Check a BIMI record

Enter a domain. The BIMI checker reads the TXT record at default._bimi, validates the logo URL and format, fetches a linked VMC and verifies the DMARC policy without which BIMI has no effect.

What is BIMI?

BIMI (Brand Indicators for Message Identification) displays your brand logo next to your messages in the inbox of Gmail, Yahoo, Apple Mail and other providers. Technically BIMI is a TXT record pointing to an SVG file with the logo and, optionally, to a certificate that confirms the brand entitlement. The display is a reward for clean email authentication: without SPF, DKIM and an enforced DMARC policy no provider shows the logo.

Prerequisites

Before creating a BIMI record, these points must be in place:

  • DMARC with p=quarantine or p=reject on the organisational domain. With p=quarantine, pct must be 100 or absent. p=none is not enough.
  • SPF and DKIM for all sending paths so that DMARC actually passes.
  • A logo as SVG in the Tiny PS profile (Tiny Portable/Secure): square, without external references, without scripts, with the attribute baseProfile="tiny-ps" and a title element.
  • The SVG file reachable over HTTPS, ideally under your own domain.
  • For Gmail and Apple Mail additionally a VMC (Verified Mark Certificate) or CMC (Common Mark Certificate) from DigiCert or Entrust. Yahoo shows the logo without a certificate.

Anatomy of the record

The record lives at default._bimi.example.com. The selector default is the standard; other selectors are possible but must then be named in the BIMI-Selector header of every message. The l= tag holds the logo URL, a= the URL of the certificate in PEM format. An empty l= explicitly means: no logo.

default._bimi.example.com. IN TXT "v=BIMI1; l=https://example.com/bimi/logo.svg; a=https://example.com/bimi/vmc.pem"

How to read the result

  • Logo SVG Tiny PS: file reachable, is SVG and carries the tiny-ps profile. That is how it should look.
  • SVG, but not Tiny PS: the file is a regular SVG, for example exported from Illustrator. Gmail rejects it. Convert the SVG to the Tiny PS profile.
  • Unreachable or not SVG: the URL returns an error, a redirect or a PNG.
  • VMC unreachable: the a= URL does not answer with 200. Without a certificate Gmail shows no logo.
  • DMARC policy missing or p=none: the biggest hurdle. Tighten DMARC first, then BIMI.

Common mistakes

  • Logo not square or with transparency: many providers require an opaque background and a 1:1 format.
  • SVG with an embedded raster image: Tiny PS does not allow base64 images, only vector paths.
  • Certificate for another domain or another logo: the VMC binds the hash of the SVG file. Change the logo and the certificate becomes invalid.
  • Record on a subdomain, DMARC only on the main domain: BIMI is evaluated for the domain in the From header; DMARC must pass there.

Monitor BIMI continuously

BIMI breaks quietly: a relaunch moves the logo file, a certificate expires after a year, someone resets DMARC to p=none. The logo vanishes from the inbox and nobody notices. DomainWarn checks record, logo, certificate and DMARC policy of all client domains regularly and reports changes.

Frequently asked questions

Do I need a VMC?
For Gmail and Apple Mail yes, for Yahoo no. A VMC requires a registered trademark and costs a mid three-figure to low four-figure amount per year. The cheaper CMC does not require a trademark but proof that the logo has been in use for at least twelve months.
Why does Gmail not show my logo despite a valid record?
Usually the certificate is missing, DMARC is at p=none, or the domain has too little reputation yet. Gmail only shows BIMI logos after a sending history with clean authentication.
How do I convert my logo to SVG Tiny PS?
Export it as SVG 1.2 Tiny from a vector tool, set baseProfile="tiny-ps", add a title element and remove all scripts, external links and raster images. The BIMI Group provides a free conversion tool.

Add the BIMI record at IONOS, STRATO, Hetzner, Cloudflare and others

The path to the DNS editor differs by host. For the common providers this shows where you create the BIMI record and what to watch out for.

BIMI record at IONOS

  1. Sign in to the IONOS account and open "Domains & SSL".
  2. Click the gear icon next to the domain and choose "DNS".
  3. Choose "Add record", pick the type (TXT, MX, CNAME) and host name, paste the value, save.
  4. Changes usually apply within minutes; the default TTL is one hour.

