17 June 2026 · 11 min read
BIMI, VMC and CMC: the two mark certificates explained
BIMI (Brand Indicators for Message Identification) is the standard that lets your verified logo appear next to your messages in the inbox, instead of a grey monogram or a generic avatar. Most senders who look into BIMI quickly hit a confusing decision: to actually display that logo at the major mailbox providers, you usually need a mark certificate, and there are now two kinds. The original is the VMC (Verified Mark Certificate), which proves a registered trademark. The newer option is the CMC (Common Mark Certificate), which lets you display an unregistered logo with a lighter form of verification.
These two certificates do similar jobs in the protocol, but they differ in who can get one, what they cost, how long verification takes, and crucially which inboxes will actually render your logo. Choosing the wrong one wastes money, and skipping the certificate entirely means your logo simply will not show at Gmail or Apple Mail no matter how perfect your DNS is.
This guide explains exactly what a VMC and a CMC are, who issues them, what they cost in practice, and which mailbox providers accept which. If you have not yet decided whether BIMI is worth pursuing at all, read do you need BIMI first, because the certificate is the expensive part of the project and the brand-visibility payoff is uneven across senders.
Why a certificate exists at all
BIMI on its own is just a DNS record. You publish a TXT record at default._bimi.yourdomain.com that points to an SVG logo file, like this:
default._bimi.yourdomain.com. IN TXT "v=BIMI1; l=https://yourdomain.com/logo.svg; a=https://yourdomain.com/vmc.pem"
The l= tag is the location of your logo. The a= tag is the location of your mark certificate. Without the a= tag you have what people call "self-asserted BIMI", and at the big consumer providers it does almost nothing: they will not trust an arbitrary SVG to be your real brand logo, because anyone can publish a logo claiming to be a famous bank.
The certificate solves a trust problem. It is a digitally signed document, issued by an audited Certification Authority, that ties a specific logo image to a specific organisation and (for a VMC) a specific registered trademark. The mailbox provider downloads the certificate, checks the signature chain, confirms the logo inside the certificate matches the logo you published, and only then shows your mark. That is the whole point: the certificate is the mailbox provider's way of outsourcing "is this really their logo" to a third party that did the legal and identity checks.
Everything underneath the certificate still has to be right first. BIMI only evaluates for a message that already passed DMARC with an enforced policy. If you are still on p=none, no logo will ever display, certificate or not. You can confirm your enforcement status with the free DMARC checker, and you can preview your BIMI record itself with the BIMI checker.
What a VMC is
A Verified Mark Certificate is the original BIMI mark certificate, defined to prove that the logo you want to display is a registered trademark owned by your organisation. To get a VMC you must:
- Own a trademark for the exact logo (the mark as filed), registered with a recognised intellectual-property office. Accepted offices include the USPTO (United States), EUIPO (European Union), the UK IPO, IP Australia, the Japan Patent Office, the Canadian Intellectual Property Office and several others. The list of accepted registries is maintained by the certificate authorities and has grown over time.
- Hold the trademark as a figurative/design mark, not just a word mark. The logo image has to match what is on the trademark registration. A plain text trademark of your company name does not qualify on its own; the registration has to cover the visual logo.
- Pass a full organisation-validation (OV) identity check, similar to the vetting behind an Extended Validation certificate. The CA confirms your legal entity exists, that you are authorised to request the certificate, and that you control the domain.
When all that passes, the CA issues a PEM certificate that contains your logo embedded inside it, along with the trademark details. You host that PEM file over HTTPS and reference it in the a= tag. The VMC is the strongest form of brand assertion BIMI supports, and it is the one some providers insist on.
What a CMC is
A Common Mark Certificate is the newer option, introduced to widen BIMI to brands that do not have, or do not want to pursue, a registered trademark. The key differences:
- A CMC does not require a registered trademark. You can use a logo you simply use in commerce, which opens BIMI to charities, small businesses, government bodies, and any organisation whose logo is not trademarked.
- Identity validation is lighter than a VMC. The CA still confirms your organisation and domain control, but it is not anchored to a trademark filing, so the legal-proof burden is lower.
- Certain logo types that trademark offices will not register become eligible. Government and some non-profit logos are a common example, because public-body insignia frequently cannot be trademarked in the normal way.
