BIMI record has no mark certificate
What this check looks for
Your BIMI record points at a logo but not at a mark certificate. Gmail, Apple Mail and Yahoo will not show the logo without one, so most recipients see nothing.
Why it matters
This is the difference between a BIMI record that displays your logo and one that only looks like it should. It costs money to fix, which is why it is reported as information rather than as a fault.
What it costs your score
This check never deducts. It reports a fact — or reports that something could not be verified — and is shown on the report without moving the score.
- Severity
- info
- Default confidence
- confirmed
- Status when triggered
- info
- Deduction
- 0 points
- Family cap
- none
- Category
- Email authentication
- Module
- Email bimi
- Fix owned by
- user
- In the ruleset since
- 2026.09
How to fix it
Buy a VMC (trademarked logo) or a CMC (untrademarked), then add its URL to the a= tag.
Without a certificate the major mailbox providers ignore the logo entirely.
Decide between a VMC and a CMC: a VMC needs a registered trademark and earns the Gmail checkmark; a CMC does not and does not.
Buy from a Mark Verifying Authority listed at bimigroup.org/vmc-issuers.
Host the issued PEM over HTTPS and add
a=<url>to‹selector›._bimi.‹domain›.
How to confirm it worked
dig +short TXT ‹selector›._bimi.‹domain› — expect an a= tag with an https URL
A named slot like ‹domain› — and the braces left in the configuration below — is filled in with your own values when this rule appears on a report.
Technical detail
‹selector›._bimi.‹domain› publishes l= but the a= tag is ‹certificate state›. Gmail requires a Verified Mark Certificate (VMC), issued against a registered trademark, and shows a blue checkmark for it; a Common Mark Certificate (CMC) covers untrademarked logos that have been in public use for at least twelve months and displays the logo without the checkmark. Apple Mail accepts VMCs. Certificates are issued only by the Mark Verifying Authorities listed by the BIMI Group (DigiCert, GlobalSign, SSL.com as of 2026) and are valid for at most 397 days.
Standards and references
Test this on your domain
Run the check that produces this finding, on its own, against any domain.