Mark Certificate Issuer Information
Some mailbox providers that support BIMI require DNS records asserting a domain’s BIMI information to reference a Verified Mark Certificate (VMC) or Common Mark Certificate (CMC) [collectively ‘Certs’], as outlined in the BIMI protocol. These digital credentials define not only the logo to be displayed, but also confirm that the domain’s use of the logo has been independently validated by a third party. These third parties are referred to as Mark Verifying Authorities, or MVAs for short.
While the AuthIndicators Working Group (AWG) has played a role in developing the technical specifications of the BIMI protocol, including those that describe the contents of a Certs, the AWG does not certify an MVA to issue certificates for BIMI. The decision to accept the respective Certs generated by an individual MVA is left to the discretion of each mailbox provider that supports BIMI, and the following statements are true:
- Each BIMI-supporting mailbox provider can have different rigorous criteria to apply to the decision to accept an MVA’s Certs.
- An MVA may be required to go through a separate vetting process with each mailbox provider.
- Acceptance of an MVA’s Certs by one or more BIMI-supporting mailbox providers does not guarantee that the MVA’s Certs will be accepted everywhere.
Issuance of a Cert by an MVA is done pursuant to published requirements that detail not only the format of the Cert but also the process by which a claim to use a given logo is validated, as well as other artifacts to be produced by the MVA during the process. Among those artifacts are Certificate Transparency (CT) logs, which an MVA maintains to record each Cert it issues, and Certificate Revocation Lists (CRLs), which list Certs that the issuer has revoked. The CRLs are both referenced in each individual Cert and kept as a separate list. The published requirements also describe associated third-party assessments to which an MVA must periodically subject itself in order to prove its compliance with the requirements.
On this page, the AuthIndicators Working Group maintains information about MVAs that issue Certs, including their name, a link to their Certification Practice Statement (CPS), the URL(s) of the CT Log(s) to which each MVA publishes, URL(s) pointing to each MVA’s CRL(s), and the location of each MVA’s most recent audit report as conducted in accordance with the current revision of the VMC Requirements, if available.
| Name of MVA | CPS | CT Log | CRL | Root Cert | Audit Report |
|---|---|---|---|---|---|
| DigiCert | Digicert CPS | https://gorgon.ct.digicert.com/log | DigiCertVerifiedMarkIntermediateCA.crl |
Digicert (pem) | Audit Report |
| GlobalSign | GlobalSign CPS | https://gorgon.ct.digicert.com/log | gsgccr42verifiedmarkca2023.crl | GlobalSign (pem) | Audit Report |
| SSL.com | SSL CPS | https://gorgon.ct.digicert.com/log | SSL.com-VMC-Root-2024-ECC.crl SSL.com-VMC-Root-2024-RSA.crl SSL.com-VMC-I-E1.crl SSL.com-VMC-I-R1.crl |
repository SSL EEC (pem) SSL RSA (pem) SSL E1 (pem) SSL R1 (pem) |
Audit Report |
AuthIndicators Mark Certificate Committee
Background
The AuthIndicators Mark Certificate Committee is an informal group composed of members of the AuthIndicators Working Group (AWG) and Mark Verifying Authorities (MVA) (also known as Certification Authorities (CA)). The committee was originally organized to develop standards regarding the issuance of Mark Certificates (MC).
Now that the standard has been completed (known as the Mark Certificate Guidelines), the committee continues to meet bi-weekly to:
- Make improvements to current guidelines
- Add standards for new MC products
- Discuss user feedback
- Work collaboratively with Mailbox Providers (MBP) and MVAs
CA membership and participation in the AuthIndicators MC Committee
To participate in the bi-weekly meetings of the committee, candidate CAs must follow this procedure:
- The applicant must make a request to the BIMI group to have their MC root included in an approved MC Certificate Transparency (CT) log. The organization name in the subject of the root certificate must match the organization running the proposed MVA.
- The BIMI group will notify the CT log provider(s) that the root has been approved for inclusion.
- The CT log provider will notify the applicant once the root has been included.
- The applicant will publish a certificate to the CT log.
- The applicant will complete a WebTrust MC audit and present it to the BIMI group.
- The applicant will request approval/inclusion by an MBP as a trusted MC issuer, and approval must be granted.
Note:
- MBPs may have other requirements to join their programs as trusted issuers. Recognition by AuthIndicators for a CA to be an MVA does not indicate approval by any MBPs to show an MC issued by the MVA. Root programs are free to choose their own set of requirements for CA/MVAs, independent of AuthIndicators, as well as the specific CA/MVA.
- Only root issuers are allowed to participate in the committee calls. Organizations that have been issued subordinate CAs under another MVA root do not qualify.
Once these steps have been completed and the applicant has been approved by an MBP, they will be notified to join the committee calls.
Note: Inclusion on this list does not guarantee that a Mailbox Provider will honor your Cert. The AuthIndicators working group has no decision making power in which MVAs are accepted or not.
MVAs interested in issuing Certs must provide the following details to be considered for inclusion in the list of approved providers. Submit the information displayed in the chart above and the information provided will be published (typically) within 10 business days. Fill out our contact form with the required information for inclusion.
This list is provided as a courtesy to the MVA community.