BIMI record syntax
Review v=BIMI1, duplicate tags, the logo URL and the certificate URL.
Check the BIMI TXT record, logo URL and DMARC prerequisites.
Brand email authentication
Brand Indicators for Message Identification lets a domain publish a brand logo for supporting inboxes. BIMI builds on SPF, DKIM and DMARC; it does not replace those authentication controls.
This checker queries selector._bimi, parses the logo and authority evidence URLs, and verifies that DMARC uses quarantine or reject with full policy coverage.
Review v=BIMI1, duplicate tags, the logo URL and the certificate URL.
Confirm quarantine or reject policy and 100 percent coverage.
Check default or enter the BIMI selector used by the domain.
Publishing a TXT record does not guarantee logo display. Inbox providers also evaluate the authentication chain, SVG profile, certificate and domain reputation.
Confirm DMARC enforcement before investing in a VMC/CMC or deploying a logo.
Catch duplicate records, insecure URLs, a wrong selector and missing tags.
Make legitimate messages easier to recognize while reducing brand impersonation risk.
The tool reads public DNS only. It does not send email, change DNS or store the result in a database.
Normalize the input and validate the BIMI selector.
Read selector._bimi and _dmarc TXT records in parallel.
Check BIMI tags, HTTPS URLs, DMARC policy and coverage.
Separate missing records, syntax errors and policy weaknesses with clear actions.
Providers may also require DMARC enforcement, a compliant SVG Tiny PS file, sufficient domain reputation, and an accepted VMC or CMC. Passing a DNS check does not guarantee immediate display everywhere.
Requirements vary. Some providers accept BIMI without a certificate, while platforms such as Gmail generally require an accepted VMC or CMC.
The common hostname is default._bimi.example.com. Use the matching hostname when the domain publishes another selector.
Generally no. Use quarantine or reject and apply the policy to 100 percent of messages.
This check focuses on DNS and DMARC eligibility. Final deployment should separately validate the SVG Tiny PS profile and any certificate content.
Continue through the authentication chain, transport security and DNS record generation.