BIMI (Brand Indicators for Message Identification) is an email standard that displays a sender’s verified logo in supporting inboxes, and a Verified Mark Certificate (VMC) is the digital certificate that proves the sender legally owns the trademarked logo BIMI displays.
BIMI lets a verified brand’s logo appear next to its emails in supporting inboxes like Gmail. To qualify, the sender must enforce strict email authentication (SPF, DKIM, and DMARC at enforcement) and obtain a Verified Mark Certificate, which a CA issues only after confirming the sender holds a registered trademark on the logo.
Key Takeaways
- BIMI display requires DMARC to be at enforcement (p=quarantine or p=reject), not just present in monitoring mode, alongside valid SPF and DKIM.
- A Verified Mark Certificate (VMC) is issued only to organizations that hold a registered trademark for the exact logo they want displayed, verified against a national trademark registry.
- Gmail, Yahoo, and Fastmail are among the major inbox providers supporting BIMI; support is not yet universal across all email clients.
- BIMI adoption directly improves brand recognition and can measurably improve open rates, since a verified logo helps a recipient distinguish a legitimate sender from a spoofed one at a glance.
- VMC issuance is a distinct, trademark-dependent process from standard TLS or S/MIME certificate issuance, requiring documentation a typical certificate request does not.
What Are the Prerequisites for BIMI?
- DMARC at enforcement: the domain’s DMARC policy must be set to p=quarantine or p=reject, not p=none, proving the organization actively blocks spoofed mail rather than only monitoring it.
- Valid SPF and DKIM: both underlying authentication mechanisms must pass consistently for the sending domain.
- A qualifying logo: the logo must be submitted in SVG Tiny PS format, per the BIMI specification’s rendering requirements.
- A Verified Mark Certificate: most major inbox providers, including Gmail, require a VMC before they will display the logo, even if the other technical prerequisites are met.
How Does a Verified Mark Certificate Differ From a Standard TLS Certificate?
| Aspect | TLS certificate | Verified Mark Certificate (VMC) |
|---|---|---|
| What it proves | Control of a domain | Legal trademark ownership of a specific logo |
| Validation basis | DNS or HTTP domain control validation | National trademark registry confirmation |
| Used for | Encrypting and authenticating web traffic | Authorizing a logo to display via BIMI |
| Issued by | Any publicly trusted CA | A CA specifically accredited to issue VMCs |
Why Do Some Inbox Providers Require a VMC While Others Do Not?
Requiring a VMC raises the bar for logo display beyond the base BIMI specification, since it ties the logo to a verifiable legal trademark rather than trusting the sender’s self-submitted SVG file. Gmail is the most prominent provider requiring a VMC; other BIMI-supporting providers may accept BIMI without one, though the industry trend favors requiring verified marks as adoption grows, since it closes an obvious spoofing loophole where anyone could submit any logo without a VMC requirement.
How Encryption Consulting Helps
How Encryption Consulting HelpsEncryption Consulting’s PKI Services help organizations navigate Verified Mark Certificate issuance alongside their broader email authentication rollout, ensuring DMARC, SPF, DKIM, and VMC requirements are all satisfied together rather than as disconnected projects. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.
Frequently Asked Questions
Do I need a trademark to use BIMI?
You need a registered trademark specifically if the inbox providers you are targeting require a Verified Mark Certificate, which itself requires trademark registration. Gmail is the most prominent provider with this requirement; check each target provider’s specific BIMI requirements before assuming a VMC is mandatory everywhere.
What DMARC policy is required for BIMI?
BIMI requires DMARC to be at enforcement, meaning a policy of p=quarantine or p=reject, rather than the monitoring-only p=none policy many organizations start with. This proves the domain is actively blocking, not just observing, unauthenticated mail.
What format does a BIMI logo need to be in?
BIMI requires the logo to be submitted as an SVG Tiny PS file, a restricted profile of SVG designed for consistent rendering across different inbox providers and email clients.
Does BIMI improve email deliverability?
BIMI itself is primarily a brand-recognition and anti-spoofing signal rather than a direct deliverability mechanism, but the DMARC-at-enforcement prerequisite it requires is itself associated with improved sender reputation and deliverability.
Roll Out Verified Mark Certificates the Right Way
Take the next step Encryption Consulting’s PKI Services help you coordinate DMARC enforcement, SPF, DKIM, and Verified Mark Certificate issuance as one rollout. Explore PKI Services to get started.
