Mark Verifying Authority FAQs
Expanding MVA Participation: AuthIndicators Working Group Vision
The adoption of Verified Mark Certificates (VMCs) and Common Mark Certificates (CMCs) has grown steadily, with an inaugural number of Certification Authorities (CAs) currently serving as Mark Verifying Authorities (MVAs). While these providers have played a crucial role in establishing the foundation for BIMI adoption, broader participation from additional CAs is essential to scaling the ecosystem and increasing BIMI adoption for brands.
The AuthIndicators Working Group aims to facilitate the expansion of MVAs by guiding and encouraging more CAs to participate. Through efforts to streamline requirements, enhance transparency, and provide clear, supportive guidelines, the group seeks to create an environment that fosters greater adoption of VMCs and strengthens the trust and security of email authentication.
Frequently Asked Questions (FAQ) on the AuthIndicators Working Group’s Efforts to Expand MVA Participation
What is the AuthIndicators Working Group?
The AuthIndicators Working Group (“BIMIGroup”) is a voluntary organization dedicated to standardizing Brand Indicators for Message Identification (BIMI). BIMI enables brands to display verified logos next to authenticated emails, improving recognition and trust in email communications.
What are Verified Mark Certificates (VMCs)?
Verified Mark Certificates (VMCs) authenticate brand logo ownership and domain verification. They ensure that only verified logos appear in authenticated emails, preventing misuse and enhancing email integrity.
What are Common Mark Certificates (CMCs)?
Common Mark Certificates (CMCs) are a new type of digital certificate introduced by the BIMI Group to simplify and standardize the process of verifying brand logos for use in email authentication, particularly with BIMI (Brand Indicators for Message Identification). CMCs are designed to provide a more accessible and streamlined alternative to Verified Mark Certificates (VMCs) by reducing complexity and cost for brands. They ensure the authenticity of a brand’s logo in emails, enhancing trust and security while making BIMI adoption easier for organizations of all sizes.
Who issues the various Mark Certificates??
VMC and CMCs are issued by Mark Verifying Authorities (MVAs), typically Certification Authorities (CAs) that have undergone rigorous validation. The BIMIGroup maintains a list of approved MVAs along with their compliance documentation.
What are the key differences between a VMC and a CMC?
- VMC (Verified Mark Certificate)
is a more rigorous and established digital certificate issued by Certification Authorities (CAs) to verify brand logos for BIMI. It requires detailed validation, including trademark verification, and is typically more complex and costly. - CMC (Common Mark Certificate)
, introduced by the BIMI Group, is a newer, simplified alternative designed to reduce complexity and cost. It streamlines the validation process while still ensuring logo authenticity, making BIMI adoption more accessible for smaller brands or those seeking a less resource-intensive option.
How does the BIMIGroup plan to expand MVA participation?
The BIMIGroup is focused on providing resources and guidance to increase VMC issuance and encourage broader CA participation. By offering clear guidelines, promoting transparency through Certificate Transparency (CT) logs, and advocating for regular audits, the BIMIGroup aims to support the growth of trusted MC providers and help them navigate the process effectively.
How can a Certification Authority become an MVA?
Certification Authorities interested in issuing VMCs/CMCs should:
1) Understand the AuthIndicator’s Mark Certificate guidelines and technical specifications
a) Update the CP/CPS to recognize adherence to the Mark Certificate Guidelines
2) Issue a Mark Certificate
a) Post a Mark Certificate to a Mark Certificate Guideline recognized log
3) Register in the Common CA Database (CCADB) – Ensure inclusion in the CCADB to promote transparency and interoperability across trust stores. Once the steps on the CCADB site have been followed, the support email is support _at_ ccadb.org.
4) Pass an appropriate WebTrust audit
a) “Verified Mark Certificate” audit
i) Including establishing Certificate Revocation Lists (CRLs): Provide mechanisms for revoking MCs when necessary.
b) Network Security
c) Post to CCADB
5) Provide CPS, Proof of CT logging, CRL URLs, root certificates, and audit letter for review to AuthIndicators via the Contact Us form.
6) Be included by a MBP (Mailbox Provider) as a MC issuer.
Following these steps allows CAs to be considered for inclusion as MVAs, contributing to BIMI adoption and strengthening email security.
NOTES:
1) There are multiple Mailbox Providers implementing BIMI that can help with testing before becoming an official MVA. Both Apple and Fastmail have helped with this in the past. Contact the BIMI Group at our Contact Page for assistance.
2) There is a bi-weekly call consisting of some representatives from CAs and AuthIndicators. If you would like to be included in this call, please use the Contact form, and once the steps above have been validated, an invitation should be extended. This process can take a bit of time.
A more formal definition of the requirements to join the call can be found on the Resources page for VMC Issuers.
What is the BIMIGroup’s role in certifying MVAs?
The BIMIGroup does not certify MVAs but provides technical specifications and requirements for Mark Certificate issuance. Each mailbox provider determines whether to accept VMCs from a given MVA based on their own criteria and vetting processes.
How does the BIMIGroup support BIMI and VMC adoption?
The BIMIGroup promotes BIMI and VMC adoption by:
- Providing Resources:
Offering implementation guides, tools, and best practices. - Maintaining MVA Information:
Keeping an updated list of compliant MVAs. - Engaging with Stakeholders:
Collaborating with brands, CAs, MVAs, and mailbox providers to advance BIMI adoption.
These efforts aim to improve email authentication and promote a more secure and trusted email ecosystem.
Last Updated October 2026