Your logo does not depend on you

by Francis Rozange | Sep 8, 2026 | Email Marketing

Someone will sell you a certificate. They will explain that it makes your logo appear in the inbox, and that this appearance buys trust, therefore opens, therefore revenue.

All of that may happen. None of it depends on you.

The mechanism is called BIMI, and the only way to understand it is to read what each operator writes about it. The four documents do not say the same thing.

The status of the text, first

BIMI is not a standard. It is an IETF working document whose most recent version is dated 1 May 2026 and carries, like all its kind, the standard warning:

“It is inappropriate to use Internet-Drafts as reference material or to cite them other than as ‘work in progress.’ This Internet-Draft will expire on 2 November 2026.”

Eight years of work, fourteen versions, and still no RFC. That is not a criticism of the protocol, it is a description of its status. It explains why each operator applies its own reading.

Two certificates, two worlds

The specification draws a sharp line between the two documents the market confuses.

“A Verified Mark Certificate is an MC issued by an MVA in support of BIMI Indicators that are representations of either Registered Trademarks or Government Marks.”

“A Common Mark Certificate is an MC issued by an MVA in support of BIMI Indicators that are representations either of Prior Use Marks or Modifications of Registered Trademarks.”

The VMC assumes a registered trademark. The CMC does not: it covers prior use or a variant of a registered mark, which allows a seasonal colour change or a logo stacked on two lines.

Google puts it in the buyer’s terms: “To be eligible for a VMC, your logo must be trademarked with an intellectual property office that’s recognized by VMC issuers. […] The trademark process can take 6 to 12 months.”

Six to twelve months of process before you can even order the certificate. That is the first piece of information sales pages leave out.

Only four authorities issue these certificates today: DigiCert, Entrust, GlobalSign and SSL.com. Their maximum validity is 398 days, meaning an annual renewal.

What Yahoo displays, and on what terms

Yahoo is by far the most transparent operator on this subject. Its sender page lists four conditions, and the fourth is the most interesting:

“A BIMI record exists which points to a valid logo in SVG format. A DMARC policy of quarantine or reject is in place. The mailing is sent to a large number of recipients (bulk mail; we don’t display brand logos for personal emails). We see sufficient reputation and engagement for the sending email address.”

Sufficient reputation and engagement. No figure is published, and Yahoo publishes none elsewhere either: that is a constant with this operator.

And above all, this sentence, which the certificate market prefers to ignore:

“We currently do not require VMCs to be set up for BIMI logos to appear in Yahoo applications.”

At Yahoo the certificate is not required. It is only taken into account if it exists.

What Gmail displays, and what it reserves

Google requires a certificate, VMC or CMC: “The third-party certification must be a Verified Mark Certificate (VMC) or a Common Mark Certificate (CMC).”

The difference between the two comes down to one visual detail, and Google says it plainly: “In Gmail, you’ll see a checkmark next to senders verified with a VMC. Non-Gmail web apps do not support this feature.”

The blue checkmark is therefore reserved for the VMC, and for Gmail. Paying for the registered trademark buys a glyph in a single interface.

The technical requirements are precise and unforgiving: SVG with size declared in absolute pixels, at least 96 pixels per side, file of 32 KB or less, HTTPS server, certificate in PEM format, and up to 48 hours before display.

One recommendation deserves attention for what it says about the craft: “The SVG file should include the <desc> element (description) for accessibility.” The logo is an image, so it gets described.

What Google does not publish: any volume, reputation or engagement threshold conditioning logo display. Any claim of the form “Gmail requires such and such a volume for BIMI” is unsourced.

Apple, or the most widespread misunderstanding

Apple Mail has displayed BIMI since iOS 16, iPadOS 16 and macOS Ventura. On that everyone agrees.

On the rest, the developer documentation says the opposite of what you read everywhere:

“BIMI compliance is managed by the mail provider on the server. An organization’s logo appears in Apple Mail for a given email message when the mail provider has: Been added to the bimigroup.org list of providers supporting BIMI, and been verified by Apple. […] Added the required headers vouching for these checks.”

Apple Mail validates nothing. It displays what the server has already validated, through headers set upstream. A user reading mail in Apple Mail from a provider that does not implement BIMI will never see your logo, whatever your certificate.

Note too that Apple writes “for example, a VMC trusted by the mail provider”. Apple nowhere requires a VMC.

What it costs, and what it buys

Let us restate the real chain. A strict DMARC policy on the domain and its subdomains. A logo redrawn in SVG Tiny PS. A registered trademark, if you want the checkmark, with six to twelve months of examination. An annual certificate from one of four authorities. An HTTPS server dedicated to two files.

And at the end: a logo displayed at Yahoo if your engagement is sufficient, at Gmail if your certificate suits, at Apple if the recipient’s provider has done its job.

None of those three conditions is under your control. All you can do is meet the prerequisites and wait.

There remains one good reason to do it, and it is not visual. BIMI’s only genuinely expensive prerequisite is a DMARC policy at quarantine or reject, applied to subdomains. A company that reaches that state has, along the way, fixed nearly all of its authentication problems.

The logo is not the benefit. It is the proof that the work was done.

What to do tomorrow morning

Before asking for a certificate quote, check your DMARC policy and that of your subdomains. If either is not at quarantine or reject, the certificate you buy will do nothing for months.

Then look at where your recipients are. If your list is overwhelmingly corporate mailboxes, with no consumer Gmail or Yahoo, the display will cover a fraction of your sends that you can estimate before spending.

And if someone promises you a quantified open rate gain from the logo, ask for the primary source. You already know the answer.

Sources


LaFactory works email on the evidence: headers, DNS records, rejection logs. No open rate promises, ever. Get in touch for a deliverability audit.

Cart