Skip to content

/ Free Tools — BIMI Generator

Get your verified logo into the inbox.

Check whether your domain is BIMI-ready, validate an existing record, and generate the DNS line to publish. We confirm the DMARC prerequisite first, because that's the step most domains haven't finished. Runs in your browser — no signup.

/ 1 — Check readiness

Checks your DMARC policy and any existing BIMI record over DNS-over-HTTPS.

/ 2 — Generate the record

/ 3 — Validate your SVG (Tiny P/S)

/ What this checks

BIMI displays your verified logo beside your messages in supporting inboxes, but it only works once your domain has DMARC at an enforced policy — quarantine or reject. That prerequisite is the part most domains haven't finished, so this tool checks it first: it reads your DMARC policy, validates any existing BIMI record, and only then helps you generate the DNS line to publish your logo.

The full setup needs three things: enforced DMARC, a logo in the SVG Tiny PS profile served over HTTPS, and — for the verified checkmark in Gmail and Apple Mail — a Verified Mark Certificate. Senders with BIMI report open-rate lifts of up to 39%, which makes it a rare case where a security control also pays off as a visible brand signal. This tool gets you to a correct record; the trademark certificate and logo conversion are the steps that happen outside DNS.

  • DMARC first

    BIMI is ignored unless DMARC is at p=quarantine or p=reject. The enforced policy is a hard prerequisite, which is why this tool checks it before anything else.

  • +39%

    Senders with a BIMI logo report open rates up to 39% higher — a visible trust signal that's also a measurable deliverability-adjacent win.

  • VMC vs CMC

    A VMC (~$1,500/yr, registered trademark) unlocks Gmail, Yahoo, and Apple Mail; a CMC needs no trademark but currently centers on Gmail.

  • SVG Tiny PS

    The logo must be square, solid-background SVG Tiny PS served over HTTPS. A standard design-tool SVG almost never conforms without conversion.

/ How BIMI works

How does a logo in DNS end up beside your name?

BIMI — Brand Indicators for Message Identification — is a DNS record that points to your logo and, optionally, to a certificate proving you're entitled to use it. When a message arrives at a supporting provider, the provider first confirms the message passed DMARC under an enforced policy, then reads your BIMI record, fetches the logo, validates the certificate if one is present, and displays the logo beside your name in the inbox. The logo only appears when the authentication chain holds, which is what makes it a trust signal rather than mere decoration: a displayed BIMI logo means the message is provably from you.

# A BIMI record, tag by tag
v=BIMI1;                          # version
l=https://example.com/logo.svg;   # logo (SVG Tiny PS, HTTPS)
a=https://example.com/vmc.pem;    # VMC/CMC certificate (optional but needed for checkmark)

# published at: default._bimi.yourdomain.com
# prerequisite: DMARC at p=quarantine or p=reject

The l tag points to your logo, which must be in the SVG Tiny PS profile and served over HTTPS. This is where many setups stall: a logo exported from a design tool is almost never in the right profile, because SVG Tiny PS forbids scripts, external references, animation, and transparency, and requires a square aspect ratio with a title element. Converting a brand logo to a conforming file is usually a one-time task, but it's a real one, and a logo that doesn't conform simply won't display even with a perfect record.

The a tag points to your certificate, and whether you need one depends on where you want the logo to show. Gmail and Apple Mail require a certificate — a VMC if you hold a registered trademark, or the newer CMC if you don't — before they'll display the logo with the verified checkmark. Some providers will show a logo from the record without a certificate, but the widest, checkmark-bearing reach needs the a tag populated. The certificate is the part of BIMI that costs money and takes time, because it involves trademark or prior-use verification by a certificate authority.

Everything about BIMI rests on the prerequisite the tool checks first: DMARC at enforcement. Without it, the record is inert no matter how correct the logo and certificate are, which is why a domain stuck at p=none can't benefit from BIMI at all. This is also why BIMI is best understood as the visible reward for completing authentication rather than a feature you bolt on — the enforced DMARC it demands is the genuinely important work, and the logo is what you get for finishing it.

/ Is it worth it

When does BIMI earn the certificate cost?

