BIMI rarely fails on the BIMI record
People set up BIMI, write a TXT record at default._bimi, publish an SVG — and then wonder why no logo appears in the inbox. The reason is almost never the record itself but its prerequisite: BIMI requires an enforced DMARC policy.
"Enforced" means p=quarantine or p=reject — and pct=100. A policy covering only part of the mail does not count. If the domain is still on p=none, BIMI does nothing, however correct everything else may be. That is why this tool checks the DMARC policy too — using the same lookup as the DMARC check.
What this tool checks
- BIMI record at
default._bimi, falling back to the organizational domain. - DMARC prerequisite — policy and
pct, reported explicitly as its own finding. - Logo URL from the
l=tag: HTTPS requirement, an actual fetch, HTTP status, content type and size. - SVG profile — BIMI permits only SVG Tiny 1.2 Portable/Secure. Without
baseProfile="tiny-ps", providers discard the file. - Certificate — whether an
a=tag points at a Verified Mark Certificate.
The logo URL is only fetched when it points at a publicly routed address. That is not decoration: without the check, the tool could be used to send requests into other people's internal networks.
Without a VMC, Gmail shows nothing
The a= tag points at a Verified Mark Certificate — a paid certificate confirming that the trademark in the logo is yours. Gmail and Apple Mail only display the logo with a valid VMC. Without one the record stays technically correct and practically inconsequential, which is why a missing a= is called out here explicitly.
What this test cannot see
Whether a mailbox provider ultimately displays the logo also depends on the sending domain's reputation and on the VMC being valid and unrevoked. Neither is visible in DNS. And whether your messages actually pass DMARC in practice — the real condition — is shown by the full report on a real email.