The Gmail blue checkmark is supposed to make a legitimate brand easier to spot before a recipient opens an email. But newly shared BIMI data suggests the harder problem is not getting the badge in the first place—it is keeping the certificate, DNS configuration, trademark evidence, and internal ownership current enough for it to remain visible.
A Reddit post by Email Detective founder and r/Emailmarketing user u/pesito reported that 175 of more than 1,200 observed BIMI mark certificates—roughly 14%—appeared to be expired. The finding is not an independent industry census, and it should be treated as a snapshot of that dataset rather than a universal expiry rate. Still, it exposes a useful operational lesson for marketing, security, and email teams: BIMI is a lifecycle program, not a logo-setting exercise. (reddit.com)
The reported BIMI expiry data: what stood out
The original analysis examined BIMI data across 1,200-plus brands and found 175 apparently expired Mark Certificates. It also reported that roughly 90% of certificates with identifiable issuers were issued by DigiCert, and that 110 expired certificates in the dataset came from DigiCert. The post named major brands—including Wells Fargo, Capital One, Booking.com, T-Mobile, Adidas, Binance, Hyatt, and monday.com—as publishers of expired certificates at the time the records were checked. (reddit.com)
The most consequential detail involved Entrust. The post found that all 65 Entrust VMCs in its dataset had expired. That is plausible in the context of Entrust's own transition notice: Entrust stopped issuing VMCs and S/MIME certificates from Entrust Certificate Services on May 12, 2025, while existing certificates remained usable only until their individual expiration dates. (entrust.com)
That does not mean every listed brand abandoned BIMI or failed to care about sender trust. A brand can be migrating to a new issuer, waiting for validation, changing logo assets, moving domains, reworking its DMARC posture, or intentionally deciding that the expense is no longer justified. Public DNS records can also lag internal project status.
Still, an expiry rate in the double digits is enough to challenge a common assumption: that once a company earns a Gmail blue checkmark, its email identity work is effectively complete. In practice, the visual badge depends on a chain of controls that can break at any point.
What the Gmail blue checkmark actually represents
A Gmail blue checkmark is often described as a security feature, a deliverability feature, and a branding feature all at once. That framing is too loose. It is best understood as a visible assertion of validated brand identity that sits on top of email authentication—not as a replacement for authentication and not as a direct inbox-placement lever.
BIMI, short for Brand Indicators for Message Identification, is the mechanism through which a domain publishes an indicator—usually a brand logo—for supporting mailbox providers. The underlying specification describes BIMI as a way for domain owners and email clients to coordinate the display of brand-specific indicators next to properly authenticated messages. The domain publishes the assertion in DNS, while receiving systems determine whether and how to display it. (datatracker.ietf.org)
For Gmail's authenticated blue checkmark, a brand generally needs a Verified Mark Certificate, or VMC. A VMC is tied to a trademarked logo and validates that the organization is authorized to use that mark. DigiCert's current documentation describes VMCs as allowing a company to place a trademarked logo next to the sender field and notes that the certificate is connected to the domain's DMARC status and authenticated organizational identity. (docs.digicert.com)
The four layers behind a visible badge
The recipient sees a small logo and a blue checkmark. The sender has to manage several distinct layers:
- Email authentication: SPF and DKIM need to be configured correctly, and messages need to align with the domain used for DMARC.
- DMARC enforcement: BIMI generally requires an enforcing DMARC policy, rather than a monitoring-only
p=nonerecord. - Logo readiness: The logo has to meet BIMI technical requirements, including the appropriate SVG profile and hosting arrangement.
- Mark certificate lifecycle: For the Gmail blue checkmark, the VMC has to be issued, valid, reachable, correctly referenced in BIMI DNS, and renewed before expiry.
