DMARC Engine
Home/Blog/BIMI VMC cost and certificate authorities
Blog

BIMI VMC cost and certificate authorities

What a Verified Mark Certificate actually costs, which CAs issue them (DigiCert and Entrust), how trademark and entity validation works, and what to watch at renewal so your logo never silently disappears.

14 March 2026 · 11 min read

BIMI VMC cost and certificate authorities

A Verified Mark Certificate (VMC) is the part of BIMI that most people underestimate. The DNS record is free, the SVG logo is a one-off design job, but the certificate that proves you own your trademarked logo is a recurring, audited purchase from a very small number of certificate authorities. If you are budgeting a BIMI rollout, the VMC is the line item that needs a real number against it, plus a renewal reminder. This article breaks down what a VMC actually costs, who issues them, what the validation process involves, and what happens at renewal, all specific to how BIMI works in 2026 rather than a generic certificate explainer.

If you only want to confirm your logo is showing and your certificate is valid, the BIMI VMC checker and BIMI checker will read your live record and certificate without you spending anything. But if you are weighing up whether to buy one at all, read on.

What a VMC is, and why it costs money

BIMI (Brand Indicators for Message Identification) lets a mailbox provider display your brand logo next to authenticated mail. The mechanism is a DNS TXT record at default._bimi.yourdomain.com that points to an SVG logo and, optionally, to a certificate:

default._bimi.example.com. IN TXT "v=BIMI1; l=https://example.com/logo.svg; a=https://example.com/vmc.pem"

The l= tag is the logo. The a= tag is the authority evidence, and that is the VMC. Gmail, Apple Mail (iOS 16+ and macOS Ventura+), and several other providers will not display your logo unless the a= tag resolves to a valid VMC or its cheaper sibling, a Common Mark Certificate (CMC). Yahoo historically displayed BIMI logos with just a logo and no certificate, but the large providers that matter for inbox real estate now require certificate-backed BIMI.

The certificate costs money because it is not a free domain-validated TLS certificate. It is an audited assertion that:

  1. You control the domain in the BIMI record.
  2. The logo in the certificate is a registered trademark (for a VMC) or has documented prior use (for a CMC).
  3. The legal entity named in the certificate is the genuine rights holder.

That requires a human-driven validation process at the CA, legal review of trademark documents, and an industry audit regime. None of that is free, and that is the entire reason the VMC carries a price that free TLS does not.

If your only blocker is the certificate cost, it is worth understanding what BIMI gives you without one before committing. We cover that in BIMI without a VMC and the wider question of whether BIMI is worth it in do you need BIMI.

VMC cost in 2026: the honest numbers

There is no single published "list price" that holds across every reseller, but the market has settled into a fairly narrow band. Treat these as planning figures, not quotes, because resellers, volume, and bundling all move the final number.

  • VMC (trademark-backed): roughly 1,000 to 1,500 USD per year, per certificate. Buying direct from a CA tends to sit at the higher end of that range. Buying through a reseller or as part of a larger certificate portfolio can bring it down.
  • CMC (Common Mark Certificate, no trademark required): typically a little cheaper than a VMC, often in the 1,000 to 1,300 USD per year range. The saving is modest because the validation work is similar; the difference is the logo eligibility rules, not a fundamentally cheaper product.
  • Multi-year terms are usually offered as an upfront multiple (for example, paying for two years up front), sometimes with a small discount versus paying annually. Be careful here: BIMI certificate validity periods have been trending shorter, so a long term may not always be available.

A few cost realities that catch people out:

  • The certificate is per logo and per legal entity, not per domain in the simple sense. One VMC can cover multiple domains and subdomains in its Subject Alternative Names if they belong to the same entity and use the same mark, but a genuinely different brand or logo needs its own certificate. A holding company with five distinct consumer brands is looking at five certificates, not one.
  • Trademark registration is a separate, prior cost. A VMC requires a registered trademark for the exact logo. If you do not already hold one, registering a figurative (logo) trademark through an office such as the UKIPO, EUIPO, or USPTO is its own multi-hundred-pound process that takes months. The VMC price assumes you already have the registration.
  • Design and conversion are extra. Your logo must be a specific, tightly constrained SVG (SVG Portable/Secure, the SVG Tiny 1.2 profile with restrictions). Converting a normal SVG or designing a square, centred mark is design time, not a CA fee. Our BIMI SVG converter and logo validator handle the technical SVG constraints for free, but the artwork judgement is on you.

