Truvo Free Tools
BIMI record checker
BIMI puts your verified logo next to your messages in Gmail, Apple Mail and Yahoo, but only when DMARC is enforced and the record is valid. This checker reads the record at default._bimi.yourdomain.com, confirms the logo location and Verified Mark Certificate, and checks the DMARC policy BIMI depends on.
Ali Aleali, CISSP, CCSP
Co-Founder & Principal Consultant
Former security architect for Bank of Canada and Payments Canada. 20+ years building compliance programs for critical infrastructure. These tools come out of that work.
Connect on LinkedInHow the BIMI checker works
The check is passive: it reads two public DNS records through DNS over HTTPS and never sends mail or touches your servers.
01
Query
You enter a domain. The tool asks a public DNS over HTTPS resolver for the TXT record at default._bimi.
02
Read
The result shows whether a record exists, whether the l tag points to an HTTPS SVG logo, whether the a tag names a Verified Mark Certificate, and whether DMARC is at quarantine or reject. A record with DMARC at none is flagged: providers will not show the logo.
03
Map
Each finding names the controls it speaks to: SOC 2 CC6.1, CC6.7 and CC7.2, and ISO 27001:2022 A.5.14 and A.8.20. BIMI itself is a trust signal rather than a control, so the audit weight sits in the enforced DMARC policy it requires.
Want your logo in the inbox? Finish mail authentication first.
Truvo's security engineers take DMARC to reject without breaking legitimate senders, publish BIMI, and hand you the evidence an auditor asks for. Tell us the domain and we will scope the work.
-
DMARC to reject
-
SPF and DKIM
-
BIMI and VMC setup
-
Report monitoring
-
Audit evidence
-
Fixed-price scope
BIMI checker: frequently asked questions
It looks up the TXT record at default._bimi.yourdomain.com and reads the v=BIMI1 record. It confirms the l tag points to an HTTPS logo, checks whether the a tag names a Verified Mark Certificate, and reads your DMARC policy, because mailbox providers ignore BIMI unless DMARC is at quarantine or reject.
The two usual reasons are a DMARC policy still at p=none, and no Verified Mark Certificate. Gmail and Apple Mail require both an enforced DMARC policy and a VMC (or a Common Mark Certificate) before they display a logo. Yahoo shows logos without a certificate but still requires enforced DMARC.
An SVG Tiny Portable/Secure (SVG P/S) file served over HTTPS, square, with a solid background and no external references or scripts. The checker confirms the l tag is an HTTPS URL; it does not render the file, so validate the SVG itself with your certificate authority's tooling.
For Gmail and Apple Mail, yes. A VMC ties the logo to a registered trademark; a Common Mark Certificate covers logos in use for at least a year without a trademark. Both are issued by a small set of certificate authorities and cost money each year, which is why many teams publish BIMI first for Yahoo and add the certificate later.
Not directly: no framework requires a logo in the inbox. What matters is the DMARC enforcement BIMI depends on, which is evidence for SOC 2 CC6.7 and ISO 27001 A.5.14. Treat BIMI as the visible reward for finishing mail authentication, not as a control.
Brand Indicators for Message Identification is a DNS record at default._bimi.yourdomain.com that points mailbox providers to your logo. When your DMARC policy is enforced and, for Gmail and Apple Mail, a Verified Mark Certificate is present, the provider shows the logo next to your messages. It is the visible reward for finishing SPF, DKIM and DMARC.
More free tools
Check the DMARC and DKIM records BIMI depends on, or run the full domain scan. See all free tools.
DMARC record checker
Check whether your DMARC record exists, whether the policy enforces or only monitors, and whether reporting is set up.
DKIM record checker
Look up the DKIM record for a domain and selector, validate the key, and catch weak, revoked or test-mode keys.
Domain security scan
Scan any domain for SPF, DMARC, DNS, TLS, security headers and subdomains in one pass. Graded A to F, each finding mapped to the SOC 2 and ISO 27001 control it supports.