The BIMI Group's implementation guidance states that SPF, DKIM, and DMARC must be aligned and that DMARC needs to operate at an enforcement policy of quarantine or reject on the organizational domain and subdomains. It also notes that self-asserted BIMI has limited support and that a VMC or Common Mark Certificate can be used to validate logo ownership. (bimigroup.org)
That structure matters because it separates the security foundation from the visual reward. DMARC enforcement helps a domain instruct receivers what to do with unauthenticated mail that purports to be from that domain. BIMI can make an authenticated identity more recognizable. A VMC adds third-party validation of a trademarked mark. Those are connected technologies, but they do not produce the same business outcome.
Expired VMCs are an operations problem before they are a marketing problem
The reported expiration numbers are most interesting not as a scorecard of which brands “forgot” BIMI, but as evidence of a recurring ownership gap. Many companies implement BIMI as a campaign or a narrowly scoped security project. Certificates, however, demand the same discipline as domains, TLS certificates, DKIM keys, sender identities, and trademark records.
A VMC renewal may involve more than paying an invoice. The organization can need domain-control validation, organization validation, logo or trademark verification, certificate reissuance, hosting checks, and DNS updates. DigiCert's lifecycle documentation lists steps including preparation, certificate ordering, domain-control validation, organization and logo validation, issuance, reissue, renewal, and revocation. (dev.digicert.com)
That means a missed renewal can originate in several places:
- Marketing owns brand assets but has no access to DNS.
- Security owns DMARC but does not own the certificate budget.
- Legal owns trademark evidence but is not included in email infrastructure projects.
- Procurement treats the VMC as a low-priority annual software renewal.
- An agency implemented BIMI, then left without handing over renewal documentation.
- The domain or sending architecture changed after a merger, rebrand, ESP migration, or business-unit restructuring.
The Reddit post included an anecdote from one VMC user who said recertification took seven months. One report does not establish a typical timeline, but it is directionally consistent with the fact that VMC validation requires coordination across legal identity, trademark documentation, domain control, and technical implementation. DigiCert's current validation guidance specifically calls out identity verification, trademark verification, and preparation steps intended to avoid issuance delays. (knowledge.digicert.com)
Why expiry can be invisible internally
An expired VMC often does not create the kind of incident that wakes up an on-call engineer. Your campaigns may still send. SPF, DKIM, and DMARC may still pass. Mail can still arrive in the inbox. The sender's logo or checkmark may simply stop rendering in supporting clients.
That makes the failure subtle. A deliverability dashboard may show no sudden crisis, while a brand team quietly loses a trust cue in the inbox. If nobody is assigned to test the visible sender experience periodically, a lapse can persist until a customer, executive, or phishing-response team notices it.
This is a classic monitoring blind spot: organizations track whether email was sent and delivered, but not always whether the recipient saw the intended authenticated brand presentation.
Does a Gmail blue checkmark improve deliverability?
The short answer is: do not buy or renew a VMC on the assumption that it directly improves deliverability. This was the clearest point in the Reddit discussion. One commenter argued that the checkmark is a small trust signal during inbox scanning and a brand-consistency element at open, but that it does not itself determine spam placement, inbox rate, or deliverability. Another commenter similarly described BIMI as branding rather than a security control and said renewal should depend on proof of a lift in opens or trust-related outcomes. (reddit.com)
That distinction is technically important. Gmail's sender guidelines focus on the controls that help messages reach Gmail users as expected: authentication, compliance with sending requirements, spam prevention, and responsible sending practices. Gmail introduced baseline requirements for all senders beginning February 1, 2024, with additional requirements for higher-volume senders. BIMI is not the same thing as satisfying those core delivery requirements. (support.google.com)
A VMC can be valuable because it gives a recipient a more recognizable indication that a message is really from your organization. But the certificate does not erase negative engagement, poor list quality, unwanted mail, complaint spikes, weak reputation, malformed authentication, or content that resembles phishing.
A useful causal model
It is more accurate to think about the relationship this way:
- Strong sending practices and authentication can support deliverability.
- DMARC enforcement can reduce opportunities for unauthorized use of your domain.
- BIMI and a VMC can make an already authenticated identity more visible in supported inboxes.
- Greater recognition may improve a recipient's willingness to open, trust, or act on a message.
