Skip to content
← Blog

The VMC certificate for BIMI: price, requirements and how to get one

By Thomas · virtual CISO · August 13, 2026

The domain is at p=reject, the logo is compliant, the BIMI record is published — and yet, in Gmail, no logo appears. The reason is almost always the same: the VMC is missing. For the major mailbox providers to display a logo, a BIMI record is not enough; a certificate proving that the logo really belongs to the sender is also required. This article explains what a VMC is, why it is required, what it truly costs, and how to obtain one.

What a VMC is

A VMC (Verified Mark Certificate) is a digital certificate that cryptographically binds a logo to a registered trademark. It is issued by a small number of authorised certificate authorities — chiefly DigiCert and Entrust — after verification of the holder's rights to the mark.

Concretely, the VMC is the file the a= tag of a BIMI record points to. When a provider receives an authenticated email from the domain, it does not just fetch the logo: it verifies the certificate, ensures it is valid and matches the published logo. It is that verification which authorises display.

Why providers require it

The reason is the same one underpinning DMARC itself: preventing impersonation. Without a certificate, anyone could publish a BIMI record pointing to a well-known brand's logo and, provided they enforce DMARC on their own domain, display that stolen logo. The VMC closes that door: it attests that the organisation publishing the logo actually holds the rights to the corresponding trademark.

In other words, the VMC protects the logo as DMARC protects the domain. That is why Gmail and the other large inboxes make it a condition: displaying an unverified logo would turn BIMI into a new fraud vector instead of a trust signal. The consistency is total — the whole edifice rests on verifiable proof, from the domain to the trademark.

The hard requirement: a registered trademark

This is the obstacle that surprises most organisations: a VMC requires a registered trademark. Not a logo used for years, not a brand guideline: a figurative mark (or the logo itself) officially registered with a competent office — the USPTO in the United States, the EUIPO for the European Union, the INPI in France, depending on the territory covered.

Where the mark is already registered, the key piece is in hand. Where it is not, registration comes first — a process with its own cost and, above all, its own lead time: several months between filing and final registration, during which the VMC cannot be issued. This is the most underestimated factor in a BIMI project: the certificate itself takes days to obtain, but the trademark that conditions it can take months.

The real cost

Two line items must be distinguished:

  • The VMC certificate: on the order of $1,000–$1,500 per year (renewable), depending on the authority. It is a subscription, not a one-time purchase.
  • The trademark registration, where none exists yet: office fees varying by number of classes and territory, plus possibly IP-counsel fees. To budget separately, and upfront.

Set against the benefit — a brand signal displayed across a majority share of consumer inboxes — this cost is modest for a financial brand, an established e-commerce merchant or a large sender. It is less so for a small organisation with no registered trademark, for whom the no-certificate alternative is worth weighing: BIMI without VMC, is it possible.

The process of obtaining one

Once the trademark is registered and the domain is at DMARC enforcement, obtaining the VMC follows marked steps:

  1. Preparing the compliant logo in SVG Tiny PS format, square, matching exactly the registered trademark (the certificate's logo must match the registered mark).
  2. Choosing an authorised authority (DigiCert, Entrust) and submitting the request, with proof of trademark registration.
  3. Passing validation: the authority verifies the rights to the mark and the organisation's identity. It is a serious check, comparable to an extended-validation certificate.
  4. Receiving the certificate (PEM file) and hosting it over HTTPS.
  5. Publishing the default._bimi record with the a= tag pointing to the VMC, alongside the l= pointing to the logo.

The full mechanics of the record and logo format are detailed in the pillar article, showing a BIMI logo in Gmail.

VMC or CMC?

A word on an increasingly visible alternative: the CMC (Common Mark Certificate). Where the VMC requires a registered trademark, the CMC addresses logos that cannot get one — unregistered marks, government-entity logos, marks too old for classic registration. The CMC is generally cheaper, but it is not accepted everywhere: notably, Gmail relies on the VMC, while Apple Mail accepts the CMC. The choice therefore depends on the inboxes being targeted. That trade-off is developed in BIMI without VMC.

