Suped

A guide to BIMI accredited certificate providers

Published 11 Jul 2025
Updated 24 Jul 2026
11 min read
Summarize with
BIMI VMC and CMC certificate provider guide with email and verified logo icons.
Updated on 24 Jul 2026: We updated this guide with the current MVA list, clearer VMC and CMC eligibility, and the validation evidence to prepare before buying.
The current public BIMI Group issuer list names DigiCert, GlobalSign, and SSL.com as Mark Verifying Authorities (MVAs). All three offer Verified Mark Certificates (VMCs) and Common Mark Certificates (CMCs), although ordering routes, account requirements, and regional availability differ. The current BIMI issuer list should be checked again before purchase because issuer information and mailbox acceptance can change.
The word "accredited" needs care. The AuthIndicators Working Group publishes MVA information, but it does not certify or accredit an MVA. Each mailbox provider decides which issuers and certificate types it accepts, so inclusion on the public list does not guarantee logo display in every inbox.
Before spending money on a certificate, check DMARC enforcement, aligned SPF or DKIM, BIMI DNS, the logo SVG, and the certificate URL. Suped's DMARC monitoring workflow connects DMARC reports, authentication failures, policy staging, alerts, blocklist (blacklist) context, and fix steps in Suped's platform.

The short answer

Choose from the MVAs on the current public list first, then compare procurement fit, validation process, support, renewal terms, hosting, and whether the brand qualifies for a VMC or CMC.
  1. DigiCert: A listed MVA with direct VMC and CMC ordering, certificate management, and hosted logo and certificate files through its DigiCert page.
  2. GlobalSign: A listed MVA offering VMC and CMC ordering, with account and regional sales routes that should be confirmed during procurement.
  3. SSL.com: A listed MVA offering VMCs and CMCs, with public validation and installation guidance for comparing the two routes.
  4. Sectigo: Not named on the current public MVA list. If a Sectigo quote is in scope, get written confirmation of the issuing MVA, certificate chain, and target mailbox acceptance.
Do not buy before DMARC is enforced
A VMC or CMC does not fix weak email authentication. BIMI requires the organizational domain to use p=quarantine or p=reject with pct=100. Subdomains also need an enforcing inherited or explicit policy. A domain at p=none is not ready for a BIMI certificate launch.

Current BIMI certificate providers

A procurement review should separate public MVA listing from practical buying considerations. The list shows which organizations publish the required MVA materials, while mailbox providers make their own certificate acceptance decisions.

Provider

Current status

Best fit

Watch item

digicert.com logoDigiCert
Listed MVA and direct seller
Central certificate management
Mark evidence and renewal
globalsign.com logoGlobalSign
Listed MVA and direct seller
Existing certificate accounts
Account and regional route
ssl.com logoSSL.com
Listed MVA and direct seller
Public validation guidance
Hosting and renewal details
sectigo.com logoSectigo
Not on the current MVA list
Existing procurement route
Actual issuer and acceptance
Provider status and selection notes for BIMI mark certificates.
DigiCert CertCentral order workflow for a mark certificate.
DigiCert CertCentral order workflow for a mark certificate.
For most senders, provider selection is less technical than the readiness work around it. Once a certificate chains to an accepted MVA and the BIMI record points to the right evidence file, the receiving mailbox provider still decides whether to render the logo.

VMC, CMC, and self-asserted BIMI

The certificate type changes the evidence required and the inbox treatment to expect. A registered trademark or eligible government mark usually points toward a VMC. A logo without a registered trademark can qualify for a CMC when the issuer can verify prior use, commonly at least 12 months on a domain the applicant controls. A self-asserted BIMI record leaves the certificate evidence field blank, but support is limited and Gmail requires a VMC or CMC for BIMI logo display.
VMC
  1. Requirement: Requires an eligible registered trademark or government mark that the issuer can validate.
  2. Inbox result: Supports BIMI logo display in participating inboxes and can add Gmail's verification checkmark.
  3. Tradeoff: Requires trademark or government-mark evidence plus organization, domain, and contact validation.
CMC
  1. Requirement: Can cover an unregistered prior-use mark or an eligible modified registered mark under issuer rules.
  2. Inbox result: Supports logo display where CMCs are accepted, but does not add Gmail's VMC verification checkmark.
  3. Tradeoff: Prior-use marks commonly need at least 12 months of visible logo history on a controlled domain.
For a deeper comparison, see CMC and VMC differences. Choose a VMC when the exact logo has eligible trademark or government-mark protection and the Gmail checkmark matters. Consider a CMC when the mark has sufficient prior-use evidence but does not meet the VMC route.
BIMI certificate choices begin with DMARC enforcement and a valid SVG logo.
BIMI certificate choices begin with DMARC enforcement and a valid SVG logo.

