DMARC Engine
Home/Blog/CMC: BIMI for unregistered logos
Blog

CMC: BIMI for unregistered logos

A Common Mark Certificate lets brands without a registered trademark show a verified BIMI logo. Here is how a CMC is checked, how it differs from a VMC, and where it is accepted today.

4 June 2026 · 12 min read

CMC: BIMI for unregistered logos

When BIMI first arrived, it came with a catch that quietly excluded a large share of legitimate senders: to show your logo in the inbox, you needed a Verified Mark Certificate (VMC), and a VMC required a registered trademark. If your logo was not a registered mark in a recognised trademark office, you were stuck. You could publish a perfect BIMI record, host a flawless SVG, sit at p=reject, and still see a blank avatar or a plain initial where your brand should be.

The Common Mark Certificate (CMC) exists to close that gap. It is a certificate type designed for unregistered logos, so brands that never trademarked their mark, or whose mark is not yet registered, can still earn a verified logo slot in supporting mailbox providers. This article explains what a CMC actually is, how it differs from a VMC, exactly what evidence the certificate authority checks, where it is accepted today, and how to decide whether a CMC is the right route for your domain or whether you should wait or pursue a full VMC instead.

BIMI (Brand Indicators for Message Identification) lets a mailbox provider display your logo next to your messages, but only once you have proven two things:

  1. You control the domain and authenticate your mail. BIMI is gated behind DMARC at an enforced policy. If you are not at p=quarantine or p=reject with a sufficiently strong policy, no logo shows regardless of certificates.
  2. You are entitled to the logo. This is where the certificate comes in. Gmail, Apple Mail and others want assurance that the picture being shown is genuinely yours and not a logo lifted from a brand you are impersonating.

For the first few years, the only way to satisfy point 2 in the providers that required a certificate was the VMC. The VMC is issued by a small number of certificate authorities (DigiCert and Entrust being the established ones) and its core requirement is a registered trademark. The CA verifies that the logo in your certificate matches a live registration in an accepted trademark office, that the registration is in good standing, and that your organisation is the registered owner.

That requirement is sensible for large brands, but it locks out a huge population of legitimate senders:

  • A charity or small business that simply never registered its mark.
  • A school, club, council department or membership body whose logo is a long-standing word-and-device mark but was never trademarked.
  • A company in a jurisdiction whose trademark office is not on the accepted list.
  • A brand that has filed for a trademark but is still years away from registration (registration can take twelve to eighteen months or longer, and design marks can be refused).

All of those senders authenticate their mail correctly and have a genuine, honestly-owned logo. The CMC is the mechanism that lets them show it.

What a CMC actually is

A Common Mark Certificate is an X.509 certificate, issued by a certificate authority, that binds a specific logo image to a specific organisation, without requiring that the logo be a registered trademark. Structurally it is very similar to a VMC. It is a PEM file you host alongside your SVG logo, and you reference it from your BIMI DNS record using the a= tag, exactly as you would a VMC.

The crucial differences are in two places: the evidence the CA checks before issuing, and the mark type asserted inside the certificate.

Inside a VMC, the certificate signals that the logo is backed by a registered trademark and carries the trademark details (registration number, office, jurisdiction). Inside a CMC, the certificate signals that the logo is a common mark: a logo the organisation uses and is entitled to, but which is not being asserted as a registered trademark. Mailbox providers that read the certificate can tell the two apart, and they apply their own policy about which types they will trust and display.

A BIMI record that points at a CMC looks identical in structure to one that points at a VMC. Here is a complete example:

default._bimi.example.org.  IN  TXT  "v=BIMI1; l=https://bimi.example.org/logo.svg; a=https://bimi.example.org/cmc.pem"
  • v=BIMI1 is the version tag.
  • l= is the HTTPS URL of your SVG Tiny Portable/Secure logo.
  • a= is the HTTPS URL of your certificate. This is the same tag whether the file is a VMC or a CMC; the difference lives inside the PEM, not in the DNS syntax.

The logo itself has identical requirements either way. It must be SVG Tiny Portable/Secure (SVG Tiny PS), square, with a solid background, no external references, no scripting, and the title element set. If your artwork is not already in that profile, you will need to convert and tighten it. Our BIMI SVG converter and logo validator check the profile and flag the common rejection reasons before you ever submit it to a CA.

