Digital content

Logo and blue check in Gmail

how BIMI helps confirm brand authenticity in corporate communications

Інна Возняк Інна Возняк September 22, 2026
Logo and blue check in Gmail

Logo and blue check in Gmail: how BIMI helps confirm brand authenticity in corporate communications 


A phishing email today can almost completely copy the communication of a well-known brand - from the sender name to the design and content of the message.


Therefore, for companies that actively communicate with clients via email, the issue of protecting the brand’s digital identity goes far beyond trademark registration.


In this article, we examine BIMI and the VMC/CMC certificates: how to confirm the link between the brand, the corporate domain and the logo, obtain logo display next to emails and, in the case of VMC, a verified checkmark in Gmail. We separately explain what companies without a registered trademark should do regarding a logo, when CMC may be appropriate, and what the entire process looks like, from verifying brand rights and DMARC to obtaining a certificate and configuring BIMI.

To counter sender spoofing and phishing, a multi-layered email authentication system has been developed, which includes SPF, DKIM and DMARC. The next level of such a system is BIMI (Brand Indicators for Message Identification) — a standard that allows an authenticated mail domain to be linked with a brand logo and displays that logo next to email messages in mail services that support BIMI.


To confirm the link between the domain, the organization and the logo, two types of digital certificates are used, in particular:


- VMC — Verified Mark Certificate;

- CMC — Common Mark Certificate.


Obtaining such a certificate is not limited to uploading a logo to Gmail or another mail service. It is a procedure consisting of verifying the mail domain, configuring DMARC, preparing the logo, confirming rights or long-term use of the mark, verifying the applicant, obtaining the certificate and publishing the BIMI record in DNS.


1. How BIMI works


BIMI functions on top of the existing email authentication mechanisms.


SPF


SPF (Sender Policy Framework) allows the domain owner to define the servers and other systems that are permitted to send emails on its behalf.


DKIM


DKIM (DomainKeys Identified Mail) adds a cryptographic signature to the message, by means of which the mail server can verify its origin and integrity.


DMARC


DMARC (Domain-based Message Authentication, Reporting and Conformance) establishes a policy for messages that do not pass proper authentication.


For BIMI, it is not sufficient to have DMARC with a monitoring policy `p=none`.


The policy must be set to: `p=quarantine` or `p=reject`.


It must also apply to 100% of messages. A `pct` value below 100 does not meet BIMI requirements.


Google’s official step-by-step instructions for configuring BIMI are available on the website.


 2. What CMC is


Common Mark Certificate (CMC) is a digital certificate that allows a logo to be verified for use in BIMI without the mandatory existence of a registered trademark. This does not mean that any newly created logo may be used for CMC.


For example, DigiCert allows CMC for a Prior Use Mark — an unregistered mark that has been used for at least 12 months prior to the verification date. Such use must take place on a domain controlled by the applicant. To verify the history of logo use, DigiCert may use the web archive Archive.org.


Accordingly, the classic CMC scenario looks as follows:


no registered trademark for the logo → the logo has been used for 12+ months → use can be confirmed → CMC eligibility can be assessed.


CMC may also be applied in other cases provided for by a specific provider, for example in relation to a modified version of a registered mark.


3. What VMC is


Verified Mark Certificate (VMC) is a certificate that provides a more formal confirmation of the logo.


For a standard VMC, the logo must be registered as a trademark with an intellectual property office recognized by the relevant certificate provider.


Importantly, it is not merely the fact that the company has any trademark that is verified.


What matters is the correspondence of the specific logo that will be used in BIMI to the relevant registered mark.


Therefore, a situation where a company has registered only the word mark of the brand but uses a separate graphic logo requires separate verification.


VMC has another important distinction: in Gmail, it is VMC that can provide the blue verified sender badge. CMC does not provide such a badge.


4. CMC or VMC: which to choose


Option 1. The logo is registered as a trademark.


The possibility of obtaining a VMC is assessed.