Requirements before you buy

A certificate provider validates the mark and issues the evidence file. It does not make a sending domain BIMI-ready. Complete these checks before opening a purchase order.
  1. DMARC enforcement: Set the organizational domain to p=quarantine or p=reject with pct=100 and enforcing subdomain coverage.
  2. Authentication pass: Make sure routine mail passes SPF or DKIM with alignment to the visible From domain.
  3. Logo format: Prepare a compliant SVG Tiny PS logo and validate it before certificate issuance.
  4. Evidence URL: Host the PEM certificate file over HTTPS without access controls, unstable paths, or redirects that break retrieval.
  5. BIMI DNS: Publish the BIMI TXT record at the selector in use, commonly default.
DMARC enforcement exampleDNS
_dmarc.example.com. 3600 IN TXT ( "v=DMARC1; p=quarantine; sp=quarantine; pct=100; " "rua=mailto:dmarc@example.com" )
Use a DMARC checker before treating the policy as complete. Syntax can look correct while a policy value, inherited subdomain rule, or reporting address still needs work.

DMARC checker

Look up a domain's DMARC record and catch policy issues.

?/7tests passed
BIMI record with certificate evidenceDNS
default._bimi.example.com. 3600 IN TXT ( "v=BIMI1; " "l=https://assets.example.com/bimi/logo.svg; " "a=https://assets.example.com/bimi/vmc.pem" )
Complete BIMI SVG validation early. Certificate validation can stall when the logo file has unsupported SVG elements, incorrect dimensions, or a mismatch between the mark and the certificate request.

What the issuer will validate

Price and advertised issuance time mean little if the application evidence is incomplete. The issuer must validate the applicant and its right to use the mark, so legal, brand, DNS, and email owners should prepare the evidence together.
  1. Organization identity: Legal name, registration details, business presence, and a reliable contact method must match authoritative records.
  2. Domain control: The applicant must prove control of every domain included in the certificate request.
  3. Authorized contacts: The issuer verifies the identity and authority of the requester, contract signer, or certificate approver.
  4. Mark eligibility: A VMC needs eligible trademark or government-mark evidence. A prior-use CMC commonly needs at least 12 months of exact logo use on a controlled domain.
  5. Technical files: The final logo, SVG Tiny PS file, domain names, and PEM hosting plan must agree with the application.
Preserve prior-use evidence
For a CMC, keep dated proof that the exact logo appeared on a domain the organization controls. A recent redesign can restart the evidence question, so confirm eligibility before replacing the public logo or submitting the order.

How to choose a provider

Use a simple decision path. Start with whether the provider appears on the current MVA list or can document a route that produces an accepted certificate. Then check mark eligibility, evidence requirements, support, renewal, file hosting, and coverage for the sending domains.
A BIMI certificate provider decision path from DMARC readiness to BIMI publishing.
A BIMI certificate provider decision path from DMARC readiness to BIMI publishing.
The lowest certificate price does not always produce the lowest project cost. Slow evidence collection can delay launch, and a certificate requested for the wrong mark can require correction or reissue. Ask these questions before approval.
  1. Issuer acceptance: Which target mailbox providers accept this issuer and certificate type?
  2. Mark fit: Does the exact logo match an eligible registered mark, government mark, modified mark, or prior-use mark?
  3. Validation burden: Who can provide the legal entity, domain control, authorized-contact, and mark evidence?
  4. Renewal plan: Who owns renewal, certificate replacement, expiry alerts, and BIMI record verification?
  5. Hosting responsibility: Will the issuer host the SVG and PEM files, and what happens to those URLs at renewal or cancellation?
  6. Domain coverage: Which sending domains and approved logos does one order cover, and where are separate certificates required?
For implementation detail beyond provider choice, the VMC setup guide covers the setup sequence and where a certificate is required.

