VMC vs CMC: Which BIMI certificate is right for your brand?

Published on:January 23, 2026
Last Modified on:August 5, 2026
8 Min Read
Table of contents

Should you choose a VMC or a CMC?

Choose a Verified Mark Certificate (VMC) if you hold a registered trademark and you want the widest current provider support, including the Gmail verified checkmark and logo display in Apple Mail. Choose a Common Mark Certificate (CMC) if you do not hold a registered trademark but have displayed your logo publicly on a domain you own for at least 12 months. Gmail shows a CMC logo without the verified checkmark.

Your situation

Better fit

Why

You hold a registered trademark

VMC

A VMC gives the widest support. It is the only certificate that gets the Gmail verified checkmark, and Apple documents a VMC for Apple Mail on macOS 13, iOS 16, and iPadOS 16 and later.

You have no registered trademark, but your logo has been public on a domain you own for 12 or more months

CMC

A CMC verifies prior use instead of a trademark, and Gmail shows a CMC logo without the checkmark.

Your trademark application is in progress

CMC now, VMC later

A CMC gets your logo into supporting inboxes now, and you move to a VMC once the trademark registers.

Cost and logo-modification flexibility usually favor a CMC, but they rarely outweigh trademark status. If you hold a trademark and want the checkmark or Apple Mail, a VMC is still the better fit. Government entities use a Government Mark Certificate (GMC), verified through official government records.

Both certificates need the same foundation, which is DMARC at enforcement plus a compliant logo file, and both bind your logo to a certificate that a mailbox provider reads before it shows the logo. They differ in the eligibility you must prove, the providers that display them, and the flexibility you have with the logo artwork.

Gmail shows these logos now, Yahoo shows them for senders with a good sending reputation, and Apple documents support for Apple Mail, so a correctly issued certificate shows your logo across the major inboxes. Issuers and provider rules do change, so check the sources and the last-reviewed date on this page before you apply.

Not sure where your domain stands? Check your BIMI readiness to see what it still needs.

Check your BIMI readiness

Are you eligible for a VMC, CMC, or GMC?

Each certificate is a Mark Certificate, a digital certificate issued by a certificate authority that ties your logo to the domain authorized to send your email, and it acts as the evidence document a BIMI record points to. The type you qualify for depends on the evidence you can show.

  • VMC. You need a logo registered as a trademark with a recognized intellectual-property office. The certificate authority verifies the registration with the relevant trademark office or the WIPO Global Brand Database.
  • CMC. You need no trademark. Instead you show common-law prior use, a logo displayed publicly on a domain you own for at least 12 months, which the certificate authority verifies through website history, archive.org, or marketing materials. The authority also confirms no other organization holds a trademark on the logo.
  • GMC. A Government Mark Certificate exists for government entities, verified through official government records.

A CMC still blocks lookalike senders even without a trademark, because the authority runs prior-use due diligence on the logo, confirms you control the sending domain and pass DMARC at enforcement, and vets that the applicant is authorized to act for your organization.

How do VMC and CMC requirements compare?

This is the single comparison table for the two certificates. Every row is self-contained, and the volatile rows carry a primary source and a review date.

Factor

VMC

CMC

Primary source

Last reviewed

Eligibility basis

A logo registered as a trademark with a recognized IP office

A logo shown publicly on a domain you own for at least 12 months, no trademark needed

DigiCert; SSL.com

2026-07-30

Accepted mark evidence

The authority verifies the registration with the trademark office or the WIPO Global Brand Database

The authority verifies 12 months of public use through website history, archive.org, or marketing materials

DigiCert; SSL.com

2026-07-30

Provider-dependent display

Gmail shows the logo and its verified checkmark, and Apple documents a VMC for Apple Mail

Gmail shows the logo without the checkmark, and whether Apple accepts a CMC is not confirmed

Google Workspace; Apple

2026-07-30

Logo modification rules

The displayed logo must match the registered trademark

More flexibility to use a logo without a registered trademark, so you are not tied to a registered design