It is necessary to establish:


- who owns the trademark;

- in which country or through which office it is registered;

- whether the selected VMC provider recognizes this registration;

- whether the registered image corresponds to the current logo.


Option 2. The logo is not registered as a trademark, but has been used for more than 12 months.


The possibility of obtaining a CMC is assessed.


Option 3. The logo is not registered and has been used for less than 12 months.


The standard route through CMC on the basis of prior use is currently not suitable. It is necessary either to wait for the required period of use or to analyze the possibility of registering the logo as a trademark for subsequent VMC.


 5. Who issues CMC and VMC


Certificates are issued by Mark Verifying Authorities (MVA) — specialized certification authorities.


As of today, the BIMI Group publishes information, in particular, about the following providers:


- DigiCert;

- GlobalSign;

- SSL.com.


The current list should be checked immediately before submitting an application on the BIMI Group Mark Certificate Issuer Information page.


Inclusion of a certification authority in this list does not in itself mean that its certificate will be accepted by absolutely every mail service. Each mailbox provider independently determines which MVA certificates it accepts.


6. What needs to be prepared before starting the procedure


Before purchasing a CMC/VMC, it is advisable to collect at least the following:


1. the applicant’s full legal name;

2. the company’s registration details;

3. the corporate domain;

4. access to DNS or the contact details of the person who can change DNS records;

5. a list of all services that send mail on behalf of the domain;

6. information about SPF, DKIM and DMARC;

7. the current logo in vector format;

8. for VMC — information about the trademark;

9. for CMC — evidence of logo use for the required period;

10. the details of the company’s authorized representative;

11. documents to confirm his or her identity, if requested by the certification authority.


After that, technical verification may begin.


7. How much it costs


The BIMI standard itself does not provide for a state fee for creating a DNS record.


The main external costs arise from CMC/VMC and, if necessary, trademark registration, technical mail configuration or SVG preparation.


For example, according to DigiCert’s published pricing, the cost is:


CMC — $1,416 for a 12-month subscription;


VMC — $1,752 for a 12-month subscription.


Prices may change, so before purchasing it is necessary to check the current rate directly on the provider’s page


8. How long the procedure takes


If the domain is already configured correctly, DMARC is in enforcement, the logo is prepared, and rights to it can be easily confirmed, the main stage remains validation by the certification authority.


However, if DMARC is still set to `p=none`, third-party mailing systems have not been checked, there is no proper SVG, or there are issues with the trademark, the main time is spent on preparation itself.


It should also be taken into account that if a trademark must first be registered for VMC, the trademark registration period becomes a separate and potentially the longest stage.


9. Does CMC/VMC guarantee that emails will not end up in spam


No. CMC and VMC are not anti-spam certificates.


Email deliverability is affected by the reputation of the domain and IP address, SPF/DKIM/DMARC results, sending history, recipient complaints, the quality of the address list, the content of the emails and the internal algorithms of the mail provider. Therefore, the statement “after obtaining VMC, emails do not end up in spam” is technically incorrect.


The function of CMC/VMC is different — to confirm the link between the organization, the domain and the logo for the use of that logo in BIMI.


10. Will the logo be displayed in all mail clients


Also no.


Each mailbox provider independently determines:


- whether it supports BIMI;

- which Mark Certificates it recognizes;

- where exactly it displays the logo;

- which additional criteria it applies to the sender.


Conclusion


CMC and VMC are not merely “certificates for a logo.” They are one of the final elements of the authentication and brand confirmation system in email.


VMC is used primarily when the logo has proper formal registration as a trademark, whereas CMC allows, under certain conditions, the use of a logo without such registration, including on the basis of verified prior use.


The practical process consists of three interrelated parts: configuring a secure mail infrastructure, confirming the brand and technically implementing BIMI. Therefore, before purchasing a certificate, it is advisable first to verify the readiness of the domain and logo.

Інна Возняк
Інна Возняк

Помічник юриста юридичної агенції «Digilaw»

Need a consultation
15 min intro call