BIMI Record Checker
Instantly check any domain's BIMI record, logo URL, and certificate status.
Need to monitor this across every client domain you manage? ActiScan does bulk scanning, scoring, and white-labeled reporting for MSPs.
How to Use the BIMI Checker
Enter a domain
No http:// prefix – just the domain itself (e.g. company.com).
Click Check
ActiScan looks up the domain's default._bimi TXT record live, over DNS.
Read the result
A pass/warn/info status plus a plain-English explanation of what to do next.
What Your Result Means
BIMI + certificate foundPassA v=BIMI1 record exists and includes an a= tag pointing to a certificate. This is the configuration Gmail and Apple Mail require to actually render your logo next to the message.
BIMI found, no certificateWarnA v=BIMI1 record exists with a logo (l=) but no a= tag. The record is valid per the BIMI spec, but Gmail will not display the logo without a VMC or CMC attached.
No BIMI recordInfoNothing is published at default._bimi.<domain>. This isn't a security failure – BIMI is an optional branding feature, and it only does anything once your DMARC policy is already enforcing.
What is a BIMI Record?
BIMI (Brand Indicators for Message Identification) is a DNS TXT record that lets your logo appear next to your emails in supporting inboxes – currently Gmail, Apple Mail, and a handful of others. It's a branding feature, not an authentication protocol: it doesn't stop spoofing or improve deliverability by itself.
BIMI has a hard prerequisite: your domain's DMARC policy must already be enforcing (p=quarantine or p=reject). Mailbox providers use that enforcement as proof that mail claiming to be from your domain is actually being authenticated – without it, they won't trust the logo you're asserting is yours. This checker only reads the BIMI record itself; check your DMARC policy separately with the DMARC checker.
It's published at the fixed default._bimi subdomain: for example.com, that's default._bimi.example.com. Unlike DKIM, BIMI doesn't support multiple selectors – "default" is the only one mailbox providers look for.
The Logo File: SVG Tiny PS
The l= tag can't point to just any image. The BIMI spec requires the logo be an SVG file conforming to the SVG Tiny Portable/Secure (SVG Tiny PS) profile: square aspect ratio, no scripts, no external references or animations, and a restricted, secure subset of SVG. Most standard design tools (Illustrator, Inkscape) can export a compliant file, but a plain SVG export usually needs cleanup before it validates.
What is a VMC (or CMC)?
A Verified Mark Certificate (VMC) is a paid, third-party certificate that proves you legally own the trademarked logo you're publishing – issued by an authorized certificate authority such as DigiCert, Entrust, or GlobalSign, typically requiring a registered trademark. A Common Mark Certificate (CMC) is a newer, lower-barrier alternative some CAs offer for organizations without a registered trademark.
ActiScan does not issue or broker VMCs or CMCs. If you already have one from a CA, ActiScan's BIMI generator can add its URL to a correctly formatted record. Without one, your record is still valid – it just won't render in Gmail.
Want to check whether your logo file actually meets the SVG Tiny PS format the spec requires, before you spend money on a certificate? Use the free BIMI readiness check.
BIMI Record Examples
Logo only, no certificate
v=BIMI1; l=https://example.com/logo.svg
Valid per the BIMI spec and enough for some mail providers, but Gmail requires a certificate before it will show the logo.
With a VMC
v=BIMI1; l=https://example.com/logo.svg; a=https://example.com/vmc.pem
A Verified Mark Certificate proves you own the trademarked logo. This is the combination Gmail looks for.
With a CMC
v=BIMI1; l=https://example.com/logo.svg; a=https://example.com/cmc.pem
Some certificate authorities offer a Common Mark Certificate as a lower-barrier alternative to a VMC for organizations without a registered trademark. The a= tag works the same either way.
Need to build your own? Use the free BIMI generator.
BIMI Record Tags Explained
| Tag | What it does | Example | Required? |
|---|---|---|---|
| v | Protocol version. Must be the first tag. | v=BIMI1 | Required |
| l | Location (URL) of the brand logo, an SVG Tiny PS file. | l=https://example.com/logo.svg | Required |
| a | Location (URL) of a VMC or CMC certificate authenticating the logo. | a=https://example.com/vmc.pem | Optional (required by Gmail) |
How to Find Your BIMI Record Manually
If you'd rather look it up yourself instead of using the checker above:
Using nslookup
nslookup -type=TXT default._bimi.yourdomain.com
Using dig
dig TXT default._bimi.yourdomain.com
Next Steps After Your Check
Not enforcing DMARC yet?
BIMI won't render anywhere until your policy reaches p=quarantine or p=reject. Check that first.
DMARC Checker →Want ongoing monitoring?
ActiScan scans on a schedule and alerts you when something changes – across every domain you manage.
Start free →Frequently Asked Questions
Is this BIMI checker free?
Yes – check any domain's BIMI record for free, no signup required.
Do I need to own the domain I'm checking?
No. BIMI records are published in public DNS, so anyone can look one up.
Why does my domain show "no record" right after I added one?
DNS changes take time to propagate – wait for the record's TTL to expire (often up to a few hours) and check again.
Do I need a VMC to publish BIMI at all?
No – the BIMI spec itself makes the a= tag optional. In practice, though, Gmail requires a VMC (or CMC) before it will render the logo, so most real-world deployments include one.
Does BIMI improve deliverability or stop spoofing?
No. BIMI is a branding feature, not an authentication mechanism – it displays a logo, it doesn't add security on its own. It only takes effect once your domain's DMARC policy is already enforcing (p=quarantine or p=reject).
Where is a BIMI record stored?
As a TXT record at the default._bimi subdomain – for example.com, that's default._bimi.example.com. Unlike DKIM, BIMI always uses the fixed selector "default," not a variable one.