Email Marketing

BIMI, VMC and a Verified Logo in the Inbox: What They Are

Rafal ChojnackiBy Rafal Chojnacki8 min

BIMI (Brand Indicators for Message Identification) is a standard that lets a supporting mailbox provider display an organisation's logo beside an authenticated message. It requires an enforced DMARC policy, a compliant SVG logo and a DNS record. Gmail also requires a VMC (Verified Mark Certificate) or CMC (Common Mark Certificate) for a certified logo. Both can enable the logo, but only a VMC receives Gmail's blue verification checkmark.

BIMI, VMC and a Verified Logo in the Inbox: What They Are

TL;DR

  • BIMI lets a participating mailbox provider display a logo beside authenticated messages. The provider retains discretion over whether it appears.
  • DMARC must be enforced with p=quarantine or p=reject and pct=100; messages must pass DMARC.
  • A VMC (Verified Mark Certificate) unlocks the blue verified checkmark in Gmail and requires a registered trademark.
  • A CMC can verify certain logos without trademark registration, usually through documented prior use. Gmail displays the logo without a blue checkmark.
  • Validity Certified Sender is a separate, paid reputation programme — not the same as BIMI/VMC.
  • BIMI does not guarantee inbox placement or higher open rates. It is a brand-identification layer built on authenticated email.

What BIMI actually does

BIMI publishes the location and certification of a logo associated with the sender's domain. A mailbox provider may use that information as the message avatar. Gmail can also show a blue checkmark for a valid VMC; a CMC can display the logo without that checkmark.

Diagram illustrating what BIMI actually does.

BIMI is not a standalone security control and does not prove that every message's content is safe. It builds on domain authentication and, with a VMC or CMC, third-party validation of the logo. That makes it materially different from a manually selected profile image.

The requirements, in order

Requirement What it means Why it's needed
DMARC at enforcement p=quarantine or p=reject, with pct=100, including the relevant organisational domain and subdomains Restricts unauthenticated use of the domain
BIMI DNS record A TXT record pointing to your logo file Tells inboxes where to find the logo
Logo in SVG (SVG Tiny P/S) A specific, square, simplified SVG format The only format BIMI accepts
VMC or CMC A mark certificate and publicly accessible PEM file Required by Gmail for a certified logo; only a VMC gets the checkmark

The order matters. First authenticate every legitimate source with SPF, DKIM and DMARC, verify alignment, then move safely to enforcement. BIMI Group does not accept p=none or a pct value below 100. Next prepare the SVG, certificate and default._bimi DNS record, using l= for the logo URL and a= for the certificate URL. See the email authentication guide for the foundation.

VMC vs CMC vs Validity — clearing up the terms

These get confused, so here's the distinction:

  • VMC (Verified Mark Certificate) — a certificate authority verifies the organisation, domain and an eligible registered trademark or government mark. Gmail can then show the logo and blue checkmark. A pending trademark application is not enough.
  • CMC (Common Mark Certificate) — the mark does not have to be a registered trademark. For a Prior Use Mark, the authority must verify that a matching logo appears on a website controlled by the applicant and appeared there at least 12 months earlier. CMCs can also cover defined modifications of registered marks. Gmail shows the logo without the blue checkmark.
  • Validity Certified Sender (formerly Return Path Certification) — a separate, paid reputation programme where a third party vouches for your sending practices to participating mailbox providers. It's about reputation and inbox placement, not the logo — often confused with BIMI/VMC but a different thing entirely.

Use a VMC when the logo has eligible registration and the Gmail checkmark matters. A CMC broadens access to a certified logo but does not provide that checkmark. Validity's programme concerns a separate part of email operations and does not replace either certificate.

Glossary

  • BIMI — standard that displays a verified brand logo next to emails.
  • VMC — Verified Mark Certificate; binds a logo to a registered trademark; unlocks Gmail's checkmark.
  • CMC — Common Mark Certificate; available for a Prior Use Mark or a defined Modified Registered Mark.
  • SVG Tiny P/S — the specific SVG format BIMI logos must use.
  • Validity Certified Sender — a paid third-party reputation/certification programme (not BIMI).
  • Enforcement — DMARC at quarantine or reject, a BIMI prerequisite.

