The short answer
There is no free Verified Mark Certificate. There is no trial, no non-profit tier, no open source equivalent, and no discount code that takes one to zero. Any page offering a free VMC is either selling something else or selling nothing.
Two things near VMCs are genuinely free, and they are worth having. Self-asserted BIMI puts your logo in Yahoo Mail and Fastmail with no certificate. Apple Branded Mail puts your logo and brand name in Apple Mail through Apple Business Connect, also with no certificate.
If you do need a paid certificate, three companies are authorized to issue one: DigiCert, GlobalSign and SSL.com. Our recommendation is DigiCert if you want published pricing and the fastest path, GlobalSign if you want the lowest real price and will tolerate a quote process, SSL.com if you are buying a Common Mark Certificate rather than a VMC.
Why a free VMC cannot exist
It helps to understand what you are buying, because it is not a file. A VMC is the outcome of an audited identity investigation. A Mark Verifying Authority confirms your company is a real registered legal entity, confirms the person signing is genuinely authorized to sign for it, confirms you own the trademark you claim, and confirms the logo in the certificate matches the registered mark.
That work is done by people. The authority is bound by a published Certification Practice Statement, has to run Certificate Transparency logs and revocation lists, and has to pass WebTrust audits to stay on the list. Those obligations cost money every year whether or not you buy anything.
So the price is not the certificate. The price is the investigation and the audit regime that makes the investigation worth trusting. A free version would mean nobody checked, and a logo nobody checked is exactly what BIMI exists to prevent.
This is also why a trademark is the real gate. A VMC needs a registered trademark from an accepted office. That includes the US, EU, UK, Canada, Australia, Japan, India, France, New Zealand and Sweden, among others. A pending application is not enough. If you do not hold a registration, the certificate price is irrelevant, because your trademark filing is the actual project and it takes months to years.
Watch for this
What is actually free, and what it costs you
Self-asserted BIMI is free. You publish a DMARC policy at enforcement, host a compliant SVG logo over HTTPS, and add a BIMI record to DNS. Yahoo and Fastmail can then display your logo. No certificate, no trademark, no vendor.
Apple Branded Mail is also free. You register in Apple Business Connect and pass Apple's own review of your organization, brand and domain. Apple runs its own check instead of relying on a certificate. We set this up for our own store and it cost nothing but time.
Here is what free does not get you. Gmail does not accept self-asserted BIMI. Gmail is where most people will see your mail, so a free setup leaves the biggest inbox untouched. Free also never produces the blue checkmark next to your sender name, because that specific mark requires a VMC.
Do the free work first anyway. Every free step is a prerequisite for the paid one. DMARC at enforcement and a compliant SVG are required either way, so nothing is wasted.
- Free, no certificate: Yahoo Mail, Fastmail, Apple Mail via Apple Business Connect
- Paid, certificate required: Gmail logo display
- Paid VMC only: the Gmail blue checkmark
- Required in all cases: DMARC at p=quarantine or p=reject, and an SVG Tiny Portable/Secure logo
Entrust is gone, and the Sectigo question
Entrust used to be one of the two main issuers. It is not any more. Entrust stopped issuing mark certificates on 12 May 2025 and sold its public certificate business to Sectigo, Entrust Certificate Services was retired on 8 September 2025, and Sectigo announced the migration complete on 25 September 2025. Older guides that still name Entrust as an option are out of date. If you hold a legacy Entrust VMC, your account moved to Sectigo.
Sectigo now markets mark certificates under its own brand, and both VMC and CMC products appear on its site. At the same time, Sectigo does not appear on the BIMI Group issuer directory, which lists only DigiCert, GlobalSign and SSL.com. That directory is out of date: we pulled the live certificate from tjx.com in August 2026 and it is signed by "Sectigo Limited VMC Issuing RSA CA 1", carries the Registered Mark attribute against USPTO registration 75102671, and runs to August 2027.
