Should you choose a VMC or a CMC?
Choose a Verified Mark Certificate (VMC) if you hold a registered trademark and you want the widest current provider support, including the Gmail verified checkmark and logo display in Apple Mail. Choose a Common Mark Certificate (CMC) if you do not hold a registered trademark but have displayed your logo publicly on a domain you own for at least 12 months. Gmail shows a CMC logo without the verified checkmark.
Your situation | Better fit | Why |
You hold a registered trademark | VMC | A VMC gives the widest support. It is the only certificate that gets the Gmail verified checkmark, and Apple documents a VMC for Apple Mail on macOS 13, iOS 16, and iPadOS 16 and later. |
You have no registered trademark, but your logo has been public on a domain you own for 12 or more months | CMC | A CMC verifies prior use instead of a trademark, and Gmail shows a CMC logo without the checkmark. |
Your trademark application is in progress | CMC now, VMC later | A CMC gets your logo into supporting inboxes now, and you move to a VMC once the trademark registers. |
Cost and logo-modification flexibility usually favor a CMC, but they rarely outweigh trademark status. If you hold a trademark and want the checkmark or Apple Mail, a VMC is still the better fit. Government entities use a Government Mark Certificate (GMC), verified through official government records.
Both certificates need the same foundation, which is DMARC at enforcement plus a compliant logo file, and both bind your logo to a certificate that a mailbox provider reads before it shows the logo. They differ in the eligibility you must prove, the providers that display them, and the flexibility you have with the logo artwork.
Gmail shows these logos now, Yahoo shows them for senders with a good sending reputation, and Apple documents support for Apple Mail, so a correctly issued certificate shows your logo across the major inboxes. Issuers and provider rules do change, so check the sources and the last-reviewed date on this page before you apply.
Not sure where your domain stands? Check your BIMI readiness to see what it still needs.
Are you eligible for a VMC, CMC, or GMC?
Each certificate is a Mark Certificate, a digital certificate issued by a certificate authority that ties your logo to the domain authorized to send your email, and it acts as the evidence document a BIMI record points to. The type you qualify for depends on the evidence you can show.
- VMC. You need a logo registered as a trademark with a recognized intellectual-property office. The certificate authority verifies the registration with the relevant trademark office or the WIPO Global Brand Database.
- CMC. You need no trademark. Instead you show common-law prior use, a logo displayed publicly on a domain you own for at least 12 months, which the certificate authority verifies through website history, archive.org, or marketing materials. The authority also confirms no other organization holds a trademark on the logo.
- GMC. A Government Mark Certificate exists for government entities, verified through official government records.
A CMC still blocks lookalike senders even without a trademark, because the authority runs prior-use due diligence on the logo, confirms you control the sending domain and pass DMARC at enforcement, and vets that the applicant is authorized to act for your organization.
How do VMC and CMC requirements compare?
This is the single comparison table for the two certificates. Every row is self-contained, and the volatile rows carry a primary source and a review date.
Factor | VMC | CMC | Primary source | Last reviewed |
Eligibility basis | A logo registered as a trademark with a recognized IP office | A logo shown publicly on a domain you own for at least 12 months, no trademark needed | 2026-07-30 | |
Accepted mark evidence | The authority verifies the registration with the trademark office or the WIPO Global Brand Database | The authority verifies 12 months of public use through website history, archive.org, or marketing materials | 2026-07-30 | |
Provider-dependent display | Gmail shows the logo and its verified checkmark, and Apple documents a VMC for Apple Mail | Gmail shows the logo without the checkmark, and whether Apple accepts a CMC is not confirmed | 2026-07-30 | |
Logo modification rules | The displayed logo must match the registered trademark | More flexibility to use a logo without a registered trademark, so you are not tied to a registered design | 2026-07-30 | |
Application evidence | DMARC at enforcement, a compliant SVG P/S logo, trademark proof, and CA identity and domain-control verification | DMARC at enforcement, a compliant SVG P/S logo, 12-month public-use proof, and CA identity and domain-control verification | 2026-07-30 | |
Transition constraints | You can hold both a VMC and a CMC, but only one certificate is active per sending domain at a time | You can upgrade to a VMC once a trademark registers | 2026-07-30 | |
Cost and timing variables | Cost and issuance time vary by authority and by whether the trademark is already registered | Cost and issuance time vary by authority | 2026-07-30 |
Both certificate types are valid for about one year, up to a maximum of 397 days, and need annual renewal to keep the logo showing. Both are issued by the same set of authorities, listed in the Sources section.
