Skip to content

BIMI checker: your logo in the inbox

Enter a domain. We check where mailbox providers check: the DMARC gate, the record at default._bimi, the l= logo against SVG Tiny PS, then the a= mark certificate. A certificate displays nothing without the policy underneath it.

DMARC gate checked first SVG Tiny PS linted clause by clause VMC decoded & matched
Why "BIMI: record found" proves nothing

Four setups with no inbox logo

BIMI fails silently by design: no provider tells you why your logo isn't showing. These four setups look correct from the outside and still show nothing.

The logo before the policy

VMC purchased, record published, logo pixel-perfect — and DMARC still says p=none. Every provider checks the gate before the paint, and stops there. Money parked.

gate: closed

The design-tool export

A normal SVG 1.1 file: no tiny-ps profile, no <title>, an external font import. Listing-only checkers say "SVG found ✓". Gmail says nothing, forever.

not Tiny PS

The silent VMC expiry

Mark certificates last a year. When one lapses, the logo quietly reverts to initials — and nobody audits their own avatar in other people's inboxes. Renewal is a calendar problem.

expired = invisible

Expecting it in Outlook

BIMI displays at Gmail, Yahoo, Apple Mail and a handful of others — not Outlook. If your stakeholders live in Microsoft-land, set that expectation before anyone buys a certificate.

coverage ≠ everywhere
Readout decoder

Six BIMI states, decoded

Providers evaluate one prerequisite, one record, one file and one certificate in a fixed order. Where they stop decides what your recipients see.

gate ✓ · Tiny PS ✓ · VMC ✓

The full stack: DMARC enforced, profile-clean logo, valid mark certificate. Displays at Gmail (with the verified tick), Yahoo, Apple Mail.

→ monitor the three expiry dates it now has
DMARC p=none

Providers stop at the gate. Record, logo and certificate are never even fetched. The only fix lives entirely outside BIMI: the DMARC ladder.

→ quarantine → reject, then return here
quarantine, pct<100

Almost. Gmail requires enforcement covering all mail — a rollout dial at pct=60 or an sp=none escape hatch keeps the gate shut.

→ finish the ramp: pct=100, no sp=none
SVG fails Tiny PS

Scripts, external references, missing <title>, no tiny-ps profile, non-square canvas, oversized file — any one clause fails the whole logo at parse time.

→ re-export against the profile — lint below
no a= evidence

"Self-asserted" BIMI. Yahoo may display it for senders with strong reputation; Gmail and Apple require a VMC or CMC. Free to try, limited where it counts.

→ price a CMC — trademark not required
VMC ≠ served logo

The certificate embeds the exact SVG it was issued for. Redesign the logo, forget to re-issue, and the two files no longer match — verification fails quietly.

→ every logo change = a certificate re-issue
The killer detail

The BIMI pipeline, in provider order

BIMI is a chain of five checks, evaluated strictly in sequence. One red light anywhere and the logo simply doesn't appear — no error, no report, no explanation to anyone:

  • 1 · The DMARC gate. Policy at quarantine or reject, effectively at 100%, no sp=none back door. A provider that finds the gate shut never consults BIMI at all.
  • 2 · The record. One TXT at default._bimi, v=BIMI1 first, l= pointing at HTTPS.
  • 3 + 4 · The logo, twice. Fetched — then parsed against SVG Tiny PS. The parse is the killer: a file that renders perfectly in every browser can still fail every clause.
  • 5 · The evidence. The a= certificate chain, validity, and the embedded logo matching the served one byte for byte.
Run my pipeline

VMC · CMC · nothing

the a= evidence, with price tags
VMCVerified Mark Certificate — requires a registered trademark; issued by DigiCert or Entrust; list price $1,000–1,700 a year. Gmail shows the logo and the blue verified tick.
CMCCommon Mark Certificate — no trademark needed, 12 months of prior logo use instead; cheaper. Gmail shows the logo without the verified tick.
noneSelf-asserted — record + SVG only. Yahoo may display it for well-reputed senders; Gmail and Apple won't.
Whichever you buy: the certificate embeds the exact SVG. Change the logo → re-issue the certificate, or verification quietly fails.
For terminal people

What you can check by hand

The record and the files are fetchable by hand. The Tiny PS lint and the cert-to-logo match are the parts worth automating.