How long it really takes

A VMC project's timeline is dominated by a factor often ignored: the trademark. Broken down:

  • Trademark registration (where none exists): several months between filing and final registration, depending on the office and any oppositions. It is the longest item, by far.
  • DMARC enforcement: a few weeks to a few months to cleanly bring the domain from p=none to p=reject, depending on the size of the sending estate.
  • The certificate itself: once mark and domain are ready, issuing the VMC takes days to a few weeks, the time for the authority's validation.

The classic trap is to treat the VMC as a last-minute checkbox, then discover that a trademark has to be registered first — and wait. Where the verified logo is a goal, the trademark filing starts early, in parallel with the DMARC work, not after.

The logo must match the registered mark

A point that regularly blocks requests: the logo published via BIMI must match the trademark as registered. Registering one logo then publishing a substantially different variant does not work; the authority checks the correspondence. In practice, this means aligning three elements upfront: the registered figurative mark, the SVG Tiny PS file prepared for BIMI, and the logo's actual use. A divergence — colours, proportions, added elements — can fail validation or delay issuance. Better to freeze the logo before the trademark filing, so the three coincide.

Renewal and lifecycle

The VMC is not a one-time purchase: it is a time-limited certificate, to be renewed periodically (typically each year). On expiry, if renewal has not been done, providers stop displaying the logo — exactly as an expired TLS certificate breaks a site's padlock. The VMC is an asset to maintain, with a renewal alert, on a par with every other certificate in the estate. A logo that vanishes overnight is almost always a forgotten VMC.

Who can issue a VMC

The number of authorities allowed to issue VMCs is deliberately small — to date, essentially DigiCert and Entrust. This is not an open market like TLS certificates: verifying trademark rights requires an authority accredited by the BIMI ecosystem. The choice between these issuers turns on price, validation process and geography; the resulting certificate is then recognised by every provider that requires a VMC.

The validation these authorities run is no formality: it verifies the organisation's legal existence, its rights to the mark and the logo's correspondence, in a process close to an extended-validation certificate. It is deliberately long and demanding — that rigour is exactly what gives the displayed logo its value, since a VMC that were easy to obtain would be worthless as a trust signal. Even before an issuer is contacted, the documents that will be requested are worth gathering: proof of trademark registration, evidence of the organisation's legal identity, and the finalised SVG Tiny PS logo that matches the mark. Having these ready turns a weeks-long back-and-forth into a short exchange — the single most effective lever for shortening the VMC timeline once the trademark itself is secured.

Is it worth it?

For whom is the VMC a good investment? Typically, organisations for whom the brand is the asset: banks and insurers, e-commerce merchants, large consumer brands, heavily-spoofed services. For them, the verified logo protects brand recognition and widens the gap with fraud — the natural extension of the reasoning in the dossier on the banking sector. For a small organisation with no consumer-facing brand and no registered trademark, by contrast, the honest answer may be "not yet": the cost and the trademark requirement outweigh a logo few recipients would even notice. The decision is genuinely case-by-case, and tying it to who the recipients are — and which inboxes they use — keeps it grounded.

But the order matters: the VMC is useless until the domain is enforcing. Before a certificate is budgeted, the step that unlocks everything has to be cleared — it is described in getting to p=reject.

The DMARC foundation comes first

No point incurring certificate costs while the domain is not ready. A pass through our free DMARC analyzer settles it: below p=quarantine or p=reject, no logo will show, VMC or not. The brand also has its place in the DMARC Observatory.

Bringing a domain to enforcement and then preparing the ground for BIMI and the VMC is precisely what Thomas, the virtual CISO, orchestrates: he takes a domain to p=reject without breaking legitimate mail, the step without which the certificate would be dead weight. Free DMARC analysis of a domain · the DMARC Observatory · getting started with Thomas.

Related guides

About the author

ThomasThomas is the virtual CISO of DMARC.com: a copilot specialized in email authentication that walks organizations from p=none to p=reject without breaking their mail. His guides draw on real data from the DMARC Observatory and the RUA reports the platform analyzes.