How does mailbox-provider support change your choice?
Provider support is the practical tie-breaker, because a certificate only helps where the provider displays it. Support and conditions vary by provider, so match your choice to the mailboxes your recipients actually use.
Provider | VMC | CMC | Display surface and caveat | Primary source | Last reviewed |
Gmail and Google Workspace | Shows the logo and the verified checkmark | Shows the logo without the checkmark | Web and mobile apps, self-asserted records not shown | 2026-07-30 | |
Yahoo and AOL | Factored if present, not required | Accepted, gated on reputation | Mobile message list and read view in the Yahoo and AOL apps, desktop read view in webmail, no checkmark distinction | 2026-07-30 | |
Apple Mail | Documented, with other BIMI evidence documents | Not confirmed | macOS 13, iOS 16, and iPadOS 16 and later, provider must be on the BIMI Group list and Apple-verified with valid evidence and vouching headers | 2026-07-30 | |
Fastmail | Optional | Optional | Conditional display, needs DMARC at enforcement, and Fastmail does not fetch external servers at view time | 2026-07-30 | |
Microsoft Outlook | Not displayed | Not displayed | Outlook, Outlook.com, Exchange Online, and Microsoft 365 do not render inbound BIMI as of 2026, with no announced date | 2026-07-30 |
The Gmail verified checkmark is the clearest split. It appears for a VMC only, and a CMC shows the same logo without it, so the checkmark is a reason to prefer a VMC when it matters to your audience and not a reason to expect different logo placement. Apple Business Connect is a separate Apple program from BIMI, so enrolling in Business Connect is not the same as publishing a BIMI record.
If your question is general logo troubleshooting rather than certificate choice, the complete BIMI implementation guide covers why a logo does not appear.
What evidence does a certificate application require?
Both certificates share the same technical prerequisites and differ only in how the authority verifies your logo.
- DMARC at enforcement. Your domain needs a DMARC policy of
p=quarantineorp=rejectapplied to all mail. A monitor-only policy ofp=nonedoes not qualify. - A compliant SVG logo. The file must meet the SVG Portable/Secure (SVG P/S) profile, a profile of SVG Tiny 1.2, with a square aspect ratio, a solid background, a required
<title>element, and a size at or under 32 KB. If you need to produce one, create a BIMI-compatible SVG logo. - A published BIMI record. A DNS TXT record that points to the logo file and the certificate.
For a VMC the authority verifies the trademark registration with the trademark office or the WIPO Global Brand Database, and if you are not the direct trademark owner you supply an authorization letter from the mark owner. For a CMC the authority verifies 12 months of public logo use through website history, archive.org, or marketing materials, and confirms no conflicting trademark.
Certification Authority Authorization (CAA). CAA is a general public-key-infrastructure control, not a BIMI-specific rule. A CAA record lets a domain owner list which certificate authorities may issue certificates for the domain, which narrows the risk of mis-issuance, and if you publish no CAA record any authority may issue. Treat it as background that applies to certificate issuance in general.
Multiple domains and subdomains. Plan for a separate certificate per distinct logo. The verified sources do not confirm that a single VMC extends to subdomains, so do not assume one certificate covers every subdomain until you check with the issuing authority.
Approved jurisdictions. A VMC trademark must come from a recognized IP office. These are the trademark offices for common jurisdictions.