Check the gate first (like providers do)dig +short TXT _dmarc.paypal.com
Read the BIMI recorddig +short TXT default._bimi.paypal.com
Eyeball a logo's profile claimscurl -s https://www.paypalobjects.com/marketing/web/logos/paypal_ppe.svg | grep -oE 'baseProfile="[^"]*"|<title>'
Decode the mark certificateopenssl x509 -in mark.pem -noout -issuer -dates
Lint six Tiny PS clauses + match cert to served logo# ↑ that's this tool
FAQ

Common BIMI questions

Type your domain above. We evaluate exactly what a mailbox provider evaluates, in the same order: your DMARC policy (must be quarantine or reject, effectively at 100%), the TXT record at default._bimi.yourdomain, the l= logo linted against 6 SVG Tiny PS clauses, and the a= mark certificate — issuer, validity, and whether the embedded logo matches the served one. Free, no signup.

Start with DMARC. If the policy isn't at enforcement (p=none, quarantine with pct<100, or an sp=none escape) no BIMI-side change can fix it. Next: the SVG isn't Tiny PS profile-clean, there's no VMC or CMC (Gmail requires one), or the certificate expired or no longer matches a redesigned logo. Reputation counts too. Gmail applies BIMI to senders it already trusts, so a brand-new domain waits even with perfect records. Run the check above and we show you which step the pipeline stops at.

For Gmail and Apple Mail — yes, a VMC or CMC. For Yahoo — sometimes not: self-asserted BIMI (record + SVG, no a=) can display there for senders with good reputation. The CMC lowered the barrier: no registered trademark required, just documented prior use of the logo, at a lower price than a VMC. If the trademark paperwork was what stopped you, it no longer has to.

A locked-down SVG profile ("Tiny Portable/Secure") designed so mail clients can render third-party vector files safely. The headline clauses: baseProfile="tiny-ps" declared, a <title> element present, no scripts, no animation, no external references of any kind (fonts, images, CSS imports), a square viewBox, and a small file — keep it under 32 KB. The catch: ordinary design-tool exports satisfy none of this by default, while rendering identically in a browser. That's why "the SVG opens fine" and "the SVG passes" are different claims — we lint 6 of these clauses separately.

Directly — no. BIMI is a display standard: it changes how your mail looks once it has already arrived, not whether it arrives. The real value is indirect: BIMI forces you to DMARC enforcement (a genuine security and deliverability win), the logo can lift open rates (your mail is recognizable in a crowded inbox), and the Gmail verified tick adds a phishing-resistance signal your recipients can see. But anyone selling BIMI as an inbox-placement trick is overclaiming.

Gmail (logo + verified tick with a VMC), Yahoo/AOL, Apple Mail (iOS 16+/macOS Ventura+, certified marks required), Fastmail, La Poste and a growing tail of smaller providers. The notable absence is Microsoft: Outlook and Microsoft 365 don't render BIMI. Plan the business case on Gmail + Apple + Yahoo coverage of your own list. Count the recipient domains you actually send to rather than an industry average.

A selector, exactly like DKIM's. default is what providers look up unless the message carries a BIMI-Selector header naming another — which lets one domain publish multiple marks (a seasonal logo, a sub-brand) and choose per message. Unless you're doing that deliberately, publish at default and forget the header exists. This tool checks the default selector, which is what nearly all mail uses.

Free tools are just the start.
Uptimia keeps your sites healthy.

Uptime, SSL, domain expiry, page speed, transactions — monitored from 171+ locations worldwide. Free for 30 days.

30 days free no credit card cancel anytime free plan after trial
100,000+ websites monitored · GDPR-compliant