- Any lift remains contingent on audience, mailbox-provider support, creative quality, send frequency, existing brand familiarity, and campaign purpose.
The difference may sound semantic, but it prevents bad investment decisions. If an email program has a spam-placement problem, the first fix is not a blue checkmark. It is finding the root cause in authentication alignment, list acquisition, sender reputation, content, complaint rates, volume patterns, and unsubscribes.
The business case for BIMI: measure it instead of assuming it
The commercial case for a Gmail blue checkmark is plausible, particularly for established consumer brands, financial services, marketplaces, travel companies, and high-risk categories frequently impersonated by fraudsters. But plausible is not the same as proven for every sender.
VMC providers commonly promote engagement and trust benefits. For example, DigiCert highlights a customer case study that reported a 10% lift in opens after deploying a verified logo. That is useful as an example of a possible result, but it is vendor-published evidence from one case—not an across-the-board benchmark that every program should expect. (digicert.com)
The right question is not, “Does BIMI work?” It is, “Does a visible authenticated logo create enough incremental value for our audience and our sending mix to justify the certificate cost and maintenance burden?”
Metrics worth tracking
If you deploy or renew a VMC, tie it to a measurement plan that distinguishes visual branding from delivery performance. Consider monitoring:
- Open rate by mailbox provider: Compare Gmail engagement trends with other major providers, while accounting for privacy-related measurement limits.
- Click-to-open rate: If more recipients recognize the sender but message relevance is unchanged, opens may rise more than clicks. That finding still has value, but it should be interpreted honestly.
- Conversions per delivered email: For commerce, bookings, subscriptions, and lead-generation programs, this matters more than opens alone.
- Phishing-related contacts: Track customer-support reports, account-takeover attempts, impersonation reports, and whether recipients say they could identify legitimate messages more easily.
- Brand search and direct traffic around major campaigns: A visible sender mark may affect recall even when immediate email clicks do not move dramatically.
- Support and fraud-team feedback: Teams handling scam reports may see benefits that do not appear in campaign dashboards.
How to evaluate impact without fooling yourself
A clean A/B test is difficult because BIMI is set at the domain level and recipient interfaces decide whether to render it. You usually cannot randomly show a Gmail blue checkmark to half of an identical audience. But you can still improve the quality of your decision-making.
First, document a baseline for at least several comparable sends before launch or renewal. Segment results by mailbox provider where your platform permits it. Second, annotate the date when the VMC was active, renewed, lapsed, or reconfigured. Third, control for changes in subject lines, offers, cadence, seasonality, sender names, segmentation, and creative.
For a large sender, a temporary unplanned lapse may create a natural experiment—but do not intentionally let a valid certificate expire simply to test a theory. The reputational downside, inconsistency, and restoration delays are not worth it. Instead, use observational evidence and make the decision with a realistic estimate of annual cost, operational overhead, recipient reach, and plausible value.
VMC, CMC, and no certificate: choose the right level of investment
The expiration discussion also arrives as the market broadens beyond VMCs. A Verified Mark Certificate remains the option associated with a trademarked logo and Gmail's blue authenticated checkmark. A Common Mark Certificate, or CMC, is a newer route designed for logos that may not have a registered trademark but can demonstrate prior use under the applicable requirements.
The BIMI Group characterizes VMCs as the more rigorous, established certificate type requiring detailed validation, including trademark verification. It describes CMCs as a newer and simplified alternative intended to reduce complexity and cost. (bimigroup.org)
That creates three practical paths.
1. VMC: best when visible Gmail verification matters
A VMC makes the strongest case when your logo is registered, Gmail is a meaningful portion of your subscriber base, brand impersonation is a material concern, and your organization has enough sending volume or customer lifetime value to justify ongoing administration.
It is particularly defensible for banks, insurers, retailers, travel brands, B2B platforms sending account or billing notifications, crypto and fintech companies, healthcare organizations, and any brand that customers may reasonably expect criminals to imitate. In those cases, the checkmark is not a magic anti-phishing shield, but it can give legitimate messages a clearer visual identity.
