Skip to content

Gmail Blue Checkmark: What BIMI Actually Costs in 2026

Email Security · practitioner · 10 min read · last reviewed 2026-08-31

Gmail's blue checkmark requires BIMI, DMARC at enforcement, a registered trademark, and a VMC costing $750 to $1,400 a year. Full requirements, steps, costs, and when to skip it.

TL;DR

  • The blue checkmark is not a Gmail setting. It is BIMI plus a Verified Mark Certificate (VMC). A Common Mark Certificate (CMC) shows your logo but never the checkmark.
  • Hard gates with no exceptions: SPF and DKIM aligned, DMARC at p=quarantine or p=reject with pct=100, and a registered trademark matching the logo.
  • Cost in 2026 is $750 to $1,400 a year for a VMC, with authorized resellers roughly 40 to 50 percent under CA retail. No trademark yet adds $1,000 to $2,500 and a 10 to 18 month USPTO wait.
  • Coverage is partial: Gmail, Apple Mail, Yahoo, and Fastmail. Outlook does not support BIMI at all, so a Microsoft-heavy B2B list sees none of it.
  • URIports found 53.6 percent of BIMI-enabled domains had at least one error in 2025, up from 41.8 percent. Google reports nothing to the domain owner when display fails.

Gmail's blue checkmark comes from BIMI paired with a Verified Mark Certificate. It requires a registered trademark, DMARC at enforcement, a compliant SVG logo, and roughly $750 to $1,400 a year for the certificate.

It is not a Gmail feature you apply for. There is no form, no support queue, and no setting in Workspace admin. The checkmark is the visible output of an email authentication chain that ends at a certificate authority, and the certificate needs a trademark you already own. Most guides bury that. Putting it first is what decides whether this project takes you two months or two years.

What the blue checkmark actually is

BIMI stands for Brand Indicators for Message Identification. It lets a domain owner publish a logo in DNS, and lets mailbox providers verify the logo genuinely belongs to that sender before displaying it next to the message.

Google's own admin documentation splits the outcome cleanly. BIMI requires third-party certification for your domain and logo, either a Verified Mark Certificate (VMC) or a Common Mark Certificate (CMC), and in Gmail a checkmark appears only next to senders verified with a VMC.

That single sentence is the whole decision tree.

CertificateRegistered trademark requiredGmail logoGmail blue checkmarkApple Mail
VMCYesYesYesYes
CMCNo. Needs 12 months of public logo useYesNoNo
No certificateNoNoNoNo

Google began accepting CMCs on September 24, 2024. That changed the answer for brands without a trademark, but only partially. A CMC gets your logo into the Gmail inbox. It does not trigger the checkmark. And a BIMI record carrying only an SVG with no certificate satisfies nothing at Gmail.

If you want the checkmark specifically, you need a VMC. If you want a logo and nothing more, a CMC saves you the trademark.

The five requirements, in order

Every one must pass. Every failure in the chain is silent. Google sends no error to the domain owner.

1. SPF and DKIM passing, with alignment

Both must authenticate and align with the domain in your From header. Most senders have this, though not always aligned correctly.

2. DMARC at enforcement

Your DMARC record must be p=quarantine or p=reject at pct=100. A p=none monitoring policy disqualifies you. This is where most projects stall, and it is the step carrying real operational risk, because enforcement starts rejecting any legitimate mail stream you forgot to authenticate.

3. A registered trademark

VMC only. The BIMI Group recognizes trademark offices in more than a dozen jurisdictions, including the USPTO, EUIPO, UK IPO, and IP Australia. The mark must match the logo you intend to display.

4. An SVG Tiny PS logo

A deliberately restricted SVG profile: no animation, no interactivity, no embedded bitmaps. Practical constraints are a square aspect ratio, at least 96x96 pixels, under 32 KB, viewBox values separated by spaces rather than commas, hosted over HTTPS. Exporting from Illustrator or Figma will not produce a compliant file on its own. Expect manual editing.

5. Sender reputation

A valid VMC does not guarantee display. Gmail applies its own receiver policy and reputation checks, so a technically perfect certificate can sit in DNS while the logo stays invisible.

Step 1: Audit your authentication

Publish DMARC at p=none with an rua reporting address. Read the aggregate reports for two to four weeks until you can name every system sending as your domain. Marketing platform, billing system, support desk, CRM, recruiting tool. There are always more than you expect.

Step 2: Move DMARC to enforcement

Fix or authorize every legitimate sender, then step from p=none to p=quarantine to p=reject at pct=100. Red Sift budgets six to eight weeks to reach enforcement, which matches what I have seen for a mid-sized sending estate.

Step 3: Secure the trademark, if you want the checkmark

File with your national IP office. This is the long pole. USPTO registration takes 10 to 18 months. If you already hold a registration, skip ahead and save yourself a year.

Step 4: Build the SVG Tiny PS file

Square canvas, solid background, no gradients you cannot afford to lose. Validate it with a free BIMI SVG checker before you pay anyone.