Use "@" as the host name for the apex domain; IONOS shows it as the domain name.

BIMI record at STRATO

  1. In the STRATO customer login open "Domains" and then "Domain administration".
  2. Choose "manage" next to the domain and switch to the "DNS settings" tab.
  3. STRATO separates by type: "TXT and CNAME records" for SPF, DKIM, DMARC and verifications, "MX records" for mail delivery.
  4. Enter the value and save; propagation can take up to an hour.

For subdomain records such as _dmarc or selector._domainkey put the prefix into the "Subdomain" field, not into the value.

BIMI record at Hetzner

  1. Open the Hetzner DNS Console (dns.hetzner.com) and select the zone of the domain.
  2. Choose "Add record", enter type, name and value, lower the TTL if needed.
  3. Save; the Hetzner name servers serve the record immediately.

BIMI record at ALL-INKL

  1. Sign in to KAS (the customer administration system) and open "Domain".
  2. Click "edit" next to the domain and then "DNS settings".
  3. "Create new DNS record", enter name (empty for the apex), type and value, save.
  4. ALL-INKL applies changes within minutes.

BIMI record at Cloudflare

  1. In the Cloudflare dashboard open the domain and choose "DNS" → "Records".
  2. Choose "Add record" and enter type, name and content.
  3. For MX, TXT and mail-related CNAME records keep the proxy status on "DNS only"; the orange cloud belongs to web records only.
  4. Save; Cloudflare propagates instantly.

BIMI record at netcup

  1. In the netcup Customer Control Panel (CCP) open "Domains" and select the domain.
  2. Switch to the "DNS" tab and choose "Add new record".
  3. Enter host (@ for the apex), type and destination, then "Save DNS records".

BIMI record at united-domains

  1. In the united-domains portfolio click the domain and open "DNS settings".
  2. Under "Custom DNS records" choose the type, enter subdomain and value.
  3. Save; propagation takes a few minutes.

BIMI record at checkdomain

  1. In the checkdomain customer area open "Domains" and select the domain.
  2. Open "DNS settings" and create a new record with type, name and value.
  3. Save.

BIMI record at domainfactory

  1. In the domainfactory customer menu open "Domains" and select the domain.
  2. Open "Name server settings" and create a new record.
  3. Enter type, host name and value, save.

BIMI record at Alfahosting

  1. In the Alfahosting customer center open the domain and choose "DNS management".
  2. Create a new record with type, name and value, save.

BIMI record at webgo

  1. In the webgo customer portal open "Domains" and choose "DNS management" next to the domain.
  2. Create a record with type, name and value, save.

BIMI record at 1blu

  1. In the 1blu customer service area open "Domains" and choose "DNS settings" next to the domain.
  2. Create a record with type, name and value, save.

BIMI record at Host Europe

  1. In KIS (the customer information system) open "Domain services" and then "Domain administration".
  2. Choose "Name server / DNS" next to the domain and create the record with type, name and value.
  3. Save.

BIMI record at Mittwald

  1. In mStudio open the project and select the domain under "Domains".
  2. Open "DNS", edit or create the record, save.

BIMI record at GoDaddy

  1. At GoDaddy open "My Products" and choose "DNS" next to the domain.
  2. Choose "Add", enter type, name and value, save.

BIMI record at Hostinger

  1. In hPanel open "Domains" and choose "DNS / Nameservers" next to the domain.
  2. In the DNS zone editor create the record with type, name and value.

BIMI record at Amazon Route 53

  1. In the AWS console open Route 53, "Hosted zones" and select the zone.
  2. Choose "Create record", enter name, type and value, set the TTL, "Create records".

BIMI record at Google Cloud DNS

  1. In the Google Cloud console open "Cloud DNS" and select the zone.
  2. "Add record set", enter name, type and value, create.

BIMI record at Azure DNS

  1. In the Azure portal open "DNS zones" and select the zone.
  2. Add a "Record set", enter name, type and value, OK.

BIMI record at OVHcloud

  1. In the OVHcloud control panel open "Web Cloud" → "Domain names" and the domain.
  2. Tab "DNS zone", "Add an entry", choose the type, enter subdomain and value, confirm.