DigiCert; SSL.com

2026-07-30

Application evidence

DMARC at enforcement, a compliant SVG P/S logo, trademark proof, and CA identity and domain-control verification

DMARC at enforcement, a compliant SVG P/S logo, 12-month public-use proof, and CA identity and domain-control verification

BIMI Group

2026-07-30

Transition constraints

You can hold both a VMC and a CMC, but only one certificate is active per sending domain at a time

You can upgrade to a VMC once a trademark registers

DigiCert

2026-07-30

Cost and timing variables

Cost and issuance time vary by authority and by whether the trademark is already registered

Cost and issuance time vary by authority

DigiCert

2026-07-30

Both certificate types are valid for about one year, up to a maximum of 397 days, and need annual renewal to keep the logo showing. Both are issued by the same set of authorities, listed in the Sources section.

How does mailbox-provider support change your choice?

Provider support is the practical tie-breaker, because a certificate only helps where the provider displays it. Support and conditions vary by provider, so match your choice to the mailboxes your recipients actually use.

Provider

VMC

CMC

Display surface and caveat

Primary source

Last reviewed

Gmail and Google Workspace

Shows the logo and the verified checkmark

Shows the logo without the checkmark

Web and mobile apps, self-asserted records not shown

Google Workspace

2026-07-30

Yahoo and AOL

Factored if present, not required

Accepted, gated on reputation

Mobile message list and read view in the Yahoo and AOL apps, desktop read view in webmail, no checkmark distinction

Yahoo

2026-07-30

Apple Mail

Documented, with other BIMI evidence documents

Not confirmed

macOS 13, iOS 16, and iPadOS 16 and later, provider must be on the BIMI Group list and Apple-verified with valid evidence and vouching headers

Apple

2026-07-30

Fastmail

Optional

Optional

Conditional display, needs DMARC at enforcement, and Fastmail does not fetch external servers at view time

Fastmail

2026-07-30

Microsoft Outlook

Not displayed

Not displayed

Outlook, Outlook.com, Exchange Online, and Microsoft 365 do not render inbound BIMI as of 2026, with no announced date

BIMI Group

2026-07-30

The Gmail verified checkmark is the clearest split. It appears for a VMC only, and a CMC shows the same logo without it, so the checkmark is a reason to prefer a VMC when it matters to your audience and not a reason to expect different logo placement. Apple Business Connect is a separate Apple program from BIMI, so enrolling in Business Connect is not the same as publishing a BIMI record.

If your question is general logo troubleshooting rather than certificate choice, the complete BIMI implementation guide covers why a logo does not appear.

What evidence does a certificate application require?

Both certificates share the same technical prerequisites and differ only in how the authority verifies your logo.

  • DMARC at enforcement. Your domain needs a DMARC policy of p=quarantine or p=reject applied to all mail. A monitor-only policy of p=none does not qualify.
  • A compliant SVG logo. The file must meet the SVG Portable/Secure (SVG P/S) profile, a profile of SVG Tiny 1.2, with a square aspect ratio, a solid background, a required <title> element, and a size at or under 32 KB. If you need to produce one, create a BIMI-compatible SVG logo.
  • A published BIMI record. A DNS TXT record that points to the logo file and the certificate.

For a VMC the authority verifies the trademark registration with the trademark office or the WIPO Global Brand Database, and if you are not the direct trademark owner you supply an authorization letter from the mark owner. For a CMC the authority verifies 12 months of public logo use through website history, archive.org, or marketing materials, and confirms no conflicting trademark.

Certification Authority Authorization (CAA). CAA is a general public-key-infrastructure control, not a BIMI-specific rule. A CAA record lets a domain owner list which certificate authorities may issue certificates for the domain, which narrows the risk of mis-issuance, and if you publish no CAA record any authority may issue. Treat it as background that applies to certificate issuance in general.

Multiple domains and subdomains. Plan for a separate certificate per distinct logo. The verified sources do not confirm that a single VMC extends to subdomains, so do not assume one certificate covers every subdomain until you check with the issuing authority.

Approved jurisdictions. A VMC trademark must come from a recognized IP office. These are the trademark offices for common jurisdictions.