The roughly $1,500 annual cost of a Verified Mark Certificate makes sense to question, and the honest answer depends on your volume and your brand. For a company sending meaningful marketing or transactional volume to consumers, the math tends to work: a verified logo beside your name lifts recognition at the moment of the open decision, and the reported open-rate gains of up to 39% compound across every campaign for the life of the certificate. For a low-volume sender or a brand recipients don't recognize on sight, the lift is smaller and the certificate harder to justify on open rates alone.

The framing that resolves it is to stop treating BIMI as a standalone purchase. The expensive, time-consuming prerequisite — enforced DMARC with every legitimate source aligned — is work you should complete regardless, because it stops domain spoofing and is increasingly required by mailbox providers as a baseline rather than an option. Once that work is done, the marginal cost of turning it into a visible logo is the certificate and a conforming SVG, both one-time efforts rather than ongoing burdens. Seen that way, BIMI isn't a $1,500 question about logos; it's a modest add-on that converts security work you needed anyway into a brand asset. The domains for which BIMI clearly pays are the ones that were going to enforce DMARC regardless and send enough volume for the recognition to matter.

/ BIMI FAQ

What does BIMI require before it works?
BIMI does nothing until your domain has DMARC at an enforced policy — p=quarantine or p=reject. This is a hard prerequisite, not a recommendation: a BIMI record published on a domain still at p=none will be ignored by every mailbox provider. You also need a logo in the specific SVG Tiny PS profile (a constrained version of SVG, square, with a solid background), and for the verified checkmark in Gmail and Apple Mail, a Verified Mark Certificate. Our tool checks the DMARC prerequisite first, because it's the step most domains haven't completed, and there's no point generating a BIMI record until it's met.
What's the difference between a VMC and a CMC?
A Verified Mark Certificate (VMC) proves you own a registered trademark for your logo. It's issued after trademark verification, costs roughly $1,500 per year, and unlocks logo display in Gmail, Yahoo, and Apple Mail. Microsoft Outlook and Microsoft 365 don't render BIMI at all as of 2026, so the reach is the combined Gmail, Yahoo, and Apple audience. A Common Mark Certificate (CMC) is newer and doesn't require a registered trademark — it verifies the logo has been in prior use — but its support is narrower, currently centered on Gmail, and it costs less. If you hold a registered trademark, a VMC gives the widest reach; if you don't, a CMC is the path that still lets you display a verified logo in supporting inboxes.
Why does my BIMI logo need to be a special SVG?
BIMI requires the SVG Tiny Portable/Secure profile (SVG Tiny PS), a deliberately restricted form of SVG. It must be square (1:1 aspect ratio), have a solid background rather than transparency, include a title element, and exclude scripts, external references, and animation — the restrictions exist for security and consistent rendering across mailbox providers. A normal SVG logo exported from a design tool almost never meets the profile without conversion. The logo also has to be served over HTTPS at the URL in your BIMI record. If the logo doesn't conform, providers that would otherwise show it will simply skip it.
Is BIMI worth the cost?
For brands that send meaningful volume and have completed DMARC enforcement, usually yes. A verified logo beside your name is a visible trust and recognition signal, and senders with BIMI report open-rate lifts of up to 39%. The honest framing is that BIMI is the payoff for authentication work you should be doing anyway — the DMARC enforcement BIMI requires is itself a deliverability and anti-spoofing win, and BIMI turns that necessary work into a visible brand benefit. If you're not yet at enforced DMARC, that's the higher priority; BIMI is the reward for getting there.
Does this tool send anything or store my domain?
No. The readiness check runs in your browser as read-only DNS-over-HTTPS lookups of your BIMI and DMARC records, and the record generator builds the DNS line locally from what you enter — nothing is transmitted to us, no email is sent, and your domain isn't logged. The generated record is yours to publish in your DNS.

The logo is the reward. Enforced DMARC is the work.

BIMI pays off only after your domain reaches enforced DMARC with every source aligned — which is exactly what we operate. We get you to p=reject cleanly, then help you light up the logo. Bring us your domain and we'll map the path.

Book infrastructure review