We are not going to tell you a Sectigo certificate will not work. We have not deployed one ourselves, but a live example is in production and the BIMI Group directory does not decide acceptance. We will tell you what that gap means in practice. Before you pay Sectigo or any reseller, ask in writing which certificate authority signs the certificate, get the exact root and intermediate chain, and confirm your target mailbox providers accept that chain. The chain is what receivers evaluate. A vague answer to that question is the answer.
Apply the same test to resellers generally. Plenty of sites sell certificates issued by someone else. That is normal and often cheaper. It only becomes a problem when the reseller is vague about whose certificate it is.
The question to ask any vendor
Comparing the three on what actually matters
Price is the least interesting difference, but it is the one people ask about, so here it is. DigiCert publishes VMC pricing at 1,416 US dollars per year and prices its CMC at the same figure. SSL.com is the highest of the three on published price, at 1,500 dollars a year direct for a one year VMC, dropping to 1,350 a year on a two year term and 1,275 a year on a three year term. GlobalSign does not publish public pricing at all and routes you to a quote.
That last point matters more than it looks. GlobalSign's unpublished pricing is not a red flag, it is a negotiation. We bought our own GlobalSign VMC through the reseller SSL2BUY for roughly 780 dollars a year, well under DigiCert's list price for the same outcome. If you are willing to work a quote or buy through an authorized reseller, GlobalSign is usually the cheapest of the three.
Validation experience is where the three genuinely diverge. All of them require the same core evidence: company registration details, an officer-level signer, trademark registration, a compliant SVG, and an identity verification step that is typically a live video call. DigiCert states it can often issue the same day once documentation is verified, which is realistic only if your paperwork is already clean. In our experience the certificate authority is rarely the bottleneck. The bottleneck is your trademark record and your logo file.
Hosting is simpler than vendors make it sound. You host the SVG yourself on your own HTTPS domain in every case. DigiCert additionally offers to host for you and supports multiple logos for sub-brands or seasonal variants, which is genuinely useful for larger senders and irrelevant for everyone else.
Support quality tracks the buying model. DigiCert is the most self-serve and the most documented. GlobalSign is the most hands-on, because a human is already involved in quoting you. SSL.com sits between the two. All three certificates are capped at 397 days, so whichever you pick, you are repeating this annually.
- DigiCert: published pricing, most documentation, optional logo hosting, multi-logo support
- GlobalSign: no public price, quote or reseller only, usually the lowest real cost, hands-on validation
- SSL.com: highest published VMC price at 1,500 a year, issues both VMC and CMC, and its 1,150 a year CMC undercuts DigiCert's 1,416, so it is the strongest option if a CMC is what you need
- All three: 397 day maximum validity, you host the SVG, live identity verification required
Our recommendation
If you have a registered trademark and you want the Gmail blue checkmark with the least friction, buy a DigiCert VMC. The pricing is public, the documentation is the best of the three, and you will not spend a week in a quote loop. You will pay a few hundred dollars more than necessary for the privilege.
If you are price sensitive and can tolerate a quote, buy a GlobalSign VMC through an authorized reseller. That is what we did for our own store, at roughly half DigiCert's list price, and the certificate is live in Gmail today. The trade is a slower purchase for a materially lower bill.
If you do not have a registered trademark, do not buy a VMC from anyone. Look at a Common Mark Certificate instead. A CMC skips the trademark requirement and instead verifies that your logo has been publicly displayed on a domain you control for at least twelve months, checked against web archives. Gmail has accepted CMCs since late 2024. SSL.com and DigiCert both issue them. Be clear on the trade: a CMC gets you the logo in Gmail and Yahoo, and it does not get you the blue checkmark. Only a VMC does that.
When we would tell you not to buy at all
Plenty of senders should not buy a certificate this year. If you send low volume from a single domain, if your DMARC is not yet at enforcement, or if your brand recognition is low enough that a logo in the inbox changes nothing, the money is better spent elsewhere. Do the free work, take Yahoo and Apple, and revisit in a year.
Also do not buy if your trademark is pending. It will be rejected. And do not buy if your logo has been redesigned since you registered the mark, because the logo in the certificate has to match the registered mark. That single mismatch is the most common reason a VMC application stalls. We hit it ourselves and it is the first thing we check now before quoting anyone.