In the certificate itself, a CMC and a VMC are distinguished by an internal indicator (the certificate type, expressed through a logotype/extension that marks it as a registered mark versus a common mark). To the DNS, both look the same: they are a PEM file referenced in the a= tag. The difference that matters to you is who will accept each one, which we come to below.
The trade-off is straightforward. A CMC is cheaper and easier because it skips the trademark requirement, but because it carries a weaker assurance, not every mailbox provider treats it the same way as a VMC.
Who issues them
Both VMCs and CMCs are issued by a small number of audited Certification Authorities that have been approved for the BIMI ecosystem. As of writing the established issuers are:
- DigiCert, which was the first CA to offer VMCs and remains one of the two main providers.
- Entrust, the other major issuer offering both VMC and CMC products.
A handful of other CAs have entered or signalled intent to enter this market, but for practical purposes most organisations buy from DigiCert or Entrust, often through a reseller or their existing certificate vendor. You do not get a mark certificate from a generic domain registrar the way you might grab a basic TLS certificate; the issuance involves manual identity and (for VMCs) trademark vetting that an automated certificate pipeline cannot do.
It is worth knowing that the certificate is tied to your logo and organisation, not just your domain, and it is renewed annually. If you rebrand your logo, you generally need a new certificate, because the embedded image must match what you publish.
What they cost
Pricing changes over time and varies by issuer, reseller and contract length, so treat these as orders of magnitude rather than quotes. As a guide:
- A VMC typically lands in the region of a few hundred to around a thousand US dollars per year, with figures commonly quoted around 1,000 USD per year at list price from the major CAs, and lower through resellers or multi-year deals. That is the certificate alone.
- A CMC is generally cheaper than a VMC because it skips trademark verification, though both issuers price these as ongoing annual products rather than one-off purchases.
The certificate is rarely your only cost. Behind a VMC sits the trademark itself, which is the real expense and the real timeline. Registering a figurative trademark from scratch, in one jurisdiction, often runs to hundreds or low thousands in fees plus legal costs, and it can take several months to over a year to be granted. If you do not already hold a registered logo trademark, the VMC route is a multi-month, multi-cost project before the certificate even begins. A CMC sidesteps that, which is much of its appeal.
You should also budget time for the operational prerequisites: getting to DMARC enforcement safely, producing a compliant SVG logo, and hosting both the SVG and the PEM over HTTPS. Those steps are the same regardless of which certificate you choose.
Which mailbox providers accept which
This is the question that decides whether the spend is worth it, and it is where VMC and CMC genuinely diverge. Support evolves, so verify against current provider documentation before you buy, but the broad picture at the time of writing is:
- Gmail (Google): requires a mark certificate to show the BIMI logo and the blue verified checkmark. Google accepts both VMCs and CMCs. Self-asserted BIMI without a certificate does not display a logo for ordinary senders here.
- Apple Mail (iOS, iPadOS and macOS): supports BIMI and, importantly, has shown logos in some cases via self-asserted BIMI as well as with a certificate, but a certificate gives you the reliable, broadly supported result. Apple has been the most permissive of the big consumer clients, though relying on self-asserted display is fragile.
- Yahoo and AOL (Yahoo Mail group): among the earliest BIMI adopters. Historically anchored on VMCs; treat a VMC as the safe choice for guaranteed display here.
- Fastmail: supports BIMI display.
- La Poste, and several other regional providers: have participated in BIMI, generally on the VMC track.
- Microsoft Outlook and Microsoft 365: this is the big gap. Microsoft has run BIMI in preview and signalled support, but consumer Outlook and Microsoft 365 have historically not displayed BIMI logos in general availability the way Gmail does. Do not assume Outlook will show your logo; check Microsoft's current status before you justify the spend on Outlook reach.
The practical headline: a VMC is accepted everywhere BIMI is supported, because it is the original and strongest assertion. A CMC is accepted at Gmail and is being adopted more widely over time, but it is not yet universally honoured across every provider that supports VMCs. If your audience is heavily on Gmail, a CMC can be a sensible, cheaper entry point. If you need the broadest possible inbox coverage and you already hold (or are willing to obtain) a registered trademark, a VMC remains the most complete option.
