Email Authentication Glossary
Certificate & VMC
BIMImedium

VMC PEM Bundle Contains Only the Leaf Certificate

“VMC PEM bundle contains only the leaf certificate” means the fetched PEM bundle contains one end-entity VMC and no issuer certificate. The VMC draft requires every intermediate certificate but makes

The exact error

VMC PEM bundle contains only the leaf certificate

What Does “VMC PEM Bundle Contains Only the Leaf Certificate” Mean?

“VMC PEM bundle contains only the leaf certificate” means the fetched PEM bundle contains one end-entity VMC and no issuer certificate. The VMC draft requires every intermediate certificate but makes inclusion of the root optional; Google separately asks senders to append intermediates and the root. Fetch and Validation of Verified Mark Certificates draft 11 documents the controlling requirement or boundary.

A current leaf-only bundle lacks the intermediate needed to build the required VMC path. Root inclusion remains provider-specific because the draft permits omission while Google asks publishers to append it.

Why Does VMC PEM Bundle Contains Only the Leaf Certificate Appear?

VMC PEM bundle contains only the leaf certificate appears when the fetched PEM contains only the leaf certificate; the diagnostic does not establish what was originally uploaded or whether another layer modified it. The exact diagnostic should be read at the scope of served VMC PEM bundle rather than as proof that every BIMI layer failed.

How Do You Fix VMC PEM Bundle Contains Only the Leaf Certificate?

To fix VMC PEM bundle contains only the leaf certificate, append every required intermediate CA certificate in issuance order and follow target-provider guidance on including the root.

Adding intermediates does not prove certificate signatures, trust, validity, or VMC profile compliance.

What Should You Verify After Fixing VMC PEM Bundle Contains Only the Leaf Certificate?

After fixing VMC PEM bundle contains only the leaf certificate, build and validate the issuance path from the served bundle against the intended trust anchor. Verification should use the exact public selector, URL, record, or file evaluated by the receiver.

The correction clears only this condition; it does not guarantee that a receiver will display an indicator.

Key Takeaways

  • The affected object is served VMC PEM bundle.
  • The direct correction is to append every required intermediate CA certificate in issuance order and follow target-provider guidance on including the root.
  • Adding intermediates does not prove certificate signatures, trust, validity, or VMC profile compliance.
Check your BIMI record

See exactly which checks your domain passes and fails.

Email Authentication Glossary