How do you get a verified mark certificate for BIMI?

Official certification seal pressed into cream paper beside a white envelope on a walnut desk, with a wax stamp tool and warm golden light.

To get a verified mark certificate (VMC) for BIMI, you need to obtain one from an authorized certificate authority, complete trademark verification for your logo, and install the certificate alongside a valid BIMI record in your DNS. The process requires your logo to be a registered trademark in the relevant jurisdiction and formatted as an SVG Tiny P/S file. Below, we walk through every question you are likely to have along the way.

Who issues verified mark certificates for BIMI?

Verified mark certificates for BIMI are issued by a small group of authorized certificate authorities (CAs) that have been approved to validate trademark ownership and bind it to a logo. As of 2026, the two primary issuers are DigiCert and Entrust. Both organizations operate under the guidelines set by the BIMI Working Group and the Verified Mark Certificate Authority (VMCA) requirements.

These certificate authorities do not just issue a digital credential. They verify that your organization legally owns the trademark associated with the logo you want to display in the inbox. This trademark-to-logo binding is what makes a VMC trustworthy from the perspective of email clients like Gmail and Yahoo Mail, which use the certificate to confirm that the brand logo is legitimate before rendering it next to a message.

Choosing between DigiCert and Entrust largely comes down to your existing vendor relationships, regional preferences, and the support each provider offers during the application process. Both are well-established in the broader digital certificate space and follow the same underlying standards for VMC issuance.

What are the requirements to qualify for a VMC?

To qualify for a verified mark certificate, you must meet three core requirements: your logo must be a registered trademark in a jurisdiction recognized by the issuing certificate authority, your logo must be formatted as an SVG Tiny P/S file, and your email authentication must be fully configured with SPF, DKIM, and DMARC at a policy of at least quarantine or reject.

Here is a breakdown of what each requirement involves:

  • Registered trademark: The logo you submit must correspond to an active trademark registration. Pending applications or common law marks are generally not accepted. The trademark must be registered in a country or region that the certificate authority recognizes, which typically includes the US, EU, UK, Canada, Australia, and several other major markets.
  • SVG Tiny P/S format: Your logo file must conform to the SVG Tiny Portable/Secure profile. This is a restricted subset of SVG that eliminates scripting, external references, and other elements that could introduce security risks. Many standard SVG files will need to be converted or adjusted to meet this specification.
  • DMARC enforcement: A DMARC policy of p=quarantine or p=reject is mandatory. A monitoring-only policy (p=none) will not satisfy the requirement. SPF and DKIM must also be properly aligned for your sending domain.

Some certificate authorities may have additional requirements around organizational verification, so it is worth reviewing the specific documentation from DigiCert or Entrust before beginning the process.

How do you apply for a verified mark certificate step by step?

Applying for a VMC is a multi-step process that combines technical preparation with legal and organizational verification. The high-level path is: prepare your logo, confirm your trademark, set up email authentication, submit your application to a CA, and then install the issued certificate.

  1. Prepare your SVG logo: Convert your logo to SVG Tiny P/S format. Use a tool or service that validates compliance with this profile, since standard SVG editors do not always produce a conformant file automatically.
  2. Verify your trademark status: Confirm that your logo’s trademark registration is active and recognized in a supported jurisdiction. Gather your trademark registration number and documentation, as the CA will need these during verification.
  3. Audit your email authentication: Check that SPF and DKIM are correctly configured for your sending domain and that your DMARC policy is set to quarantine or reject with proper alignment. Any gaps here will block the process.
  4. Submit your application: Go to DigiCert or Entrust and begin the VMC application. You will provide your organization details, trademark registration information, and your SVG logo file. The CA will conduct an organizational validation (OV) check alongside the trademark verification.
  5. Complete validation: The CA will verify your organization and confirm the trademark ownership. This step can take anywhere from a few days to a few weeks, depending on the complexity of your trademark situation and how quickly you respond to any follow-up requests.
  6. Receive and install your VMC: Once issued, you will receive a PEM-encoded certificate file. You then host this file at a publicly accessible URL and reference it in your BIMI DNS record.