Jurisdiction | Trademark office |
United States | United States Patent and Trademark Office |
Canada | Canadian Intellectual Property Office |
European Union | European Union Intellectual Property Office |
United Kingdom | UK Intellectual Property Office |
Germany | Deutsches Patent- und Markenamt |
Japan | Japan Trademark Office |
Australia | IP Australia |
Spain | Oficina Española de Patentes y Marcas |
South Korea | Korean Intellectual Property Office |
Brazil | National Institute of Industrial Property |
India | Office of the Controller General of Patents, Designs and Trade Marks |
Switzerland | Swiss Federal Institute of Intellectual Property |
Denmark | Danish Patent and Trademark Office |
France | French Patent and Trademark Office (INPI) |
New Zealand | Intellectual Property Office of New Zealand |
Sweden | Swedish Intellectual Property Office (PRV) |
Verification and the roles it needs. The authority runs an identity and control check before issuing, which typically covers employee verification through a higher authority or HR, an identity check such as a video call with a government ID, and domain validation by adding a TXT record to your DNS zone. Three roles carry the process.
- The authorization contact grants the authority permission to issue certificates for the organization and confirms consent by email.
- The contract signer accepts the subscriber agreement for the organization, and this can be the same person as the authorization contact.
- The higher authority, also called independent confirmation, confirms that the authorization contact and contract signer work for the organization and are authorized to act.
How do you switch, renew, or change a certificate?
Your certificate choice is not permanent, and a few transitions are common.
Renewal and expiry. A VMC or CMC is valid for about one year, up to a maximum of 397 days, so renew before it lapses or the logo stops showing. A routine renewal with no logo change reuses your existing logo and certificate URLs.
Changing the logo. The logo is bound to the certificate, so a new logo needs a new certificate, not just a record edit. Validate the new SVG against the BIMI profile, obtain the new certificate for the new mark, host the new file over HTTPS, update the l= and a= URLs in your DNS record, allow DNS propagation, then send test messages. Replacing a certificate-bound logo without a matching new certificate breaks the binding and the logo stops showing.
Revocation. A VMC depends on the underlying trademark. If the trademark lapses or is successfully challenged, the certificate authority can revoke the VMC, and the logo stops showing until you resolve the registration. Keep the trademark in good standing to keep the VMC valid.
Upgrading from a CMC to a VMC. Once your trademark registers, apply for a VMC and update your BIMI record to point at the new certificate. This is the common path, which is to capture inbox branding now with a CMC and move to a VMC for the checkmark and wider support later.
Holding both certificates. You can own both a CMC and a VMC, but only one is active for a given sending domain at a time, because your BIMI record points at a single certificate. Publishing a CMC-based record replaces the VMC display and removes the Gmail checkmark. BIMI selectors can serve different logos for different mail streams, though provider support for selectors is still limited, so most senders use one logo and certificate per domain.
Multiple domains. Plan for a separate certificate per distinct logo, as covered under the application-evidence section above.
What is your next BIMI certificate step?
The clearest next step is to check your BIMI readiness, which tests your domain and shows what is still missing before you apply.
From there, the path depends on what you need next.
- If you want the full picture of how BIMI works, read the complete BIMI implementation guide.
- If you need a compliant logo file, create a BIMI-compatible SVG logo.
- If you would rather have it set up and managed for you, get help with BIMI certificates.
Sources
Primary sources for the standards, provider, and certificate-authority facts on this page. All accessed 2026-07-30.
- BIMI Group — Implementation Guide
- BIMI Group — Creating a BIMI SVG logo
- BIMI Group — FAQs for Senders and ESPs
- BIMI Group — Participating providers
- Google Workspace — Set up BIMI
- Yahoo Sender Hub — BIMI
- Apple — Support BIMI in Apple Mail
- Fastmail — Using BIMI
- DigiCert — Verified Mark Certificates
- DigiCert — BIMI setup guide (VMC and CMC)
- SSL.com — Common Mark Certificate
Current BIMI certificate authorities are DigiCert, Sectigo, GlobalSign, and SSL.com.




