VMC vs CMC for BIMI: What Is the Difference?
Verified Mark Certificates and Common Mark Certificates are evidence documents that bind an organization, domain and logo under an issuer's verification process. A VMC is centered on a qualifying registered mark; a CMC provides a path for eligible logos that do not use that trademark route. Provider support and display rules still vary.
Choose a VMC when the logo qualifies as a registered trademark accepted by an issuer. Consider a CMC when the logo is not eligible for the VMC trademark path but can satisfy the issuer's identity and prior-use or mark-control checks. Both are referenced from the BIMI record as evidence documents; neither guarantees that a mailbox provider will display the logo.
Overview
VMC means Verified Mark Certificate. Its distinguishing feature is verification of a logo through a qualifying registered trademark or another mark category accepted by the issuer's current program. CMC means Common Mark Certificate. It is designed for logos that may not have the registered-trademark status required for a VMC, while still requiring the applicant and logo to pass the issuer's identity, domain and mark-use controls.
Both certificate types are evidence documents, typically published at the HTTPS URL in the BIMI record's a= tag. The certificate is not a replacement for the l= SVG logo URL, DMARC enforcement or aligned authentication.
Why it happens
Mailbox providers need more than a self-asserted DNS statement when they want stronger confidence that a logo belongs to the organization using it. Certificate issuers therefore verify organizational identity, domain control and the applicant's right to use the mark. VMC and CMC programs use different evidence for the mark itself, which is why trademark status matters for one path but is not the only possible route.
How to fix it
Start with the providers you need to support, then check their current BIMI certificate policy. Ask an approved issuer whether the logo and trademark jurisdiction qualify for a VMC or whether a CMC is the appropriate route. Complete the issuer's legal and domain-control process, host the issued PEM file at a stable HTTPS URL, reference it in the a= tag, and use the BIMI Inspector to confirm that the public record and file location are structurally reachable.
The inspector can parse observable metadata from a fetched evidence file, but it does not replace the issuer or mailbox provider. It does not establish chain trust, revocation, Certificate Transparency, legal ownership or acceptance by a particular provider.
Examples
A company with a qualifying registered word or design mark may apply for a VMC. A company using a long-held corporate logo that is not registered in a supported trademark system may ask an issuer whether it qualifies for a CMC. Exact eligibility, accepted jurisdictions, proof-of-use periods and provider support can change, so the issuer and provider documentation are the source of truth.
Common mistakes
Do not assume CMC means no verification, assume every trademark registry is accepted for VMC issuance, reuse a certificate for domains it does not cover, host the PEM file behind authentication, or treat a successfully parsed certificate as proof that the provider trusts or will display it.
Checklist
- Identify the mailbox providers whose display policy matters to the organization.
- Confirm whether those providers accept VMC, CMC, both, or neither for the desired UI.
- Confirm trademark eligibility and jurisdiction before choosing the VMC path.
- Complete the issuer's organization, domain-control and mark-use verification.
- Host the issued evidence document over stable public HTTPS and reference it in a=.
- Validate public structure separately from provider acceptance and logo display.
Trademark and identity verification
A VMC application normally depends on a qualifying registered mark and evidence that the applicant controls both the organization and the relevant domains. A CMC still requires identity and mark-use verification, but it is intended to cover eligible common marks outside the classic registered-trademark route. The exact documents and accepted logo variations are issuer-specific.
Provider-specific requirements
A provider can require a certificate, restrict which certificate type unlocks a particular badge, or apply additional sending-history and reputation thresholds. A certificate that is valid for one provider's BIMI program may not produce the same presentation at another provider.
Frequently asked questions
Can I get a VMC without a registered trademark?
Usually the VMC route depends on a qualifying registered mark accepted by the issuer. Some issuer programs may recognize additional protected mark categories, so confirm the current eligibility rules directly with the issuer rather than assuming.
Is a CMC a self-signed or unverified certificate?
No. A CMC is still issued after organizational, domain and logo-use checks. Its distinction is the mark-eligibility route, not the absence of identity verification.
Will a VMC always display a checkmark or logo?
No. Some providers associate specific UI indicators with a VMC, but presentation is provider-specific and still depends on authentication, reputation and account policy.