Where Suped fits

Suped is not a certificate authority. Suped is our DMARC and email authentication platform. Its role in a BIMI project is to help teams discover sending sources, correct authentication failures, stage DMARC enforcement, and monitor the domain after the logo begins appearing.
DMARC record detail view showing SPF, DKIM, DMARC, rDNS diagnostics, and DNS records
DMARC record detail view showing SPF, DKIM, DMARC, rDNS diagnostics, and DNS records
Many BIMI failures occur outside the certificate order. Common causes include DNS drift, unapproved senders, SPF lookup pressure, unsigned mail, weak DMARC policy, an expired certificate, an inaccessible evidence URL, or mailbox-specific rendering rules.
For teams that need to stage enforcement without repeated manual DNS edits, Suped's hosted DMARC workflow manages policy changes inside Suped's platform. Before purchasing a certificate, a broader domain health check can also surface authentication and DNS issues that a BIMI record alone does not reveal.
A practical Suped workflow
  1. Discover senders: Use DMARC reports to find legitimate and unapproved sources before enforcement.
  2. Fix authentication: Resolve SPF, DKIM, and domain-alignment failures with issue-level steps.
  3. Stage policy: Move to quarantine or reject with reporting and alerts in place.
  4. Monitor after launch: Watch source changes, authentication pass rates, and blocklist or blacklist signals.

Common failure points after issuance

Certificate issuance is not the end of the project. BIMI display can still fail if one dependency breaks, so these are recurring operational checks rather than one-time setup tasks.
BIMI readiness decisions
Use these conditions before buying a certificate and after material DNS or sending changes.
Ready
Proceed
DMARC is enforced at 100%, routine mail authenticates with alignment, the logo is eligible, and the hosting plan is stable.
Needs work
Pause
A sender, subdomain policy, SVG file, evidence document, or hosting detail still needs correction.
Not ready
Do not buy
DMARC uses p=none, pct is below 100, or routine legitimate mail does not pass aligned authentication.
  1. Policy drift: A later DNS edit moves DMARC back to monitoring mode or reduces policy coverage.
  2. Sender gaps: A new mail source sends without aligned DKIM or SPF.
  3. Logo mismatch: The SVG differs from the validated mark, or a redesign replaces the approved logo after issuance.
  4. Certificate hosting: The PEM URL becomes inaccessible, returns the wrong content type, or points to an expired or incomplete certificate chain.
  5. Provider assumptions: The certificate is valid, but a target mailbox provider does not accept the issuer or display that certificate type as expected.
  6. Renewal drift: A renewed certificate moves to a new URL or changes the chain without a matching BIMI DNS update.
The SSL.com guide explains the validation and installation evidence an issuer can request. The checklist can help legal, brand, DNS, and email teams prepare even when another listed MVA issues the certificate.

Final recommendation

Shortlist DigiCert, GlobalSign, and SSL.com because they appear on the current BIMI Group MVA information page. Treat any quote from a provider outside that list as a reason to verify the actual issuing MVA, certificate chain, current audit status, and target mailbox acceptance in writing.
Then choose the certificate type. Use a VMC when the exact logo has an eligible registered trademark or government-mark basis and the Gmail verification checkmark matters. Use a CMC when a qualifying prior-use or modified mark fits the issuer's rules. Use self-asserted BIMI only when limited mailbox support is acceptable.
Make the provider decision after the domain is ready. A certificate cannot compensate for weak DMARC policy, broken authentication, or an invalid SVG. Complete authentication and evidence preparation first, choose the provider second, and keep monitoring the setup after launch.

Frequently asked questions

DMARC monitoring

Start monitoring your DMARC reports today

Suped DMARC platform dashboard
What you'll get with Suped
Real-time DMARC report monitoring and analysis
Automated alerts for authentication failures
Clear recommendations to improve email deliverability
Protection against phishing and domain spoofing