Jurisdiction

Trademark office

United States

United States Patent and Trademark Office

Canada

Canadian Intellectual Property Office

European Union

European Union Intellectual Property Office

United Kingdom

UK Intellectual Property Office

Germany

Deutsches Patent- und Markenamt

Japan

Japan Trademark Office

Australia

IP Australia

Spain

Oficina Española de Patentes y Marcas

South Korea

Korean Intellectual Property Office

Brazil

National Institute of Industrial Property

India

Office of the Controller General of Patents, Designs and Trade Marks

Switzerland

Swiss Federal Institute of Intellectual Property

Denmark

Danish Patent and Trademark Office

France

French Patent and Trademark Office (INPI)

New Zealand

Intellectual Property Office of New Zealand

Sweden

Swedish Intellectual Property Office (PRV)

Verification and the roles it needs. The authority runs an identity and control check before issuing, which typically covers employee verification through a higher authority or HR, an identity check such as a video call with a government ID, and domain validation by adding a TXT record to your DNS zone. Three roles carry the process.

  • The authorization contact grants the authority permission to issue certificates for the organization and confirms consent by email.
  • The contract signer accepts the subscriber agreement for the organization, and this can be the same person as the authorization contact.
  • The higher authority, also called independent confirmation, confirms that the authorization contact and contract signer work for the organization and are authorized to act.

How do you switch, renew, or change a certificate?

Your certificate choice is not permanent, and a few transitions are common.

Renewal and expiry. A VMC or CMC is valid for about one year, up to a maximum of 397 days, so renew before it lapses or the logo stops showing. A routine renewal with no logo change reuses your existing logo and certificate URLs.

Changing the logo. The logo is bound to the certificate, so a new logo needs a new certificate, not just a record edit. Validate the new SVG against the BIMI profile, obtain the new certificate for the new mark, host the new file over HTTPS, update the l= and a= URLs in your DNS record, allow DNS propagation, then send test messages. Replacing a certificate-bound logo without a matching new certificate breaks the binding and the logo stops showing.

Revocation. A VMC depends on the underlying trademark. If the trademark lapses or is successfully challenged, the certificate authority can revoke the VMC, and the logo stops showing until you resolve the registration. Keep the trademark in good standing to keep the VMC valid.

Upgrading from a CMC to a VMC. Once your trademark registers, apply for a VMC and update your BIMI record to point at the new certificate. This is the common path, which is to capture inbox branding now with a CMC and move to a VMC for the checkmark and wider support later.

Holding both certificates. You can own both a CMC and a VMC, but only one is active for a given sending domain at a time, because your BIMI record points at a single certificate. Publishing a CMC-based record replaces the VMC display and removes the Gmail checkmark. BIMI selectors can serve different logos for different mail streams, though provider support for selectors is still limited, so most senders use one logo and certificate per domain.

Multiple domains. Plan for a separate certificate per distinct logo, as covered under the application-evidence section above.

What is your next BIMI certificate step?

The clearest next step is to check your BIMI readiness, which tests your domain and shows what is still missing before you apply.

From there, the path depends on what you need next.

Sources

Primary sources for the standards, provider, and certificate-authority facts on this page. All accessed 2026-07-30.

Current BIMI certificate authorities are DigiCert, Sectigo, GlobalSign, and SSL.com.

Frequently asked questions

Do I need a trademark to use BIMI?

Not necessarily. A Common Mark Certificate (CMC) uses 12 months of public logo use instead of a trademark, while a Verified Mark Certificate (VMC) requires a registered trademark.

Can I upgrade from a CMC to a VMC later?

Yes. Once your trademark registers, apply for a VMC and update your BIMI record to point at the new certificate.

Does a CMC get the Gmail blue checkmark?

No. The verified checkmark is issued for a VMC only, and a CMC shows the same logo without it.

Which certificate authorities issue VMCs and CMCs?

DigiCert, Sectigo, GlobalSign, and SSL.com. Entrust stopped issuing mark certificates in 2025, so it is no longer an option.