2. CMC: best when you want BIMI branding without a VMC's trademark path
A CMC can be a sensible option for companies that have an established logo but do not have a registered trademark or do not need Gmail's specific blue-checkmark presentation. The exact display outcome depends on each mailbox provider, so do not sell a CMC internally as a guaranteed Gmail equivalent.
DigiCert and Sectigo both currently market VMC and CMC products, while the BIMI Group maintains issuer information and emphasizes that individual mailbox providers decide their own certificate and display requirements. (bimigroup.org)
3. No mark certificate: best when fundamentals deserve the budget first
For many startups and smaller senders, the right answer is to defer certificate spending. If SPF and DKIM are incomplete, DMARC is still in monitoring mode, sending sources are unknown, unsubscribe handling is weak, or the list has questionable provenance, BIMI is a distraction.
Invest first in authentication coverage, DMARC reporting, sender inventory, permission-based acquisition, address hygiene, consistent from-name conventions, and strong transactional-email reliability. A polished badge is less valuable than an email program recipients recognize, asked for, and can safely trust.
The Entrust transition made certificate inventory a priority
The all-expired Entrust finding in the Reddit dataset deserves special attention because it illustrates a supplier-risk problem, not just a renewal problem. When a certificate authority stops issuing a product, the affected sender needs to know which domains, marks, teams, and certificate expiration dates are in scope—and must plan a move before the existing credential becomes unusable.
Entrust states that it ended VMC issuance on May 12, 2025, while existing certificates would remain valid through their expiration dates. The company also announced a migration process for eligible customers to Sectigo's platform. (entrust.com)
A migration of customer accounts is not identical to an automatically valid replacement certificate. Brands should verify the issuer embedded in their current mark certificate, its expiration date, the certificate URL referenced in BIMI DNS, and the validation work needed for any new certificate.
A certificate inventory should answer five questions
Every organization with BIMI should maintain a simple inventory that answers:
- Which domains and subdomains publish BIMI records?
- Which sender streams actually use those domains, including marketing, transactional, support, and partner platforms?
- What logo file and certificate URL does each record reference?
- Which issuer created the certificate, when does it expire, and what renew-or-migrate process applies?
- Who is accountable across security, email operations, brand, legal, procurement, and DNS?
Without this list, it is easy for a certificate to become an orphaned asset. It may be technically visible in DNS but administratively owned by nobody.
A practical renewal playbook for email teams
A VMC renewal should begin months before the certificate expires, especially if the business has complex trademark ownership, multiple brands, international registrations, or a recent reorganization. The original Reddit post's seven-month recertification anecdote is not a universal standard, but it is a strong reminder not to rely on a last-minute workflow. (reddit.com)
120 to 180 days before expiry
Start by confirming the certificate's expiration date, issuer, domain scope, logo, and renewal eligibility. Check whether legal entity names, corporate registration details, trademark registrations, or contacts have changed since the prior issuance.
Also inspect your email architecture. A business may have added a new ESP, customer-support platform, CRM, billing provider, or product-email system since the original BIMI launch. Those systems can complicate DMARC alignment even if they are not directly involved in the VMC order.
90 days before expiry
Begin the issuer's renewal or replacement process. Confirm the designated contacts can receive validation communications and that DNS administrators can make any required changes promptly. If you are changing certificate providers, do not assume old file-hosting arrangements, records, or logo formatting will carry over unchanged.
Review the SVG asset too. Brand teams regularly update logos, color systems, legal lines, and visual identity. A logo that looks correct in a browser may not meet the SVG Tiny PS requirements or may fail validation after an update.
30 to 60 days before expiry
Complete issuance, publish any updated certificate location in the BIMI record, and test external resolution. Send real messages to seed accounts at Gmail and other relevant providers, then validate both authentication and recipient-facing rendering.
Do not stop at a DNS lookup. Check the sender name, avatar or logo, blue checkmark where applicable, message headers, DMARC alignment, and whether different sending platforms produce consistent results.
