Skip to content
Inspect My DNS

Mail authentication

BIMI certificate

mailauth.bimi-certificate

Gmail and Apple Mail show a BIMI logo only when the mark certificate it points at is valid.

What this check measures

Most large mailbox providers show a BIMI logo only when the record's a= tag points at a valid mark certificate — a Verified Mark Certificate, or the cheaper Common Mark Certificate. This check fetches that file over HTTPS and reads the first certificate in it: whether it is inside its validity period, whether it names this domain, and whether it carries the BIMI extended key usage that marks it as a mark certificate rather than any other.

The failure this check exists for is invisible from DNS. Mark certificates are renewed by hand, usually yearly, and when one lapses nothing else changes: the TXT record still parses, the logo URL still serves an SVG, and the logo quietly stops appearing in Gmail and Apple Mail. A record with no a= tag gets no row here at all — it names no certificate.

Trust in the issuing chain is not graded. The mark certificate roots are not in any TLS trust store, so a chain check would need its own root list; what is graded is what a domain owner can act on. The certificate file itself is not stored, only the fields shown.

How to fix it

Renew with the issuer before the expiry date. Verification for a renewal can take days, so start a month ahead — this check warns inside thirty days.

Publish the renewed file at the same URL, or update the a= tag to the new one. The record must point at a PEM file whose first certificate is the mark certificate, followed by its intermediates.

If the logo is no longer wanted, remove the a= tag (or the whole BIMI record) rather than leaving a lapsed certificate published.

References

Run this check on a domain

BIMI certificate is one of 62 checks in every report, alongside delegation, mail authentication, TLS and registration.