Step 5: Buy the certificate

Validation includes organization vetting, trademark verification against your logo, and for DigiCert a live identity check by video call. Budget one to four weeks depending on the CA and the certificate type.

Step 6: Host the files

Upload the SVG and the PEM certificate to HTTPS URLs on your own domain. The PEM must load without authentication over TLS 1.2 or higher, and must include the full chain in order: entity certificate, intermediate CA, root CA. Test both URLs in an incognito window. No redirect chains.

Step 7: Publish the BIMI record

A TXT record at default._bimi.yourdomain.com:

v=BIMI1; l=https://yourdomain.com/bimi/logo.svg; a=https://yourdomain.com/bimi/vmc.pem

Step 8: Test with a real external inbox

Send to a personal Gmail account, not a colleague on your own Workspace tenant.

If the logo appears for employees but not external recipients, you are not seeing BIMI. You are seeing directory data or a profile photo. This is the single most common false positive in a BIMI rollout, and it convinces teams they are done weeks before they are.

Allow up to 48 hours after DNS propagates.

What it costs in 2026

The certificate

Entrust sold its public certificate business to Sectigo and exited mark certificates in 2025. Three CAs remain authorized to issue VMCs: DigiCert, Sectigo, and GlobalSign. If a guide still lists Entrust, it is stale.

Direct retail pricing as of August 2026:

ItemDirect price
DigiCert Mark Certificateabout $1,400 per year
Sectigo VMCfrom $1,350 per year
Sectigo CMCfrom $990 per year

Authorized reseller channels sit meaningfully lower, with VMCs advertised from $749 per year and CMCs from $649 per year, roughly 40 to 50 percent below retail. Certificates are valid for 397 days. This is an annual operating cost, not a setup fee.

The trademark

USPTO base filing is $350 per class through Trademark Center, which replaced the legacy TEAS system after the January 2025 fee restructure. Using a custom goods and services description instead of the pre-approved ID Manual raises that to $550 per class. Descriptions over 1,000 characters add another $200 per extra 1,000 characters per class.

Total out-of-pocket for a straightforward single-class registration with attorney support typically runs $1,000 to $2,500 from filing to certificate.

Realistic first-year totals

ScenarioYear 1Year 2 and after
Trademark in hand, reseller VMC$750 to $1,000$750 to $1,400
Trademark in hand, direct CA VMC$1,350 to $1,500$1,350 to $1,500
No trademark, filing now, VMC$1,750 to $4,000 plus a 10 to 18 month wait$750 to $1,500
No trademark, CMC only, no checkmark$650 to $1,000$650 to $1,000

Add engineering time for DMARC enforcement and SVG production. Outsourced, that is another $1,000 to $5,000 depending on the complexity of your sending estate.

How to do this as cheaply as possible

Decide whether you need the checkmark or just the logo. This is the biggest lever by a wide margin. The logo is the asset that occupies inbox real estate. The checkmark is a smaller cue that only appears in Gmail. If your audience is not heavily Gmail-weighted, a CMC at roughly $650 avoids a $1,000 to $2,500 trademark bill and a year of waiting.

Buy through an authorized reseller, not the CA's retail page. Same certificate, same CA, same validation, materially lower price. Confirm the reseller is an authorized partner of DigiCert, Sectigo, or GlobalSign before paying.

Take a multi-year term. One, two, and three-year subscriptions are available and reduce the effective annual cost. If your logo is stable, this is free money.

File the trademark cleanly. Single class, pre-approved ID Manual descriptions, complete application. That holds you at the $350 floor instead of $550 plus surcharges. Run a clearance search first. USPTO fees are non-refundable regardless of outcome.

Certify one domain, not five. Each certificate covers the domain it is issued for. Consolidate outbound mail onto your primary sending domain before you buy, not after.

Use free tooling for the technical work. BIMI Group SVG utilities, free BIMI record checkers, and free DMARC aggregate report parsers cover a single-domain setup. A managed DMARC platform earns its keep on a complex estate. It is overkill for one domain and three sending services.

Take the free path at Yahoo and Fastmail first. Those providers display self-asserted BIMI logos without a certificate. You get partial inbox presence for the cost of the SVG alone, which validates your logo pipeline before you commit to a certificate.

One thing to be clear about: there is no legitimate free VMC, and no dependable free CMC path either. Both require manual identity and logo validation by a human at a CA. Anyone selling an instant certificate is selling you nothing.

The benefits

A brand impression on every send, opened or not. The logo renders in the message list. That is an impression you are not paying a media budget for.

Measurable engagement lift, with a caveat. Red Sift and Entrust research found visible logos increased brand recall by up to 44 percent, opens by up to 39 percent, and buying responses by up to 32 percent. An earlier Verizon study put the average open rate increase at 10 percent. The caveat matters: those figures come from vendors selling BIMI implementation, and Oracle's marketing cloud team reported their own clients saw much more modest gains, with the novelty effect fading as adoption grows. Plan against 10 percent, not 39.