After renewal
Record the new expiration date in a system that can generate multiple reminders. Assign a primary owner and a backup owner. Create alerts at six months, 120 days, 90 days, 60 days, and 30 days before expiry.
Finally, add BIMI health to a quarterly email-authentication review. That review should include SPF lookup limits, DKIM selector status, DMARC aggregate-report coverage, unknown senders, policy alignment, logo asset availability, and certificate validity.
Community reaction got the priority order right
The Reddit comments were appropriately skeptical of treating a VMC as an automatic growth purchase. One commenter framed renewal as worthwhile only if the brand actively relies on the blue checkmark; another said the decision should depend on evidence of improved opens or trust signals. The same discussion emphasized that enforcement and visibility into sending sources via DMARC are more foundational than a visual badge. (reddit.com)
That does not make BIMI frivolous. It makes it a second-order investment. The badge can matter most after a brand has already solved the less glamorous parts of email identity: knowing every authorized sender, enforcing DMARC safely, maintaining aligned SPF and DKIM, controlling subdomains, and coordinating legal and brand evidence.
The best internal framing is therefore not “BIMI versus security.” It is “BIMI as a visible dividend of mature email security and brand operations.” If your organization has the foundation, a VMC can amplify it. If the foundation is unfinished, the certificate can create the illusion of progress while leaving the major risks untouched.
What brands should do now
The report of 175 expired certificates should prompt an audit, not panic. An expired VMC does not necessarily mean a company is sending unsafe email, and a valid VMC does not prove that every message from a brand is safe. But a lapse can remove a useful recognition signal and expose gaps in governance.
Start with a quick, cross-functional check:
- Find every BIMI TXT record your organization publishes.
- Identify the logo URL and certificate URL referenced by each one.
- Check the certificate issuer and expiration date.
- Verify that DMARC remains aligned and enforced across active sending domains.
- Determine whether Gmail's share of your audience and the brand's impersonation risk justify a VMC renewal.
- Put renewal dates, ownership, validation documents, and DNS procedures in a shared system—not an individual employee's inbox.
For teams evaluating their first deployment, avoid building the business case around a generic claim that a Gmail blue checkmark will fix deliverability. Build it around the specific problem you are trying to solve: stronger sender recognition, clearer differentiation from impersonators, more consistent brand presentation, or a measurable engagement hypothesis.
The bottom line is simple. BIMI can turn hard-won authentication work into a useful customer-facing signal. But the recent expiration data shows the signal only remains useful when somebody owns its lifecycle. The brands that benefit most from the Gmail blue checkmark will be the ones that treat it as continuing email infrastructure, not an annual line item that disappears after launch.
FAQ
What happens when a Gmail blue checkmark certificate expires?
The visible verified-logo experience can disappear in mailbox providers that require a valid certificate for display. Your email may still send and authenticate normally if SPF, DKIM, and DMARC remain correctly configured, but the BIMI-related visual identity may no longer render.
Does a VMC improve Gmail deliverability?
Not directly. A VMC supports a visible brand-verification signal in Gmail, while deliverability depends on core authentication, reputation, recipient engagement, complaint levels, list quality, and compliance with Gmail sender requirements. (support.google.com)
Is BIMI the same as DMARC?
No. DMARC is an email-authentication and policy framework built around SPF and DKIM alignment. BIMI uses that authentication foundation to enable brand indicators in supporting inboxes. A VMC or CMC can provide additional validation for the logo.
Do all brands need a Verified Mark Certificate?
No. A VMC is most useful when Gmail visibility, trademarked-brand protection, recipient trust, and impersonation risk justify the cost and administration. Smaller senders may get more value first from DMARC enforcement, authenticated sending coverage, and list-quality improvements.
How early should a VMC renewal start?
Plan for at least 90 to 180 days before expiry, and allow more time if your organization has complicated trademark documentation, several domains or brands, legal-entity changes, or an issuer migration. Certificate validation and internal approvals can take longer than a routine software renewal.