Skip to content
DMARC Done

bimi

BIMI, VMC and CMC: does a small business need them?

An honest look at BIMI logos in Gmail, Apple Mail and Yahoo: what it takes, what VMC and CMC certificates cost, and when it is worth it for a small business.

DMARC Done team · 5 October 2026 · 6 min read

BIMI puts your logo next to your emails in some inboxes. It sounds like a cheap branding win. For most small businesses it is neither cheap nor a priority. This post explains what it takes, what it costs, and when it is worth doing.

What BIMI is

BIMI stands for Brand Indicators for Message Identification. It is one more DNS record, published at default._bimi.yourdomain.com, that points to your logo and, usually, to a certificate proving the logo is yours:

Type:  TXT
Host:  default._bimi
Value: v=BIMI1; l=https://yourdomain.com/logo.svg; a=https://yourdomain.com/logo.pem

The l= tag is the address of your logo file. The a= tag is the address of your certificate. Mailbox providers that support BIMI check both, and if everything is in order, show the logo as the sender’s avatar.

The requirements, in order of difficulty

1. DMARC at enforcement

BIMI only works for domains that enforce DMARC (Domain-based Message Authentication, Reporting and Conformance). Google’s BIMI page states that the policy “must be set to quarantine or reject” and that none is not supported. It also requires the percentage tag to be 100. The BIMI Group’s implementation guide adds that the subdomain policy must not be none either.

This is the step most domains have not taken. If your DMARC record still says p=none, see what “DMARC policy not enabled” means and quarantine vs reject.

2. A logo file in the right format

The logo must be an SVG file in a restricted profile called SVG Tiny Portable/Secure (SVG Tiny PS). The BIMI Group and Google describe the rules:

  • square, with a solid background
  • a <title> element
  • no scripts, animation or external links
  • 32 KB or smaller

Most logo files exported from design tools do not meet this profile as they are. They need converting and checking.

3. A certificate (for Gmail and Apple Mail)

There are two kinds of certificate:

  • VMC (Verified Mark Certificate): proves you own a registered trademark for the logo. Google says the logo “must be trademarked with an intellectual property office that’s recognized by VMC issuers”. DigiCert says the VMC guidelines recognize seventeen offices, including the EU Intellectual Property Office (EUIPO).
  • CMC (Common Mark Certificate): no trademark needed, but the logo must have been in public use for at least 12 months. DigiCert puts it as: “You must have used the logo for at least 12 months before the Mark verification date on a domain you control,” and says it can check this with the Internet Archive. SSL.com and Sectigo state the same 12-month rule.

The certificate is issued to your own company, after identity checks on your business. Nobody can buy one on your behalf in their own name.

Inbox What it needs Notes
Gmail DMARC enforcement plus a VMC or CMC CMC accepted since September 2024. The verified checkmark appears only with a VMC.
Apple Mail DMARC plus a VMC iOS 16, iPadOS 16, macOS Ventura 13 or later, and iCloud.com. Apple’s page mentions VMCs and “other forms of BIMI Evidence Documents” but does not name CMC, so we could not confirm CMC support.
Yahoo Mail DMARC quarantine or reject, no certificate required Yahoo shows logos only on bulk mail, not personal emails, and only when it sees “sufficient reputation and engagement”.
Outlook and Microsoft 365 Not supported Microsoft states that Exchange Online does “not yet support BIMI”.

So the honest picture: without a certificate, your logo can appear only in Yahoo, and only if you send bulk mail with a good reputation. Gmail, the biggest prize, requires a certificate. Outlook does not show BIMI logos at all.

What it costs

Certificates are annual. These are list prices in US dollars per year, as published by sellers when we checked in October 2026:

Seller VMC per year CMC per year
Sectigo as low as 1,350 as low as 990
SSL.com 1,500 (1 year), 1,350 (2 years), 1,275 (3 years) 1,150 (1 year), 1,035 (2 years), 977.50 (3 years)
GoGetSSL (DigiCert VMC) 1,608 (1 year), 1,527.60 (2 years), 1,474 (3 years) not listed
SSL2BUY (DigiCert) 1,350 (1 year), from 1,200 (3 years) 1,100 (1 year), from 950 (3 years)
SSL2BUY (Prime, GlobalSign-backed) from 780 (3-year rate) from 650 (3-year rate)
VMCcerts from 749 from 649

In round numbers, that is roughly USD 650 to 1,600 a year, every year. The cheaper rates usually require paying for several years up front.

For a VMC, add the trademark if you do not have one. The EUIPO lists its basic online fee for an EU trade mark as EUR 850 for one class. Registration takes time, and the trademark has to be registered, not just applied for, before a VMC can be issued.

The BIMI Group keeps a list of the certificate authorities that issue these certificates. At the time of writing it names DigiCert, GlobalSign and SSL.com. Several sellers in the table above are resellers rather than issuers, so compare who actually issues the certificate before you buy.

Plain-English takeaway: BIMI needs DMARC at quarantine or reject, a specially formatted logo, and, for Gmail and Apple Mail, an annual certificate costing roughly USD 650 to 1,600. Without a certificate, only Yahoo may show your logo. The DMARC part is worth doing for every business. The logo part is optional.

When it is worth it

BIMI can make sense when most of these are true:

  • You send regular marketing or transactional email to consumers, many of whom use Gmail or Apple Mail.
  • Your brand is recognizable, and impersonation of it is a real risk to your customers.
  • You already own a registered trademark for your logo (for a VMC), or your logo has been on your website for at least a year (for a CMC).
  • An extra USD 650 to 1,600 a year is small compared with your email marketing budget.

It is probably not worth it yet when:

  • Your email is mostly one-to-one: quotes, invoices and replies to existing customers.
  • Your customers mostly use Outlook or Microsoft 365, which do not display BIMI logos.
  • Your DMARC policy is still p=none. Fix that first. It protects you whether or not you ever show a logo.

We have not found independent, published data showing how much BIMI changes open rates for small senders, so we will not quote a number. Treat any claim you see with care, and ask for the source.

What our BIMI-ready add-on covers

DMARC Done’s main service takes your domain to p=reject, which covers the hardest BIMI requirement. The optional BIMI-ready setup add-on costs EUR 99 and covers the rest of the groundwork:

  1. An eligibility check: DMARC enforcement, and whether a VMC (registered trademark) or a CMC (12 months of public logo use) fits your situation.
  2. Converting your logo to SVG Tiny PS and validating it against the format rules.
  3. Hosting the logo file, and later the certificate file.
  4. Publishing your default._bimi record with the logo now, and adding the certificate address once it is issued.
  5. An application pack and guidance for applying to a certificate authority.

What it does not include: the certificate itself. We do not sell VMCs or CMCs. Your company applies to a certificate authority or reseller and pays it directly, because the certificate must be issued to your business. We also do not register trademarks.

Start with the part that matters

Run the free checker at /check?d=yourdomain.com. It shows your DMARC policy, which decides whether BIMI is possible at all, and whether a BIMI record already exists.

If you want the domain taken to p=reject, with or without the BIMI-ready add-on, see pricing.

Sources

See where your domain stands in 10 seconds

Free. No signup. We do not store the domains you check.