A Verified Mark Certificate is not a TLS certificate. It attests that the organisation named in it has the right to use the logo it contains, and it is checked by the mail client rather than by any transport.
What it attests
- That the mark is registered to the named organisation, in a trademark office the authority recognises.
- That the logo embedded in the certificate matches the registered mark.
- That the organisation was verified as existing and as the mark’s owner.
The logo is embedded in the certificate itself. A client compares the SVG your record points at with the one inside the certificate, so replacing the file without reissuing the certificate breaks the match.
VMC and CMC
| VMC | CMC | |
|---|---|---|
| Basis | A registered trademark | Established prior use, without registration |
| Accepted by | Gmail, Apple Mail, Yahoo, and others | Gmail; support is narrower |
| Marks in Gmail | Blue verified checkmark alongside the logo | Logo only, no checkmark |
| Who it is for | Organisations with a trademark | Organisations without one that can evidence long use |
CMC exists because the trademark requirement excluded a great many legitimate senders. It is a lower bar and it confers less: no verified checkmark, and narrower client support.
Who issues them
A short list of authorities, and it is visible in the records themselves. eBay’s certificate is served from DigiCert, Best Buy’s from GlobalSign, CNN’s through Valimail. DHL self-hosts both files on its own domain — nothing requires the certificate to be served by its issuer, only that it is reachable over HTTPS.
The cost, plainly
- An annual certificate fee, typically in the high hundreds to low thousands per domain.
- A trademark, if you do not already have one — years, and legal expense, and not guaranteed.
- Renewal every year, with the same verification each time.
- Reissuance whenever the logo changes, because the logo is inside the certificate.
What it is worth
A logo in the inbox is a brand-recognition benefit and a modest trust signal to recipients. It is not a security control: an attacker cannot obtain your VMC, and they were never going to — they spoof domains that have no BIMI and rely on recipients not noticing an absence. Judge the spend as marketing, because that is what it is.