Truvo Free Tools

BIMI record checker

BIMI puts your verified logo next to your messages in Gmail, Apple Mail and Yahoo, but only when DMARC is enforced and the record is valid. This checker reads the record at default._bimi.yourdomain.com, confirms the logo location and Verified Mark Certificate, and checks the DMARC policy BIMI depends on.

SOC 2 CC6.1SOC 2 CC6.7SOC 2 CC7.2ISO 27001 A.5.14ISO 27001 A.8.20
Ali Aleali

Ali Aleali, CISSP, CCSP

Co-Founder & Principal Consultant

Former security architect for Bank of Canada and Payments Canada. 20+ years building compliance programs for critical infrastructure. These tools come out of that work.

Connect on LinkedIn

How the BIMI checker works

The check is passive: it reads two public DNS records through DNS over HTTPS and never sends mail or touches your servers.

01

Query

You enter a domain. The tool asks a public DNS over HTTPS resolver for the TXT record at default._bimi. and looks for v=BIMI1, then reads your DMARC policy at _dmarc..

02

Read

The result shows whether a record exists, whether the l tag points to an HTTPS SVG logo, whether the a tag names a Verified Mark Certificate, and whether DMARC is at quarantine or reject. A record with DMARC at none is flagged: providers will not show the logo.

03

Map

Each finding names the controls it speaks to: SOC 2 CC6.1, CC6.7 and CC7.2, and ISO 27001:2022 A.5.14 and A.8.20. BIMI itself is a trust signal rather than a control, so the audit weight sits in the enforced DMARC policy it requires.

Want your logo in the inbox? Finish mail authentication first.

Truvo's security engineers take DMARC to reject without breaking legitimate senders, publish BIMI, and hand you the evidence an auditor asks for. Tell us the domain and we will scope the work.

  • DMARC to reject

  • SPF and DKIM

  • BIMI and VMC setup

  • Report monitoring

  • Audit evidence

  • Fixed-price scope

BIMI checker: frequently asked questions

It looks up the TXT record at default._bimi.yourdomain.com and reads the v=BIMI1 record. It confirms the l tag points to an HTTPS logo, checks whether the a tag names a Verified Mark Certificate, and reads your DMARC policy, because mailbox providers ignore BIMI unless DMARC is at quarantine or reject.

The two usual reasons are a DMARC policy still at p=none, and no Verified Mark Certificate. Gmail and Apple Mail require both an enforced DMARC policy and a VMC (or a Common Mark Certificate) before they display a logo. Yahoo shows logos without a certificate but still requires enforced DMARC.

An SVG Tiny Portable/Secure (SVG P/S) file served over HTTPS, square, with a solid background and no external references or scripts. The checker confirms the l tag is an HTTPS URL; it does not render the file, so validate the SVG itself with your certificate authority's tooling.

For Gmail and Apple Mail, yes. A VMC ties the logo to a registered trademark; a Common Mark Certificate covers logos in use for at least a year without a trademark. Both are issued by a small set of certificate authorities and cost money each year, which is why many teams publish BIMI first for Yahoo and add the certificate later.

Not directly: no framework requires a logo in the inbox. What matters is the DMARC enforcement BIMI depends on, which is evidence for SOC 2 CC6.7 and ISO 27001 A.5.14. Treat BIMI as the visible reward for finishing mail authentication, not as a control.

Brand Indicators for Message Identification is a DNS record at default._bimi.yourdomain.com that points mailbox providers to your logo. When your DMARC policy is enforced and, for Gmail and Apple Mail, a Verified Mark Certificate is present, the provider shows the logo next to your messages. It is the visible reward for finishing SPF, DKIM and DMARC.