Verified Mark Certificate (VMC): What It Is, Who Needs One & How to Get It
What a VMC actually proves, why the largest mailbox providers require one before displaying any BIMI logo, the realistic issuance process and cost, and how CMC compares as an alternative.
The Trust Gap a VMC Was Built to Close
The BIMI specification, read literally, doesn't require a certificate at all — a domain that meets the DMARC enforcement bar and publishes a valid SVG logo has, by the letter of the spec, a complete and valid BIMI record. That literal reading exposes an obvious gap the moment you think about it adversarially: DMARC enforcement proves a domain controls its own mail authentication, but it proves nothing whatsoever about whether that domain has any legitimate right to a specific logo image. Nothing in DMARC enforcement stops a lookalike domain — one that's genuinely DMARC-enforced for its own, entirely unrelated purposes — from publishing a well-known brand's exact logo as its own BIMI image, assuming it could clear that one prerequisite. A Verified Mark Certificate exists specifically to close this gap, by requiring independent, third-party verification that the entity publishing a given logo actually owns the trademark rights to it, before any major provider will agree to display it.
This is why, even though the specification lists the a= certificate tag as optional, the largest mailbox providers by user count — Gmail, Google Workspace, and Apple Mail among them — have made it a practical requirement for their own BIMI implementations. From their perspective, this isn't an arbitrary extra hurdle; it's the missing piece that makes BIMI logo display trustworthy enough to put in front of billions of users without creating a straightforward new brand-impersonation vector.
What the VMC Issuance Process Actually Involves
Applying for a VMC follows a process that will feel familiar to anyone who has gone through Extended Validation (EV) SSL certificate issuance, since both rely on a similar philosophy of thorough, human-involved identity verification rather than automated, instant issuance. The process typically starts with submitting documentation proving active, registered trademark ownership matching the exact logo intended for BIMI use — not a pending application, not a similar but distinct mark, the exact registered trademark. The Certificate Authority then verifies this registration directly against the relevant trademark office's records. In parallel, the CA verifies domain control for the sending domain the certificate will be tied to, typically through a domain validation method similar to standard SSL certificate issuance. Once both trademark and domain verification are complete, the CA verifies the submitted logo file matches the registered mark precisely, and only then issues the certificate, which is then hosted at a stable HTTPS URL and referenced in the domain's BIMI record via the a= tag.
A Realistic Application Timeline, Week by Week
While every application differs based on trademark jurisdiction and documentation readiness, a representative timeline helps set expectations for teams going through the process for the first time. In the first week, an organization typically gathers trademark registration documentation, confirms domain administrative access, and submits the initial VMC application along with the candidate SVG logo file to a chosen Certificate Authority. During the second and third weeks, the CA conducts trademark registry verification and domain control validation, a period during which applicants should expect to respond to any follow-up documentation requests promptly, since delayed responses are one of the most common causes of an application timeline extending beyond initial estimates. By the fourth week, assuming no complications, the CA typically completes final review and issues the certificate, at which point it needs to be hosted at a stable URL and referenced in the domain's BIMI record. Applications involving less common trademark jurisdictions, licensing arrangements rather than direct ownership, or documentation gaps discovered mid-process can extend this timeline considerably, sometimes to six or eight weeks or longer, which is another reason to start the VMC application well ahead of any hard external deadline like a product launch or marketing campaign.
What to Do If Your VMC Application Is Rejected or Delayed
Not every application proceeds smoothly on the first attempt, and understanding common rejection or delay reasons helps applicants course-correct efficiently rather than resubmitting the same incomplete application repeatedly. The most frequent cause is a mismatch between the submitted logo file and the registered trademark — even minor stylistic differences, a color variation, or a simplified version used for BIMI purposes that differs visually from the registered mark can trigger this. The fix is either submitting a logo that exactly matches the registered mark, or in some cases, registering the specific variant intended for BIMI use as its own trademark before reapplying. Another common cause is incomplete or ambiguous legal standing documentation, particularly for applications submitted by agencies, subsidiaries, or licensees rather than the direct trademark owner — the fix here is providing clear, explicit documentation of the legal relationship and authorization to request the certificate. Domain control verification failures are usually the most straightforward to resolve, typically requiring only that the applicant complete a standard domain validation step (DNS record, email confirmation, or file placement) that may have been missed or expired during the application window.
Real-World Use Cases
Why Certificate Authorities Are Central to How VMC Works
It's worth understanding why a third-party Certificate Authority sits in the middle of this process at all, rather than mailbox providers simply verifying trademark ownership themselves directly. The answer mirrors why the broader web relies on Certificate Authorities for SSL/TLS rather than every browser vendor independently verifying every website's identity: it would be enormously duplicative and inconsistent for every mailbox provider to build and maintain its own trademark verification infrastructure, staff, and legal review process. Instead, a small number of authorized CAs specialize in this specific verification work, and mailbox providers simply trust certificates issued by those authorized CAs, the same trust delegation model used throughout the broader public key infrastructure ecosystem. This also means the list of CAs authorized to issue VMCs isn't arbitrary — it typically requires a CA to meet specific technical and procedural standards set by the BIMI ecosystem's governing bodies, similar to how browsers maintain their own lists of trusted root certificate authorities for general SSL/TLS.