How much does a verified mark certificate cost?

The cost of a verified mark certificate varies based on several factors, and there is no single fixed price across the industry. Understanding what drives the cost helps you budget appropriately and avoid surprises.

Key factors that influence the price include:

  • Certificate authority pricing: DigiCert and Entrust each set their own pricing structures. Annual renewal fees are part of the ongoing commitment, not just a one-time cost.
  • Organizational validation complexity: If your organization requires additional verification steps, or if there are complications with your trademark documentation, the process may involve more back-and-forth, which some providers account for in their service tiers.
  • SVG preparation services: If your logo is not already in SVG Tiny P/S format, you may need to pay a designer or use a conversion service to bring it into compliance. This is a separate cost from the certificate itself.
  • Ongoing DMARC and authentication management: While not part of the VMC fee directly, maintaining the authentication infrastructure that BIMI requires carries its own operational costs, especially if you rely on external tools or consultants.

VMCs are generally considered an investment for brands that send at significant volume and want the reputational and engagement benefits that come with logo display in the inbox.

What happens after you install a VMC in your DNS?

After you install a VMC, email clients that support BIMI will begin retrieving your logo and displaying it next to qualifying messages in the inbox. The VMC acts as the authentication layer that tells participating mailbox providers your logo is verified and safe to render without any additional trust signals from the sender.

The technical flow works like this: when an email arrives, the receiving mail server checks your DMARC record, then looks up your BIMI record in DNS. The BIMI record points to both your SVG logo file and your VMC. The mailbox provider validates the certificate against the issuing CA, confirms the trademark binding, and if everything checks out, displays your logo in the inbox.

Not all email clients support BIMI with VMC requirements equally. Gmail and Apple Mail are among the most prominent supporters, but coverage continues to expand. It is worth monitoring which clients your subscribers use most, since logo display will only appear in environments that have implemented BIMI support.

Once live, your VMC needs to be renewed annually. If the certificate expires or your DMARC policy drops below the enforcement threshold, the logo will stop rendering until the issue is resolved.

Does a VMC guarantee inbox placement or better deliverability?

A verified mark certificate does not guarantee inbox placement or directly improve deliverability. A VMC is a trust and branding signal, not a deliverability mechanism. Inbox placement is determined by sender reputation, engagement metrics, list hygiene, and authentication alignment, not by whether a logo appears next to your messages.

That said, BIMI and VMCs can have an indirect positive effect on email performance. When subscribers recognize a verified brand logo in the inbox, they are more likely to open the message. Higher open rates and engagement can strengthen your sender reputation over time, which does contribute to better deliverability outcomes. But this is a downstream benefit, not a direct one.

The foundation that BIMI requires, specifically a DMARC policy at enforcement level, is itself a meaningful deliverability improvement. Many senders who pursue BIMI for the logo benefit discover that the authentication work required to get there is what actually moves the needle on inbox placement. The VMC is the final step in a process that, by its nature, forces good authentication hygiene.

How Email Industries helps with BIMI implementation

Getting BIMI right involves more than just applying for a certificate. It requires solid email authentication foundations, properly formatted assets, and ongoing monitoring to make sure everything stays in place. At Email Industries, we help brands navigate the full path from authentication audit to verified mark certificate deployment. Here is what we bring to the process:

  • Full SPF, DKIM, and DMARC audits to ensure your authentication is enforcement-ready before you apply for a VMC
  • Guidance on BIMI DNS record structure and SVG logo compliance requirements
  • Ongoing deliverability monitoring to protect the sender reputation that underpins your BIMI setup
  • Expert support for organizations dealing with complex sending environments, multiple domains, or compliance-sensitive industries

If you are ready to pursue BIMI or want to make sure your authentication infrastructure is solid before you invest in a VMC, explore our Deliverability Assurance Packages or browse our full range of services. Feel free to contact us to talk through where your program stands and what it would take to get BIMI-ready.

Related Articles

Share the Post

Related Posts

The Best Senders Read This – Do You?

Get expert-backed strategies, real-world case studies, and insider email deliverability tips straight to your inbox. Join the Inbox Insiders.