A Verified Mark Certificate (VMC) is a digital certificate that allows businesses to display their verified brand logo alongside their emails in compatible email clients. It is designed to enhance recipient trust by verifying the authenticity of a sender and reducing the risk of phishing and identity fraud.
The VMC concept is based on the BIMI (Brand Indicators for Message Identification) standard, which allows email clients to display a brand’s logo. However, unlike BIMI alone, a VMC ensures that the organization legally owns the rights to its logo through verification by a trusted certificate authority.
How VMC Works and Key Features
A VMC works in conjunction with BIMI and DMARC (Domain-based Message Authentication, Reporting & Conformance). To display a logo in an email:
- The sender must be DMARC-compliant: The sender’s domain must have a DMARC policy set to
p=quarantine
orp=reject
to ensure email authentication. - The logo must be validated by a VMC: The company must purchase a VMC from a trusted certificate authority, which verifies its identity and legal rights over the logo.
- The VMC certificate is integrated into DNS: A specific DNS entry is added to allow mail servers to retrieve and display the logo.
- The email client displays the logo: If all conditions are met, supported email clients (such as Gmail or Apple Mail) will show the verified brand logo next to the email in the inbox.
Advantages of VMC
- Increases recipient trust: A verified logo helps users recognize authentic emails, reducing phishing risks.
- Protects brand identity: Prevents cybercriminals from misusing a brand in fraudulent email campaigns.
- Improves email open rates: A verified logo stands out in the inbox, increasing engagement with email campaigns.
- Strengthened identity verification: Unlike BIMI alone, a VMC ensures the company legally owns the logo.
- Works with BIMI and DMARC: VMC relies on proven email security and verification standards.
Disadvantages of VMC
- High cost: VMCs must be purchased from a certification authority, which can be expensive for small businesses.
- Requires strict DMARC compliance: A company must have a DMARC record set to quarantine or reject.
- Limited compatibility: Not all email clients currently support BIMI and VMC, restricting logo visibility.
- Strict acquisition process: Organizations must undergo rigorous verification to prove logo ownership.
- Maintenance and renewal: Like other digital certificates, VMCs have an expiration date and require periodic renewal.
Conclusion
Verified Mark Certificates (VMC) bring a new level of security and branding to business emails. By displaying a verified logo in the inbox, they enhance user trust and improve email engagement. However, they require DMARC compliance and financial investment. For enterprises focused on security and reputation, VMCs are a strategic tool in the fight against phishing and email fraud.
Source : https://en.wikipedia.org/wiki/Brand_Indicators_for_Message_Identification