A Closer Look at the Domain Validation Component
Trademark verification gets most of the attention when discussing VMC issuance, but the domain control verification component matters just as much and is worth understanding separately. The CA needs to confirm that the entity requesting the certificate genuinely controls the sending domain the certificate will be associated with — otherwise, even a legitimate trademark holder could theoretically request a certificate tied to a domain they don't actually control, creating a different kind of trust gap. This domain validation typically follows patterns familiar from standard SSL/TLS issuance: proving control through a DNS record, an email confirmation to an address at the domain, or a file placed at a specific location on the domain's web server. Organizations preparing for VMC issuance should have domain administrative access readily available during the application process, since delays in domain validation are a common, avoidable source of extended issuance timelines that have nothing to do with the trademark verification itself.
What Happens During Trademark Verification, Specifically
The trademark verification step is typically the most involved part of the process, and understanding what the CA is actually checking helps applicants prepare more efficiently. The CA confirms the trademark registration is currently active (not expired, abandoned, or cancelled) with the relevant national or regional trademark office, confirms the registration covers a mark that visually matches the logo submitted for certification (not merely a similar or related mark), and confirms the applying entity has legitimate legal standing to request the certificate — either as the registered trademark owner directly or as an authorized licensee with documented permission to use the mark. This last point matters more than it might initially seem: a marketing agency managing BIMI on behalf of a client typically cannot request a VMC in its own name for a client's trademark without documented authorization, since the certificate needs to reflect genuine legal standing, not just technical or administrative control over the domain's DNS.
Comparing VMC Providers: What to Evaluate
Organizations evaluating which authorized Certificate Authority to work with for VMC issuance should consider several practical factors beyond price alone: typical issuance turnaround time (since this is usually the bottleneck in a broader rollout timeline), the quality and responsiveness of support during the verification process (given how much back-and-forth documentation review can involve), whether the CA offers any bundled tooling for managing certificate renewal reminders, and whether the CA has experience specifically with your organization's trademark jurisdiction, since verification familiarity with a specific country's trademark office processes can meaningfully affect how smoothly the process goes. Requesting a realistic timeline estimate directly from the CA before committing, based on your specific trademark and domain situation, tends to be more reliable than relying on general published estimates that may not reflect current processing volumes or your particular case's complexity. It's also worth asking prospective CAs directly about their track record with your specific mailbox provider targets, since a CA's certificates being reliably recognized by Gmail and Apple Mail specifically is the entire point of the exercise.
What Happens to My BIMI Logo Display if My VMC Expires
An expired VMC is worth dwelling on specifically because it's the single most common reason a previously working BIMI setup appears to break with no obvious cause. Nothing about the DNS record changes, nothing about the SVG logo file changes, and nothing generates an error message anywhere in a typical sending pipeline — the certificate simply passes its expiry date, and on the next evaluation cycle, providers that require certificate validation for display quietly stop showing the logo. From the sender's perspective, this often surfaces days or weeks later, when a marketing or brand stakeholder notices the logo is missing and asks why, at which point diagnosing the cause requires specifically checking certificate validity rather than assuming a DNS or hosting problem, since those layers remain entirely unaffected. This is precisely why calendaring renewal well ahead of the expiry date, rather than relying on someone noticing a visual change after the fact, is the single highest-leverage habit for maintaining reliable long-term BIMI display.
Internal Ownership: Who Should Manage the VMC Relationship
Because VMC issuance and renewal sits at the intersection of legal (trademark documentation), marketing or brand (the logo and its display), and IT or engineering (DNS publication and hosting), it's genuinely common for organizations to struggle with clear ownership, and that ambiguity is precisely where certificates lapse unnoticed. The most durable pattern observed across organizations that maintain BIMI reliably over multiple years is designating a single named owner — often someone on the IT or security team already responsible for domain and DNS management — who is accountable for tracking renewal dates and coordinating with legal and brand stakeholders as needed, rather than assuming renewal will be handled reactively whenever someone happens to notice the logo has stopped appearing, which by definition means the gap has already occurred by the time anyone acts on it. This single-owner model doesn't mean that person does all the work alone; it means there's one clear point of accountability rather than a shared responsibility that, in practice, often means no one specifically tracks it.
Related Reading
Start with What Is BIMI? for the foundational overview. For the complete requirements list, see BIMI Requirements. For the logo file this certificate must match exactly, read SVG Logo for BIMI. To confirm your own domain's certificate is currently reachable and referenced correctly, use the BIMI Checker.
ToolsNovaHub guides are researched against primary sources (RFCs, vendor docs) and kept up to date as standards change. Spotted an error? Let us know.
📋 Related Tools & Guides Comparison
| Resource | Type | Link |
|---|---|---|
| BIMI Checker | Tool | Open Tool → |
| DMARC Lookup | Tool | Open Tool → |
| What Is BIMI? | Guide | Read Guide → |
| BIMI Requirements | Guide | Read Guide → |
| SVG Logo for BIMI | Guide | Read Guide → |
| BIMI vs DMARC | Guide | Read Guide → |