How a CMC is verified: what the CA actually checks

This is the part people most often misunderstand. A CMC is not a free pass or a self-signed image. The certificate authority still performs identity and ownership verification; it just substitutes the trademark-registration test for a different evidence chain. Because there is no registry to point at, the CA has to establish two things by other means:

  • That your organisation is who it claims to be. This is the same organisational validation the CA does for a VMC: confirming the legal entity exists, at the stated address, through government records, dun-and-bradstreet style databases, or equivalent.
  • That you are genuinely entitled to use this logo and have been using it. Because there is no trademark certificate to lean on, the CA looks for prior use and ownership evidence. In practice that means demonstrating the logo has been in use by your organisation for a meaningful period (commonly evidenced through your website, marketing materials, and a documented history), and providing a declaration of ownership.

The exact documentary requirements vary by CA and evolve, so always work from the issuing CA's current checklist rather than a blog. But the principle is consistent: a CMC trades the objective, machine-checkable fact of a trademark registration for a human-reviewed prior-use and identity assessment. That is more work for the CA, which is why CMCs were slower to arrive than VMCs and why turnaround and pricing can differ.

One consequence worth planning for: prior-use evidence favours established logos. A logo your charity has used for fifteen years is straightforward to evidence. A logo you redesigned last month is harder, because there is little public history to point at. If you have just rebranded, expect more questions, and keep dated copies of where the mark appears publicly.

Where a CMC is accepted, and where it is not

This is the single most important section, because the value of a CMC depends entirely on which inboxes honour it. Acceptance is not universal, and it is the main reason a CMC is sometimes the wrong choice.

The landscape splits roughly three ways:

  • Providers that display BIMI logos without requiring any certificate at all. Some mailbox providers show a BIMI logo purely on the basis of authentication and a valid SVG, with no VMC or CMC. For these inboxes you do not need a CMC; you need DMARC enforcement and a clean logo. Apple Mail historically displayed logos with relaxed certificate requirements compared with Gmail, and a number of providers behave similarly. If your target audience sits mostly behind these, a certificate of any kind may be optional.
  • Providers that require a certificate and accept the CMC type. This is the population the CMC was built for. Where a provider reads the certificate and is willing to honour a common mark (not only a registered mark), your CMC unlocks the logo slot that a bare SVG would not.
  • Providers that require a certificate and accept only a VMC (registered trademark). Some inboxes will not display a logo backed by a CMC; they insist on a registered-trademark VMC. Historically, the strictest displays, including the well-known Gmail logo treatment, were tied to VMC. CMC support has been expanding, but you must verify the current behaviour for the providers your recipients actually use rather than assume parity with VMC.

Because acceptance is provider-specific and changes over time, do not treat "I have a CMC" as "my logo shows everywhere". Treat it as "my logo shows in the providers that accept common marks", and then measure. Send test mail to addresses across the providers your audience uses and look at what actually renders. Our BIMI checker confirms your record and logo are valid and reachable, and the CMC simulator and VMC checker help you reason about how a given certificate type is likely to be treated before you spend money on issuance.

CMC versus VMC: how to choose

Both certificate types sit in the same a= slot and both require the same authentication groundwork. The decision comes down to whether you have, or can reasonably get, a registered trademark, and which inboxes you most need to reach.

Choose a VMC when:

  • You already hold a registered trademark for the logo in an accepted office, or can obtain one in a sensible timeframe.
  • Your priority is the widest possible display, including the providers that only honour registered marks.
  • You are a larger brand where the trademark is worth holding for reasons beyond email anyway.

Choose a CMC when:

  • You do not have a registered trademark and do not intend to file for one soon.
  • Your logo is well-established and you can evidence prior use.
  • The providers your recipients use are ones that honour common marks, or you are content to show in those and accept blanks in the strict-VMC inboxes.

A reasonable hybrid strategy for an organisation that has filed for a trademark but is waiting on registration: get a CMC now so you display in accepting inboxes during the wait, then move to a VMC once the registration is granted to widen coverage. Because both are referenced identically in DNS, swapping the certificate later is a low-risk change. You replace the hosted PEM, update the a= URL if it changed, and the BIMI record format stays the same.

The work that comes before any certificate

It is worth being blunt about this: a CMC is the last step, not the first. Buying a certificate before the foundations are in place wastes money, because no inbox will display the logo until the prerequisites are met. The order that actually works is:

  1. Get SPF and DKIM aligned and passing. BIMI rides on DMARC, and DMARC needs at least one of SPF or DKIM to pass and align with the visible From domain. Confirm both with the SPF checker and DKIM checker.
  2. Reach an enforced DMARC policy. You need p=quarantine or p=reject. Many providers also expect the policy to be strong enough that it is not trivially weakened (for example, a pct well below 100 or a permissive subdomain policy can undermine eligibility). Move there gradually using aggregate-report data so you do not block legitimate mail. The DMARC checker shows your current policy.
  3. Prepare a compliant SVG Tiny PS logo. Square, solid background, title set, no scripts or external references. Validate it before submission.
  4. Publish the BIMI record (logo only, no certificate yet) if you want logos in the no-certificate inboxes. This is optional but free, and it lets you confirm the pipeline works end to end before paying a CA.
  5. Then obtain and reference your CMC or VMC to unlock the certificate-gated inboxes.