Anti-impersonation value. A phishing actor cannot obtain a VMC for a trademark they do not own. The checkmark is a signal that is expensive to counterfeit, which is the entire point of the standard.

DMARC enforcement as a byproduct. I would argue this is worth more than the checkmark. BIMI forces you to inventory every system sending as your domain and shut down the unauthorized ones. Most organizations never do that work without a commercial reason to.

Differentiation while adoption is low. Your competitor shows a grey initial. You show a logo and a checkmark. That gap narrows as adoption rises, but it has not closed.

The drawbacks

Recurring cost with no volume-adjusted value. A $1,400 annual certificate is trivial at 10 million sends a month and hard to justify at 5,000.

The trademark bottleneck. Ten to eighteen months at the USPTO is not a schedule money compresses. If you do not hold a mark today, the checkmark is a next-year project.

Outlook does not support BIMI. Microsoft built proprietary brand cards instead of adopting the standard. 2026 coverage means Gmail, Apple Mail, Yahoo, Fastmail, and a handful of smaller providers. For B2B senders with heavy Microsoft 365 exposure, a large share of your list will never see any of this.

Display is never guaranteed. Reputation gating means you can do everything right and get nothing. There is no support ticket to file.

Silent and common failure. URIports' 2025 analysis of the top million domains found 53.6 percent of BIMI-enabled domains had at least one error, up from 41.8 percent a year earlier. Non-compliant SVG files were the single largest cause. More than half of implementations are broken and their owners do not know it.

Rebrands are expensive. The certificate binds to a specific mark. Change the logo and you reissue, revalidate, and sometimes refile the trademark.

Enforcement risk if rushed. Moving to p=reject before inventorying your senders silently drops legitimate mail. Invoices, password resets, recruiting outreach. Do the monitoring phase properly.

Should you do it?

You hold a registered trademark and send meaningful volume

Buy a VMC through an authorized reseller on a multi-year term. The math works, and the DMARC enforcement you do along the way justifies the spend on its own.

You do not hold a trademark

Do not start an application just to get a checkmark. File the trademark because you want the trademark. Get a CMC in the meantime for roughly $650, take the logo, and upgrade when the registration lands.

You send low volume to a Microsoft-heavy B2B audience

Skip both. Fix DMARC, publish a self-asserted BIMI record for Yahoo and Fastmail, and spend the certificate budget where it reaches your actual recipients.

The checkmark is a marketing asset with a security prerequisite. The prerequisite is the part that pays for itself.

Pricing and requirements verified as of August 2026. Certificate pricing, trademark fees, and mailbox provider behavior all change. Confirm current figures with the CA and your IP office before budgeting.

Key takeaways

  • Decide first whether you want the checkmark or just the logo. That one choice is the difference between a $650 CMC this month and a $2,500 trademark project that lands next year.
  • The DMARC enforcement work is worth more than the checkmark. It forces an inventory of every system sending as your domain, which most organizations never do without a commercial reason.
  • Never test with a colleague on your own Workspace tenant. Internal directory photos look exactly like a working BIMI logo and will convince you that you are done weeks before you are.
  • Buy through an authorized reseller on a multi-year term. Same CA, same validation, materially lower price.
  • Plan engagement lift against 10 percent, not the 39 percent in vendor research. The firms publishing those numbers sell BIMI implementation.
  • If your audience lives in Outlook, spend the certificate budget somewhere it reaches people. Fix DMARC and publish a self-asserted record for Yahoo and Fastmail instead.

Frequently asked questions

Is the Gmail blue checkmark free?
No. It requires a Verified Mark Certificate, which costs roughly $750 to $1,400 a year, and a registered trademark. There is no legitimate free VMC or CMC path, because both require a human at a certificate authority to validate your organization and your logo.
Do I need a trademark to get the Gmail checkmark?
Yes for the checkmark. A VMC can only be issued against a live trademark registration in a recognized IP office. You do not need one for a logo alone: a Common Mark Certificate accepts 12 months of documented public use of the logo instead, but it never produces the checkmark.
How long does it take to get the blue checkmark in Gmail?
Two to three months if you already hold the trademark, most of which is spent moving DMARC to enforcement safely. Twelve to twenty months if you do not, because USPTO registration alone runs 10 to 18 months.
Why is my logo not showing after I published a BIMI record?
The most common causes are a non-compliant SVG Tiny PS file, a PEM missing its intermediate certificate, DMARC still at p=none, or Gmail's own reputation gating. Google sends no error to the domain owner, so validate the record and both hosted URLs with an external checker.
Does Outlook show BIMI logos?
No. Microsoft did not adopt the standard and built proprietary brand cards instead. In 2026 BIMI display means Gmail, Apple Mail, Yahoo, Fastmail, and a few smaller providers.
What is the difference between a VMC and a CMC?
A VMC is validated against a registered trademark and produces both the logo and the Gmail checkmark. A CMC is validated against 12 months of prior public use of the logo, costs less, and produces the logo only. Google began accepting CMCs on September 24, 2024.

Related

← All How-To & Implementation guides