So the all-in first-year cost for an organisation starting from scratch is rarely just the certificate. A realistic first-year figure is the VMC price plus possible trademark registration plus a little design time. Renewal years are cleaner: essentially just the certificate again.

Who issues VMCs: the certificate authorities

This is a deliberately small club. VMC issuance is governed by requirements maintained by the AuthIndicators Working Group, and a CA has to be specifically authorised, pass the relevant audits, and have its root included in the providers' trust programmes. As of 2026 the practical choices are:

DigiCert

DigiCert was the first CA to issue VMCs and remains the most widely used. They issue both VMCs (trademark-backed) and CMCs. If you ask a mailbox-provider engineer which root they see most often in the wild, DigiCert is the answer. Their validation process is mature, and a large share of the documentation and tooling in the BIMI ecosystem assumes a DigiCert-issued certificate. For most buyers, DigiCert is the default.

Entrust

Entrust is the other established issuer of VMCs and CMCs and is the main alternative to DigiCert. Functionally the product is the same: a certificate that satisfies the a= tag and is trusted by the major providers. Pricing and the validation experience differ in detail rather than in kind. If you already have a certificate relationship with Entrust, or you want a second quote to keep DigiCert honest on price, Entrust is the natural place to go.

A practical note on the field: the list of authorised VMC issuers has changed over time and is not large. Before you commit to any other vendor claiming to sell VMCs, confirm two things: that their issuing root is actually in Google's and Apple's BIMI trust programmes, and that the certificate they sell carries the correct VMC extended key usage. A certificate that is not from a recognised issuer will simply fail to render your logo, no matter how official it looks. You can validate any issued certificate against the live record with the BIMI VMC checker.

Whichever CA you choose, the certificate is technically an X.509 certificate with a BIMI-specific extension carrying the logo, and a special extended key usage OID that marks it as a VMC. The mailbox provider checks the chain, the key usage, and that the logo embedded in the certificate matches the logo at your l= URL. They must match exactly.

The validation process, step by step

This is where time and effort actually go. Budget weeks, not days, for a first VMC. The sequence is roughly:

  1. Prepare the trademark. For a VMC, you need a registered figurative trademark for the exact logo, and the registration must be live (not pending, not expired) in a jurisdiction the CA accepts. You will need the registration number and the issuing office. The logo on the certificate has to match the registered mark and the SVG you publish.
  1. Prepare the SVG logo to spec. The logo must be SVG Tiny 1.2 (the Portable/Secure profile, SVG P/S), square, with a solid background, no external references, no scripting, and within size limits. Use the BIMI logo validator to confirm conformance before you submit, because a non-conforming SVG will fail at the CA and again at the provider.
  1. Submit the order and identity documents. The CA validates the legal entity. Expect the kind of organisation validation used for EV certificates: confirming the company is real, registered, and that the person requesting is authorised to act for it. This usually means company registration details and a verification call or callback to a number the CA independently sources.
  1. Trademark and logo review. The CA's validation team checks that the trademark registration is genuine, that it belongs to the requesting entity, and that the logo in your submission matches the registered mark. Discrepancies (a colour variation, a tagline that is not in the registration, a logo that is not actually the registered figurative mark) get bounced back. This is the single most common source of delay.
  1. Domain control validation. Standard proof that you control the domains going into the certificate, similar to any other certificate issuance.
  1. Issuance and installation. The CA issues a PEM file containing the certificate and its chain. You host that PEM at an HTTPS URL and reference it in the a= tag of your BIMI record. The order of the chain matters; providers expect the leaf followed by intermediates.
  1. Publish and verify. Once the record and PEM are live, confirm with a checker that the logo renders and the certificate validates. A VMC that is installed but mis-chained, or whose embedded logo does not byte-for-byte match the published SVG, will silently fail to display.

The whole pipeline only works if your underlying email authentication is already solid. BIMI requires DMARC at an enforcing policy: p=quarantine or p=reject, and crucially not p=none, with full coverage (no pct below 100 in the way that weakens enforcement). If your DMARC is not at enforcement, no certificate will make your logo appear. Check your policy with the DMARC checker and read DMARC policy explained before you spend anything on a VMC. Getting safely from p=none to p=reject without losing mail is the prerequisite, and it is exactly what our DMARC product and the enforcement journey are built around.