How to decide between them
Work through it in this order.
- Confirm BIMI is even relevant to you. Logos only appear on messages that pass DMARC at enforcement, so a B2B sender with little consumer mail may see negligible visibility. The article on whether you need BIMI walks through this honestly.
- Check your trademark position. If you already own a registered figurative trademark for your logo, a VMC is the natural choice: you have the hard part done, and you get the widest acceptance. If you do not, ask whether the brand visibility justifies a multi-month trademark application, or whether a CMC gets you the coverage you actually care about today.
- Map your recipients. Pull your sending data and see where your humans read mail. If 70% of your engaged recipients are on Gmail, a CMC covers most of your reach immediately. If a large share are on Yahoo or other VMC-anchored providers, the VMC earns its premium.
- Get to enforcement first. No certificate is worth buying until you are at
p=quarantineorp=rejectwith healthy authentication, because the logo cannot render before then. Use the DMARC checker to confirm policy, the SPF checker and DKIM checker to confirm both mechanisms pass and align, and the BIMI checker once your record is live.
If you want the full set of prerequisites laid out, including the SVG requirements and the enforcement path, the companion piece on BIMI without a VMC covers what you can and cannot achieve before you commit to a certificate.
The prerequisites neither certificate removes
Whichever certificate you choose, BIMI still demands several things be correct, and the certificate does nothing to fix them:
- DMARC at enforcement. Your domain must publish a DMARC policy of
quarantineorreject, notnone. Many senders stall here because they are afraid of blocking legitimate mail. The safe path is to reach enforcement gradually using real report data rather than guessing. See our DMARC product and the requirements overview for the staged approach. - Passing, aligned SPF and DKIM. BIMI piggybacks on DMARC, and DMARC only passes when SPF or DKIM authenticates with proper alignment. Broken SPF or DKIM means no DMARC pass, which means no logo.
- A compliant SVG logo. BIMI requires a specific SVG profile (SVG Portable/Secure, often called SVG Tiny PS), square, with a solid background, and stripped of scripting and external references. A logo that is not in this exact format will be rejected even with a valid certificate.
- HTTPS hosting for both files. The SVG and the PEM certificate must be served over HTTPS from URLs you control, with valid TLS, and the logo inside the certificate must match the SVG you publish.
None of these are exotic, but all of them have to be right at the same time, which is why BIMI projects take longer than people expect. If you would rather not assemble the SVG, the certificate paperwork and the DMARC enforcement work yourself, our done-for-you service handles the full chain: getting you to enforcement without an email outage, preparing a compliant logo, and wiring up the BIMI record.
Common mistakes to avoid
- Buying a certificate before reaching enforcement. The certificate sits idle and renews annually while your logo never shows, because you are still on
p=none. Get toquarantineorrejectfirst. - Assuming Outlook will display your logo. It is the most common false expectation. Validate Microsoft's current support rather than projecting Gmail behaviour onto it.
- Trademarking only your company name. A VMC needs the registered mark to cover the logo image, not just the words. A word mark alone will not satisfy the trademark check.
- Publishing a non-conforming SVG. A standard web SVG exported from a design tool is almost never compliant out of the box. It must be the restricted BIMI profile.
- Letting the certificate or trademark lapse. Both are annual or periodic. An expired certificate silently stops your logo from displaying.
The practical takeaway
A VMC proves a registered trademark, costs more, can take many months if you do not already hold the trademark, and is accepted across the broadest set of BIMI-supporting inboxes including the VMC-anchored ones like Yahoo. A CMC drops the trademark requirement, is cheaper and faster, opens BIMI to organisations that could never get a VMC, and is accepted at Gmail and a growing list of providers, though not yet everywhere a VMC is honoured. Both are issued by audited CAs (principally DigiCert and Entrust), renew annually, and both sit on top of the same hard prerequisite: DMARC at enforcement with passing, aligned SPF and DKIM.
Decide based on your trademark position and where your recipients actually read mail, not on the logo alone. Before you spend anything, confirm you are at enforcement and that your record is valid with the free BIMI checker and the rest of the tool suite. If you would rather have the whole path handled end to end, from none to reject to a verified logo, the hosted BIMI service takes it off your plate.