Verified Mark Certificates (VMC)

A Verified Mark Certificate (VMC) is a digital certificate that allows businesses to display their verified brand logo alongside their emails in compatible email clients. It is designed to enhance recipient trust by verifying the authenticity of a sender and reducing the risk of phishing and identity fraud.

The VMC concept is based on the BIMI (Brand Indicators for Message Identification) standard, which allows email clients to display a brand’s logo. However, unlike BIMI alone, a VMC ensures that the organization legally owns the rights to its logo through verification by a trusted certificate authority.


How VMC Works and Key Features

A VMC works in conjunction with BIMI and DMARC (Domain-based Message Authentication, Reporting & Conformance). To display a logo in an email:

  1. The sender must be DMARC-compliant: The sender’s domain must have a DMARC policy set to p=quarantine or p=reject to ensure email authentication.
  2. The logo must be validated by a VMC: The company must purchase a VMC from a trusted certificate authority, which verifies its identity and legal rights over the logo.
  3. The VMC certificate is integrated into DNS: A specific DNS entry is added to allow mail servers to retrieve and display the logo.
  4. The email client displays the logo: If all conditions are met, supported email clients (such as Gmail or Apple Mail) will show the verified brand logo next to the email in the inbox.

Advantages of VMC

  1. Increases recipient trust: A verified logo helps users recognize authentic emails, reducing phishing risks.
  2. Protects brand identity: Prevents cybercriminals from misusing a brand in fraudulent email campaigns.
  3. Improves email open rates: A verified logo stands out in the inbox, increasing engagement with email campaigns.
  4. Strengthened identity verification: Unlike BIMI alone, a VMC ensures the company legally owns the logo.
  5. Works with BIMI and DMARC: VMC relies on proven email security and verification standards.

Disadvantages of VMC

  1. High cost: VMCs must be purchased from a certification authority, which can be expensive for small businesses.
  2. Requires strict DMARC compliance: A company must have a DMARC record set to quarantine or reject.
  3. Limited compatibility: Not all email clients currently support BIMI and VMC, restricting logo visibility.
  4. Strict acquisition process: Organizations must undergo rigorous verification to prove logo ownership.
  5. Maintenance and renewal: Like other digital certificates, VMCs have an expiration date and require periodic renewal.

Conclusion

Verified Mark Certificates (VMC) bring a new level of security and branding to business emails. By displaying a verified logo in the inbox, they enhance user trust and improve email engagement. However, they require DMARC compliance and financial investment. For enterprises focused on security and reputation, VMCs are a strategic tool in the fight against phishing and email fraud.

Source : https://en.wikipedia.org/wiki/Brand_Indicators_for_Message_Identification

Catégories d’articles