What Is a VMC? BIMI Verified Mark Certificates Explained

The short answer
A Verified Mark Certificate (VMC) is a digital certificate from an authorized Mark Verifying Authority that proves your organization owns its logo as a registered trademark. BIMI itself does not require one, but the inboxes that matter do: Gmail needs a VMC or CMC, and Apple Mail needs a VMC. It is not a TLS certificate.
A VMC is the Verified Mark Certificate that proves your logo is a registered trademark, so BIMI can display it in Gmail and Apple Mail.
On this page
If you have started setting up BIMI, you have hit the acronym that turns a free branding feature into a paid one: the VMC. A Verified Mark Certificate is the piece that makes Gmail and Apple Mail actually draw your logo, and it is the reason people ask whether BIMI is worth the money at all. This is the glossary entry for that one component — what a VMC certificate for BIMI is, who issues it, and whether you truly need it.
We have a companion guide on BIMI as a whole and one on implementing it end to end. This page stays on the certificate layer, because that is where most of the cost, the confusion, and the trademark requirement live. Every provider and issuer fact here is dated August 2026 and checked against the primary source, because this corner of email keeps moving.
What is a VMC certificate?#
A Verified Mark Certificate (VMC) is a digital certificate that attests two things about a logo: that your organization is who it claims to be, and that it owns the logo it wants shown in the inbox. It is issued by an authorized third party — a Mark Verifying Authority (MVA), also called a BIMI-qualified certification authority — after that party checks your identity and your claim to the mark.
The ownership check is the whole point. For a VMC, ownership is normally proven by a registered trademark: the logo in your BIMI record has to match a trademark your organization has registered with a recognized trademark office (a government-defined mark can also qualify with some issuers). The certificate authority verifies that registration, confirms your control of the sending domain, and issues a certificate file that ties the logo, the trademark, and the domain together.
That attestation is what a receiving inbox trusts. When a mailbox provider draws your logo, it is not taking your word that the logo is yours — it is relying on the MVA that vouched for it. The certificate is the portable form of that vouching.
A VMC is not a TLS certificate
How a VMC works with BIMI#
A VMC never works alone. It is the top of a stack that has to be healthy underneath it. Your domain must already authenticate its mail with SPF and DKIM and enforce a DMARC policy of quarantine or reject — a monitoring-only p=none policy shows no logo, certificate or not.
Once that foundation is in place, you publish a BIMI record in DNS that points to your logo file (the l= tag) and, for the VMC, to the certificate file (the a= tag). When a message passes DMARC, a supporting inbox fetches the certificate, checks that it is valid and issued for your domain and logo, and only then renders the logo next to your name.
One thing to date-stamp, because most older guides get it wrong. The DMARC standard behind that enforcement was revised in 2026: RFC 9989 now obsoletes the earlier RFC 7489, dropping the pct tag and replacing the Public Suffix List with a bounded DNS tree walk. The BIMI requirement is unchanged in spirit — enforcement across all of your mail — but some provider docs, including Google's, still reference the retired pct tag.
The certificate is not the hard part — enforcement is
Why a VMC matters — what breaks without one#
Without a certificate, the two inboxes most senders care about show nothing. Gmail will not display a BIMI logo unless the record references a VMC or a CMC, and Apple Mail requires a VMC specifically. You can publish a correct DMARC policy and a valid logo file and still see a gray placeholder in both, because the certificate is the missing link.
A VMC also earns something a plain logo does not. In Gmail, a sender verified with a VMC gets a checkmark next to the name — a stronger signal than the logo alone (Google Workspace admin help, checked August 2026). A CMC displays the logo but does not earn that checkmark.
Not every provider draws the line the same way. Yahoo Mail and Fastmail display BIMI logos from self-asserted records, with no certificate at all, so a VMC's value depends on where your audience reads mail. If most of your recipients are on Gmail and Apple Mail, the certificate is effectively mandatory; if they are on providers that accept self-asserted records, it is optional.
VMC vs CMC: the certificate that fits your logo#
The comparison the certificate layer actually turns on is VMC versus CMC. The two exist for different logos. A VMC requires a registered trademark; a Common Mark Certificate (CMC) was introduced for organizations whose logo is not a registered trademark, using a lighter verification path — so nonprofits, government bodies, and brands without a registered mark have a route in.
Which one you need depends on your trademark and your audience. DigiCert issues both; Gmail accepts both but reserves its verified checkmark for the VMC; Apple Mail accepts only the VMC. The table below lays out the difference. It is dated August 2026 — verify each row against the issuer and the provider before you buy anything.
| Dimension | VMC (Verified Mark) | CMC (Common Mark) |
|---|---|---|
| Registered trademark required | Yes | No — other evidence of the mark |
| Shown by Gmail | Yes | Yes |
| Verified checkmark in Gmail | Yes | No |
| Shown by Apple Mail | Yes | No |
| Paid, renewed annually | Yes | Yes |
| Best for | Trademarked brand logos | Logos without a registered trademark |
Which certificate should you choose?#
If your logo is a registered trademark and you want it in both Gmail and Apple Mail, the VMC is the only option that reaches both, and it is the one that earns Gmail's checkmark. If your logo is not trademarked, a CMC gets you a logo in Gmail but nothing in Apple Mail — and if Apple Mail matters to your audience, that gap is the deciding factor.
If you are only testing BIMI, or your recipients sit on providers that accept self-asserted records, you can publish a record with no certificate and add one later. Just do not expect Gmail or Apple Mail to draw anything until the a= certificate is in place.