If you skip straight to step 5, you will pay for a certificate that sits unused because step 2 was never finished. Getting to a safe p=reject without breaking real mail is precisely the hard part, and it is the part our done-for-you service and monitoring are built around. The requirements overview lays out the full eligibility checklist in one place.

Common mistakes and misconceptions

A few errors come up repeatedly with CMCs specifically:

  • Assuming a CMC equals a VMC everywhere. It does not. The whole point of the distinction is that providers can choose to treat common marks differently from registered marks. Always verify per provider.
  • Treating the CMC as a way to skip identity checks. The trademark requirement is removed; the organisational validation and the prior-use evidence are not. A CMC still proves who you are and that the logo is yours.
  • Hosting the certificate over plain HTTP, or behind a redirect, or with a broken chain. The a= URL must be reachable over HTTPS with a valid certificate chain, and the file must be the full PEM the CA issued. A broken a= fetch can suppress the logo even where everything else is correct.
  • Using a logo that does not match the certificate. The image hosted at l= must correspond to the logo bound in the certificate. Swapping in a different image after issuance breaks the binding.
  • Forgetting the DMARC gate. The most common reason a logo does not appear has nothing to do with the certificate type at all; it is that the domain is not yet at an enforced, sufficiently strong DMARC policy. If your logo is missing, check DMARC first. Our walk-through on why a BIMI logo does not show in Gmail covers the diagnostic order.

A worked example

Suppose you run a long-standing community sports charity, riverside-rowing.org. You have used the same oar-and-shield logo for over a decade, but you never registered it as a trademark. You want it in the inbox.

Your path with a CMC looks like this:

  1. You confirm SPF and DKIM pass and align, and you move DMARC from p=none through p=quarantine to p=reject over a few weeks, watching aggregate reports so legitimate club mail keeps flowing.
  2. You convert the logo to SVG Tiny PS, make it square with a solid background, set the title, and validate it.
  3. You publish a logo-only BIMI record and confirm the avatar appears in the no-certificate inboxes.
  4. You apply to a CA for a CMC. You provide organisational details (charity registration, address) and prior-use evidence: archived snapshots of the club website showing the logo over the years, printed materials, and a signed ownership declaration. The CA validates the entity and the prior use, and issues the CMC.
  5. You host the PEM over HTTPS and add a=https://bimi.riverside-rowing.org/cmc.pem to the record.
default._bimi.riverside-rowing.org.  IN  TXT  "v=BIMI1; l=https://bimi.riverside-rowing.org/logo.svg; a=https://bimi.riverside-rowing.org/cmc.pem"
  1. You send test mail across the providers your members use and record where the logo renders. In the certificate-accepting inboxes that honour common marks, the oar-and-shield now appears. In any strict-VMC inboxes, it may still show a fallback, and you accept that, or note it as a reason to pursue a trademark and VMC later.

That is the realistic outcome: a CMC gets a legitimate, unregistered logo into a meaningful share of inboxes, not necessarily every single one.

The practical takeaway

The Common Mark Certificate exists for one honest reason: plenty of legitimate senders have a real, long-used logo and no registered trademark, and they should not be permanently locked out of inbox branding because of it. A CMC lets those brands show their logo in mailbox providers that accept common marks, using exactly the same DNS plumbing as a VMC, with the trademark requirement replaced by an organisational-identity and prior-use review.

Two cautions, though. First, a CMC is not universally honoured; some inboxes, including the strictest logo displays, may still require a registered-trademark VMC, so verify acceptance for the providers your recipients actually use and measure real renders rather than assuming. Second, the certificate is the last step. None of it matters until your domain authenticates cleanly and sits at an enforced, sufficiently strong DMARC policy without breaking legitimate mail.

If you want to see whether your logo and record are valid before spending on a certificate, run them through the BIMI checker and the CMC simulator, and read the CMC glossary entry alongside VMC for the precise definitions. And if getting safely to p=reject and out the other side with a logo in the inbox sounds like more than you want to project-manage, that end-to-end journey, authentication, enforcement and BIMI, is exactly what our hosted BIMI service does for you.

Share

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.