Why VMC validation fails, and how to avoid paying twice

The validation fees are largely non-refundable once work has started, so failing validation is expensive in time and patience even when it is not expensive in re-billing. The recurring failure modes:

  • Logo does not match the registered trademark. The registered mark is black and white but you submit a colour version; the mark includes a wordmark but your BIMI SVG is the icon only; the proportions differ. The certificate's logo must correspond to the registered figurative mark.
  • Trademark is pending, not registered. "Applied for" is not enough for a VMC. The registration must be granted. If yours is still pending, a CMC may be your only certificate route in the meantime.
  • SVG is not the right profile. A normal export from a design tool is almost never SVG P/S compliant. Strip scripts, external references, and unsupported elements first; the SVG converter does the heavy lifting.
  • Entity mismatch. The trademark is held by a parent company but the certificate is requested for a subsidiary, with no documented link. CAs need the requesting entity to be the rights holder or to have a clear, evidenced relationship.
  • DMARC not at enforcement. Strictly this is not a CA failure, but it is the reason a correctly issued certificate produces no visible logo. Confirm enforcement first.

Renewal: what changes and what to watch

A VMC is not buy-once. Renewal is the part teams forget, and a lapsed VMC means your logo quietly disappears from inboxes with no error anyone sees until someone notices.

  • Validity has been getting shorter. Certificate validity periods across the public certificate ecosystem are trending down, and BIMI certificates have moved with that trend. Plan on re-validating roughly annually rather than assuming a long multi-year certificate will sit untouched. Do not architect a process that only happens every three years.
  • Renewal is not always "click renew". Because part of the value is the trademark and entity validation, renewal can require re-confirming that the trademark registration is still live and that the organisation details are unchanged. A trademark that has lapsed since issuance will block renewal of a VMC; you would either renew the trademark or drop to a CMC.
  • Logo changes mean a new certificate, not a renewal. If you rebrand and change the logo, the embedded logo in the certificate no longer matches, so you need a fresh certificate covering the new mark (and ideally a new trademark registration for it). Treat a rebrand as a new VMC project.
  • The PEM has to be re-published. On renewal you receive a new PEM. The a= URL must serve the new file. If you point a= at a static path and forget to swap the file, the old certificate expires and the logo drops.

Two operational habits prevent nearly all renewal pain:

  1. Calendar the expiry well in advance (60 to 90 days out), not on the day it expires, because re-validation takes time.
  2. Monitor the live record continuously so that an expired or mis-served certificate raises an alert before your customers notice the missing logo. This is exactly what continuous monitoring is for: it watches the BIMI record, the logo URL, and the certificate together and alerts on change, including silent expiry. Our BIMI product and analytics cover this so the certificate you paid for keeps earning its keep.

VMC versus CMC: which certificate to buy

Choosing between the two certificate types is mostly a question of whether you hold a registered trademark for the logo:

  • Buy a VMC if you have a registered figurative trademark for the exact logo you want to display. It is the original, most widely recognised credential and the one most associated with the "verified" tick that some providers add alongside the logo.
  • Buy a CMC if you do not have a registered trademark but can demonstrate prior use of the logo, or your logo is otherwise ineligible for trademark-backed validation (for example certain government, flag, or descriptive marks). The CMC fills the gap that previously locked non-trademarked but legitimate brands out of BIMI entirely.

The cost difference between the two is real but not dramatic, so the decision is driven by eligibility far more than by price. If you are unsure which you qualify for, the practical move is to confirm your trademark status first, then talk to DigiCert or Entrust about the appropriate product. You can model how the two render and validate with the BIMI VMC checker.

The practical takeaway

A VMC is a recurring, validated purchase, not a free DNS tweak. Budget roughly 1,000 to 1,500 USD per year for a trademark-backed VMC (a CMC sits slightly below that), buy it from DigiCert or Entrust as the two established issuers, and remember the hidden prerequisites: a registered trademark for a VMC, a spec-compliant SVG, an enforcing DMARC policy, and a calendar reminder for renewal. The certificate only pays off if the foundations under it are right, so the cheapest mistake to avoid is buying a VMC while your DMARC is still at p=none and your logo never appears.

Before you spend anything, confirm your DMARC is at enforcement with the DMARC checker, validate your logo with the BIMI logo validator, and check exactly what your live BIMI record and certificate are doing with the BIMI VMC checker. If you would rather not project-manage trademark documents, SVG profiles, DMARC enforcement, and annual certificate renewals yourself, the done-for-you BIMI product handles the whole chain, and our BIMI setup guide walks through it step by step.

Share

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.