One more from our own deployment. Reputation is not the gate. We spent time chasing sender reputation before realizing it was never what was blocking display. Get the trademark, the exact logo match and the certificate chain right, and the rest follows.
How we handle your data
Common questions
Is there a free Verified Mark Certificate?
No. There is no free VMC, no trial version and no legitimate route to one. A VMC is the result of an audited identity and trademark investigation carried out by people, and the authorities issuing them carry annual audit obligations. What is free is self-asserted BIMI, which displays your logo in Yahoo Mail and Fastmail, and Apple Branded Mail through Apple Business Connect. Neither works in Gmail and neither produces the blue checkmark.
Who is authorized to issue a VMC?
The BIMI Group issuer directory currently lists three Mark Verifying Authorities: DigiCert, GlobalSign and SSL.com. Check bimigroup.org/vmc-issuers yourself before buying, because the list changes. Note that inclusion on the list does not guarantee any given mailbox provider will honor the certificate, since each provider decides acceptance independently.
Can I still get a VMC from Entrust?
No. Entrust stopped issuing mark certificates on 12 May 2025 and sold its public certificate business to Sectigo, Entrust Certificate Services was retired on 8 September 2025, and Sectigo announced the migration complete on 25 September 2025. Any guide still recommending Entrust is out of date. Legacy Entrust certificate accounts moved to Sectigo.
Does Sectigo issue VMCs?
Sectigo markets mark certificates under its own brand following its acquisition of Entrust's public certificate business. It does not appear on the BIMI Group's issuer directory, which lists only DigiCert, GlobalSign and SSL.com, but that directory is stale: the live certificate on tjx.com is Sectigo-issued and valid to August 2027. Before buying from Sectigo or any reseller, ask in writing which certificate authority signs the certificate, get the root and intermediate chain, and confirm your target mailbox providers accept that chain.
What does a VMC cost?
DigiCert publishes VMC pricing at 1,416 US dollars per year. SSL.com publishes 1,500 dollars a year for a one year VMC direct, with 1,350 and 1,275 a year on two and three year terms. GlobalSign does not publish pricing and works from a quote, which usually lands lowest. We bought our own GlobalSign VMC through an authorized reseller for roughly 780 dollars a year. All mark certificates are capped at 397 days of validity, so this is an annual cost.
What is the difference between a VMC and a CMC?
A VMC requires a registered trademark from an accepted office. A Common Mark Certificate does not, and instead verifies that your logo has been publicly displayed on a domain you control for at least twelve months. Gmail has accepted CMCs since late 2024. The practical difference is the checkmark: a CMC gets your logo displayed, and only a VMC produces the blue verified checkmark in Gmail.
Why was my VMC application rejected?
The most common cause is a mismatch between the logo you submitted and the logo as registered with the trademark office. The certificate logo has to match the registered mark, so a redesign since registration will stall the application. Other frequent causes are a trademark that is still pending rather than granted, a trademark registered with an office that is not on the accepted list, DMARC not yet at p=quarantine or p=reject, and an SVG that does not meet the SVG Tiny Portable/Secure specification.
Sources checked
- https://bimigroup.org/vmc-issuers/
- https://bimigroup.org/mva-faqs/
- https://bimigroup.org/verified-mark-certificates-vmc-and-bimi/
- https://www.digicert.com/tls-ssl/verified-mark-certificates
- https://www.globalsign.com/en/verified-mark-certificate
- https://shop.globalsign.com/en/verified-mark-certificates
- https://www.ssl.com/guide/validation-requirements-and-installation-process-for-mark-certificates/
- https://www.sectigo.com/mark-certificates
- https://www.entrust.com/company/newsroom/verified-mark-certificates
- https://support.apple.com/en-us/108340
- https://www.ssl2buy.com/bimi-verified-mark-certificates
- https://knowledge.digicert.com/solution/how-to-trademark-your-logo-for-vmc
Related service
Verified Mark Certificates and BIMI
BIMI puts your logo beside your name in Gmail, Apple Mail, and Yahoo. Getting it right means a certificate, a very specific SVG, and email authentication that already passes.