Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

VMC and BIMI Explained

Homomorphic encryption

BIMI (Brand Indicators for Message Identification) is an email standard that displays a sender’s verified logo in supporting inboxes, and a Verified Mark Certificate (VMC) is the digital certificate that proves the sender legally owns the trademarked logo BIMI displays.

BIMI lets a verified brand’s logo appear next to its emails in supporting inboxes like Gmail. To qualify, the sender must enforce strict email authentication (SPF, DKIM, and DMARC at enforcement) and obtain a Verified Mark Certificate, which a CA issues only after confirming the sender holds a registered trademark on the logo.

Key Takeaways

  • BIMI display requires DMARC to be at enforcement (p=quarantine or p=reject), not just present in monitoring mode, alongside valid SPF and DKIM.
  • A Verified Mark Certificate (VMC) is issued only to organizations that hold a registered trademark for the exact logo they want displayed, verified against a national trademark registry.
  • Gmail, Yahoo, and Fastmail are among the major inbox providers supporting BIMI; support is not yet universal across all email clients.
  • BIMI adoption directly improves brand recognition and can measurably improve open rates, since a verified logo helps a recipient distinguish a legitimate sender from a spoofed one at a glance.
  • VMC issuance is a distinct, trademark-dependent process from standard TLS or S/MIME certificate issuance, requiring documentation a typical certificate request does not.

What Are the Prerequisites for BIMI?

  • DMARC at enforcement: the domain’s DMARC policy must be set to p=quarantine or p=reject, not p=none, proving the organization actively blocks spoofed mail rather than only monitoring it.
  • Valid SPF and DKIM: both underlying authentication mechanisms must pass consistently for the sending domain.
  • A qualifying logo: the logo must be submitted in SVG Tiny PS format, per the BIMI specification’s rendering requirements.
  • A Verified Mark Certificate: most major inbox providers, including Gmail, require a VMC before they will display the logo, even if the other technical prerequisites are met.

Enterprise PKI Services

Get complete end-to-end consultation support for all your PKI requirements!

How Does a Verified Mark Certificate Differ From a Standard TLS Certificate?

AspectTLS certificateVerified Mark Certificate (VMC)
What it provesControl of a domainLegal trademark ownership of a specific logo
Validation basisDNS or HTTP domain control validationNational trademark registry confirmation
Used forEncrypting and authenticating web trafficAuthorizing a logo to display via BIMI
Issued byAny publicly trusted CAA CA specifically accredited to issue VMCs

Why Do Some Inbox Providers Require a VMC While Others Do Not?

Requiring a VMC raises the bar for logo display beyond the base BIMI specification, since it ties the logo to a verifiable legal trademark rather than trusting the sender’s self-submitted SVG file. Gmail is the most prominent provider requiring a VMC; other BIMI-supporting providers may accept BIMI without one, though the industry trend favors requiring verified marks as adoption grows, since it closes an obvious spoofing loophole where anyone could submit any logo without a VMC requirement.

How Encryption Consulting Helps

How Encryption Consulting HelpsEncryption Consulting’s PKI Services help organizations navigate Verified Mark Certificate issuance alongside their broader email authentication rollout, ensuring DMARC, SPF, DKIM, and VMC requirements are all satisfied together rather than as disconnected projects. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.

Frequently Asked Questions

Do I need a trademark to use BIMI?

You need a registered trademark specifically if the inbox providers you are targeting require a Verified Mark Certificate, which itself requires trademark registration. Gmail is the most prominent provider with this requirement; check each target provider’s specific BIMI requirements before assuming a VMC is mandatory everywhere.

What DMARC policy is required for BIMI?

BIMI requires DMARC to be at enforcement, meaning a policy of p=quarantine or p=reject, rather than the monitoring-only p=none policy many organizations start with. This proves the domain is actively blocking, not just observing, unauthenticated mail.

What format does a BIMI logo need to be in?

BIMI requires the logo to be submitted as an SVG Tiny PS file, a restricted profile of SVG designed for consistent rendering across different inbox providers and email clients.

Does BIMI improve email deliverability?

BIMI itself is primarily a brand-recognition and anti-spoofing signal rather than a direct deliverability mechanism, but the DMARC-at-enforcement prerequisite it requires is itself associated with improved sender reputation and deliverability.

Roll Out Verified Mark Certificates the Right Way

Take the next step Encryption Consulting’s PKI Services help you coordinate DMARC enforcement, SPF, DKIM, and Verified Mark Certificate issuance as one rollout. Explore PKI Services to get started.