BIMI record at DigitalOcean

  1. In the DigitalOcean dashboard open "Networking" → "Domains" and select the domain.
  2. Choose the type, enter host name and value, "Create Record".

BIMI record at Squarespace

  1. At Squarespace open "Domains", select the domain and open "DNS settings".
  2. Under "Custom records" create the record with type, host and data.

BIMI record at Wix

  1. In the Wix account open "Domains" and choose "Manage DNS records" next to the domain.
  2. Under the matching type choose "Add record", enter host name and value, save.

BIMI record at Shopify

  1. In the Shopify admin open "Settings" → "Domains" and select the domain.
  2. Open "DNS settings", "Add custom record", enter type, name and value, confirm.

BIMI record at INWX

  1. At INWX open "Nameserver" and select the domain.
  2. "Add record", enter type, name and value, save.

BIMI record at dogado

  1. In the dogado customer area open the domain and choose "DNS".
  2. Create the record with type, name and value, save.

BIMI record at Variomedia

  1. In the Variomedia customer menu open the domain and choose "DNS settings".
  2. Create the record with type, name and value, save.

BIMI record at Namecheap

  1. At Namecheap open "Domain List", "Manage" and the "Advanced DNS" tab.
  2. "Add New Record", enter type, host and value, save.

BIMI record at Gandi

  1. At Gandi open the domain and choose "DNS records".
  2. "Add a record", enter type, name and value, create.

BIMI record at Vercel

  1. In the Vercel dashboard open "Domains" and select the domain.
  2. Under "DNS Records" enter type, name and value, "Add".

Guides for this tool

More tools

Free tool

SPF Checker

Free SPF record check and lookup: syntax, includes, the 10 DNS lookup limit and the closing qualifier. Shows whether your domain blocks forged senders.

Open tool →
Free tool

DMARC Checker

Free DMARC record check and lookup: policy (none, quarantine, reject), pct, reporting addresses and syntax errors. With recommendations for moving to p=reject.

Open tool →
Free tool

DNS Checker

Free DNS lookup straight from the authoritative name server: A, AAAA, CNAME, MX, TXT, NS and CAA records at a glance. No sign-up, every record explained.

Open tool →
Free tool

MX Checker

Free MX lookup: which mail servers receive for a domain, do they resolve, is the priority right? Detects missing and unreachable mail servers.

Open tool →
Free tool

SSL Checker

Free SSL certificate check: expiry date, issuer, chain, host name, alternative names and TLS version. Detects expired, self-signed and mismatched certificates.

Open tool →
Free tool

HTTP Header Checker

Free HTTP header check: HSTS, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy with recommendations.

Open tool →
Free tool

Redirect Checker

Free 301 redirect check: every hop with status code and response time, from http to https, from www to non-www. Detects redirect chains, loops and 302s.

Open tool →
Free tool

DKIM Checker

Free DKIM record check and lookup: selector, key type, key length, syntax and revoked keys. Leave the selector empty to try common selectors automatically.

Open tool →
Free tool

DNSSEC Checker

Free DNSSEC test: DS record, resolver validation and broken signature chains. Shows whether validating resolvers like Google or Cloudflare reach your domain.

Open tool →
Free tool

MTA-STS Checker

Free MTA-STS check: DNS record, policy file, mode, max_age and whether your MX servers are covered. Shows whether inbound mail enforces TLS.

Open tool →
Free tool

TLS-RPT Checker

Free TLS-RPT record check: syntax, reporting addresses (rua) and common errors such as a missing record. Shows whether you get reports on TLS failures.

Open tool →
Free tool

Blacklist Check

Free IP blacklist and domain blacklist check: mail server IPs, website IP and domain against Spamhaus, Spamcop, Barracuda, PSBL and SURBL. With delisting links.

Open tool →
Free tool

Domain Checker

Free domain check: expiry date, registrar, EPP status, transfer lock and name servers straight from the registry via RDAP. Warns about expiry and holds.

Open tool →