This guide assumes Verified Mark Certificates (VMC) is already deployed and passing. It covers what breaks at scale and how mature teams operate it.
Edge cases that break a working setup#
- Submitting a logo that differs from the registered mark, even slightly.
- Letting the certificate expire, which silently removes the logo.
- Assuming a pending trademark application qualifies; it must be registered.
- Mail forwarded through mailing lists or personal forwarders, which alters headers and content.
- Acquisitions and rebrands that introduce domains nobody audited.
- Vendors silently changing their sending infrastructure.
Operating it as infrastructure#
- Assign an owner for each sending domain and each vendor relationship.
- Put DNS records under version control or a change-review process.
- Alert on authentication pass rate drops and reputation changes, not just outages.
- Run a quarterly audit against the setup steps below.
- Document runbooks for the three most common failures.
Reference: the baseline setup#
- Confirm your logo is a registered trademark in an accepted jurisdiction (USPTO, EUIPO, UKIPO, JPO, and others).
- Prepare the exact trademarked artwork as SVG Tiny PS.
- Complete organization validation with the CA, including notarized identity verification.
- Receive the PEM certificate, host it over HTTPS, and reference it in the a= tag of your BIMI record.
- Calendar the renewal; VMCs are valid for one year.
Frequently asked questions#
How much does a VMC cost?
Roughly $1,000 to $1,500 per year per logo, depending on the CA.
How long does issuance take?
Typically 2 to 6 weeks, mostly spent on organization and trademark validation.
Do I need one VMC per domain?
One VMC can cover multiple domains using SANs, if they share the same trademark.