Is it worth it?

BIMI's business case depends on the share of active recipients using supporting mailbox providers, the value of the email programme, logo recognition and the cost of DMARC remediation, trademark work and certification. No credible universal open-rate lift should be promised, and privacy features make open rate an imperfect outcome measure.

Start by checking whether the domain can move safely to DMARC enforcement and whether supported providers represent a meaningful audience share. A CMC can be practical when the logo qualifies through prior use. A VMC offers more visual value in Gmail because it is the only one of the two that receives the checkmark.

How Space Ads approaches BIMI

At Space Ads, the work starts with an inventory of every legitimate sending source and the DMARC reports. Once those systems authenticate correctly, the domain can move safely to pct=100 and a quarantine or reject policy. We then assess the mark: an eligible registered trademark points to a VMC and Gmail checkmark, while documented prior use may support a CMC without the checkmark. Finally, we validate the SVG Tiny P/S file, PEM chain, DNS record and provider-specific display.

BIMI remains a brand-identification feature rather than a deliverability repair. It builds on the authentication setup and deliverability foundation. Ongoing email marketing still requires reputation, complaint, list-quality and content controls.

Stop doing / Do instead

Stop doing Do instead
Trying to enable BIMI at p=none Move DMARC to enforcement first
Confusing VMC with Validity Certified Know: VMC = logo/checkmark; Validity = reputation programme
Assuming a CMC receives Gmail's checkmark Remember: CMC shows a logo; VMC shows a logo and checkmark
Assuming any unregistered logo qualifies Document the required prior use for a CMC
Uploading any logo format Use the required SVG Tiny P/S format
Treating BIMI as a foundation Treat it as the capstone after authentication

Common mistakes

Common errors include using p=none, leaving pct below 100, publishing an invalid SVG, serving an incomplete PEM chain and confusing a CMC with a VMC. A technically valid record also does not guarantee display: each mailbox provider applies its own acceptance and reputation criteria.

Diagram illustrating stop doing / Do instead.

FAQ

What is BIMI?

BIMI lets participating mailbox providers display a logo beside authenticated messages. It requires enforced DMARC and a compliant SVG. Gmail requires a VMC or CMC for a certified logo, but displays the blue verification checkmark only for a VMC.

What is a VMC (Verified Mark Certificate)?

A VMC is issued after a certificate authority verifies the organisation, domain and an eligible registered trademark or government mark. It can enable the logo and blue checkmark in Gmail. A pending trademark application does not meet the registered-mark requirement.

What's the difference between VMC and CMC?

A VMC uses an eligible registered or government mark and can receive Gmail's blue checkmark. A CMC can use a Prior Use Mark or defined Modified Registered Mark, but Gmail shows its logo without the checkmark. Prior Use validation includes evidence that the matching logo appeared on a controlled domain at least 12 months earlier.

Is BIMI the same as Validity certification?

No. BIMI with a VMC or CMC concerns a certified logo. Validity Certified Sender is a separate programme concerning sender practices and reputation with participating providers. Participation in one does not replace the requirements of the other.

Does BIMI improve deliverability?

Not directly. BIMI does not move mail from spam to the primary inbox. It does require mature DMARC enforcement, which helps prevent domain spoofing. Reputation, complaints, list quality, content and each provider's filtering decisions still affect placement.

Is BIMI worth setting up?

Consider it when the domain already authenticates correctly, the logo is recognisable and supporting mailbox providers represent a meaningful share of active recipients. Compare certification and implementation costs with the value of consistent identity. Do not assume a fixed open-rate lift.

Key takeaways

  • BIMI shows your verified logo beside emails; a VMC adds Gmail's blue checkmark.
  • It requires enforced DMARC with pct=100, a compliant SVG and a BIMI DNS record.
  • A VMC uses an eligible registered mark and can receive Gmail's checkmark.
  • A CMC can use documented prior use, but Gmail displays it without the blue checkmark.
  • Validity Certified Sender is a separate reputation programme, not BIMI.
  • Worth it for established brands; premature before authentication is enforced.

Sources and further reading

Continue learning

Continue reading

Success Stories

The same operating standard, across different models