Who issues Verified Mark Certificates?#
VMCs are not issued by just any certificate authority. Only a small set of Mark Verifying Authorities are authorized, and the BIMI Group maintains the definitive list. As of August 2026, that list names DigiCert, GlobalSign, and SSL.com as VMC issuers (BIMI Group Certificate Issuers page).
The roster has changed over time, which is exactly why the live list is the source of truth, not an older article. Entrust was one of the original authorized VMC certificate authorities alongside DigiCert, but it is not on the BIMI Group's current issuer list; do not assume an issuer is still authorized from a page written a few years ago. Before you buy, confirm the issuer on the BIMI Group's page and confirm that your target inbox accepts that issuer's certificate.
On price, there is no flat industry rate. A VMC is a paid certificate, renewed annually, and pricing is set by each issuer. If your logo is not yet a registered trademark, registering one for the VMC route is a separate and slower cost handled through a trademark office. Get a current quote from an authorized issuer rather than relying on a figure copied from a blog.
Check the issuer list live before you buy
Common misconceptions about VMCs#
- BIMI requires a VMC. Not at the standard level — a self-asserted BIMI record with no certificate is valid, and Yahoo and Fastmail will show its logo. It is Gmail and Apple Mail that require a certificate, which is why most senders end up needing one.
- A VMC is a security certificate like the padlock. No. It does not encrypt anything and has nothing to do with HTTPS on your website. It attests logo ownership; the padlock is a TLS certificate doing an unrelated job.
- Any logo can get a VMC. Only a logo that is a registered trademark qualifies for a VMC. A logo without a registered mark needs a CMC instead, and a CMC does not appear in Apple Mail.
- One VMC covers all my brands. A certificate is tied to a specific logo and the domains it is issued for. Separate brands or unrelated domains generally need their own.
- A VMC improves deliverability. It does not. It changes how your mail looks once it is already delivered and authenticated; it does not move mail from spam to the inbox.
How this shows up in AI Emaily#
A VMC is something you buy for the domain you send from, so your logo appears in other people's inboxes. AI Emaily sits on the opposite side of that exchange — it is the AI-native client you read your own mail in — so it is worth being clear that we do not issue, verify, or host VMCs. That work belongs to a Mark Verifying Authority and your DNS, and a page that implied a mail client could stand in for a certificate authority would be selling you something we do not do.
Where AI Emaily meets this topic is the receiving end. The same SPF, DKIM, and DMARC results that a VMC sits on top of are signals our spam and phishing defense reads when it decides what reaches your inbox and what to hold back. The enforced DMARC that a VMC requires is exactly what lets a reading client confidently reject mail that spoofs a domain. We build AI Emaily — across Gmail, Outlook, and any IMAP account, with approve-before-send drafting, an audit trail, and no training on your mail.
Frequently asked
See it in AI Emaily
Keep reading
Sources

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.