hero-faq-1

FAQs

Which email providers support BIMI and display Mark Certificate logos?

Major BIMI-participating mailbox providers include:

  • Gmail (also displays blue checkmark for VMC)
  • Yahoo Mail
  • Apple Mail
  • Fastmail
  • Zoho Mail
  • La Poste
  • au.com

The list is growing as more email clients adopt BIMI standards.

Copy Link

What’s the difference between SPF, DKIM, and DMARC?

These are email authentication protocols that work together:

  • SPF (Sender Policy Framework): Specifies which mail servers can send emails from your domain
  • DKIM (DomainKeys Identified Mail): Adds a digital signature to verify emails haven’t been tampered with
  • DMARC (Domain-based Message Authentication, Reporting & Conformance): Enforces policies on how to handle emails that fail SPF or DKIM checks

All three are required for BIMI and Mark Certificates to function.

Copy Link

What is BIMI and how does it relate to Mark Certificates?

BIMI (Brand Indicators for Message Identification) is an email authentication standard that allows organizations to display their logo in recipients’ inboxes. Mark Certificates (VMC or CMC) are required to prove you legally own the logo you want to display. BIMI won’t work without proper email authentication (SPF, DKIM, DMARC) and a valid Mark Certificate.

Copy Link

Can I Use a Verified Mark Certificate without a Trademark?

No, VMCs require a trademarked logo or a qualifying government seal. If you don’t have either, the CMC is the alternative.

Copy Link

How Long Does it Take to Get a Mark Certificate?
  • VMC: 7–14 days (due to trademark verification).
  • CMC: 5–10 days (prior use verification).

Copy Link

Do I Need DMARC for a VMC or CMC?

Yes. DMARC enforcement is mandatory for both VMCs and CMCs before a certificate can be issued. Your domain’s DMARC policy must be set to p=quarantine or p=reject with pct=100 (applied to 100% of email traffic). A p=none policy does not qualify. DMARC must also be configured at the organizational domain level, not just a subdomain. If you’re unsure whether your domain is DMARC-compliant, tools like Valimail’s domain checker can confirm your current status.

Copy Link

What Email Providers Support VMCs and CMCs?
  • Gmail (including Google Workspace)
  • Apple Mail
  • Yahoo Mail
  • Fastmail

Copy Link

How Long Does it Take to Fix the “Not Secure” Issue?

If you buy an SSL certificate today, you can complete the HTTPS setup in less than an hour, sometimes in minutes, depending on your host. Once it’s active, your site will support HTTPS, and the browser warning will disappear. Already have a valid cert? Scan it via SSL Labs to see what’s causing the issue, then look through our SSL errors guides on how to fix not secure websites in Chrome and other browsers.

Copy Link

Is SSL Enough to Secure My Site?

SSL installation is the first and most visible step. It encrypts data and removes the “Not Secure” label. But no, it’s not the only thing you need. Keeping your site safe also means regular updates, secure passwords, and backups. We’ve written the ultimate website security guide. Check it out!

Copy Link

Should I Worry About the “Not Secure” Warning?

Yes. That security warning means your website uses the old HTTP protocol, which doesn’t encrypt any data (the sensitive information travels in plain text from your users’ browsers to your website’s server). When website visitors see this, many leave instantly, especially if they’re about to enter contact details or payment info. It can hurt both search rankings and credibility.

Copy Link