps, a title element, a square viewBox, no scripts, no external references, no animation and no embedded raster images. Exporting from a design tool usually produces plain SVG 1.1, which is rejected, so the file must be converted and checked. Keep it small (the draft and providers suggest staying under 32 KB) and served over HTTPS with a valid certificate.
The a= tag carries the evidence document. A Verified Mark Certificate (VMC) is an X.509 certificate embedding your logo, issued only after a mark verifying authority confirms a registered trademark and the applicant's identity. A Common Mark Certificate (CMC) follows the same format for logos that are not trademarked but have been publicly used for at least a year; Gmail accepts CMCs but does not show the blue verified checkmark for them. Gmail and Apple Mail (iOS 16, macOS Ventura and later) require a VMC or CMC as applicable, while Yahoo may display a logo for self-asserted records from senders with sufficient volume and reputation.
Because this tool reads only DNS, complete the picture by running the DMARC check on the organizational domain, validating the SVG against the tiny-ps profile, and confirming the PEM chain and logo hash with openssl.
Common Errors and How to Fix Them
- ProblemThe BIMI record is valid but no logo appears because DMARC is still p=none or uses pct=25 during a rollout.
- FixMove the organizational domain to p=quarantine or p=reject with pct=100 (or remove pct), make sure sp is not none, and wait for DMARC aggregate reports to confirm legitimate sources pass.
- ProblemThe logo was exported from a design tool as standard SVG 1.1 with embedded fonts or a PNG inside.
- FixConvert it to SVG Tiny PS: set version 1.2 and baseProfile tiny-ps, add a title element, outline text, remove scripts, external links and raster images, and use a square viewBox.
- ProblemThe l= URL points to a CDN path that redirects or returns text/html, so receivers cannot fetch the logo.
- FixServe the file directly over HTTPS with Content-Type image/svg+xml and no redirects, then retest with curl -I.
- ProblemThe VMC PEM at the a= URL contains only the leaf certificate, so Gmail cannot build the chain.
- FixPublish the full PEM provided by the issuer, including intermediate certificates in order, and make sure the logo embedded in the certificate is byte-identical to the l= file.
- ProblemTwo TXT records with v=BIMI1 exist at default._bimi after switching vendors, and the checker reports a failure.
- FixDelete the outdated record so exactly one v=BIMI1 string remains at the selector.
Frequently Asked Questions
Do I need a VMC to use BIMI?
It depends on the mailbox provider. Gmail requires either a Verified Mark Certificate, which needs a registered trademark, or a Common Mark Certificate for logos with at least a year of public use. Apple Mail requires a VMC. Yahoo can show logos from self-asserted records without a certificate for senders with good reputation and volume. Without a certificate, expect the logo to appear only in some inboxes.
Why is my BIMI logo not showing in Gmail?
The usual causes are a DMARC policy below quarantine or with pct under 100, an SVG that is not in the Tiny PS profile, a missing or incomplete certificate chain at the a= URL, or the message failing DMARC alignment. Gmail also needs a sending history; after fixing everything, logos may take days to appear, and they are cached once displayed.
What DMARC policy does BIMI require?
The organizational domain must publish p=quarantine or p=reject, and the policy must apply to all mail, meaning pct=100 or no pct tag. A subdomain policy of sp=none disqualifies BIMI. Each message must also pass DMARC through aligned SPF or DKIM. Monitoring-only p=none is not enough, because it does not stop spoofed mail from reaching inboxes.
What is SVG Tiny PS and how is it different from a normal SVG?
SVG Tiny Portable/Secure is a restricted profile of SVG Tiny 1.2 defined for BIMI. The file must declare baseProfile tiny-ps, include a title, use a square aspect ratio and avoid scripts, animations, external references and embedded bitmaps. Ordinary SVG exports from design tools typically break several of those rules and are ignored by receivers.
Can I use a different selector than default?
Yes. Publish another record such as brand2._bimi.example.com and add a BIMI-Selector header to messages that should use it, for example v=BIMI1; s=brand2. Receivers without that header use default. This checker queries only default._bimi, so test custom selectors with dig directly.
Academic Documentation
Protocol context and primary references
DMARC.org
Domain-based Message Authentication standard
Open source →
SPF Project
Sender Policy Framework documentation
Open source →
IETF
Internet Engineering Task Force
Open source →
RFC Editor
Official RFC documentation
Open source →
IANA
Internet Assigned Numbers Authority
Open source →
M3AAWG
Operational guidance for email authentication and abuse handling.
Open source →
REST API Documentation
v1.0GET /api/tools/bimi
curl -X POST https://epcybertools.com/api/tools/bimi \
-H "Content-Type: application/json" \
-d '{"domain":"google.com"}'
{
"success": true,
"results": [
{ "test": "Sample Check", "status": "pass", "message": "All clear" }
]
}
Usage Examples
# BIMI record at the default selector
dig +short TXT default._bimi.example.com
# Confirm the logo is served over HTTPS as image/svg+xml
curl -sI https://example.com/brand/logo.svg | grep -i content-type
# Inspect the DMARC policy BIMI depends on
dig +short TXT _dmarc.example.com