What’s the difference between CMC and VMC certification?
August 28, 2025
Phishing remains a growing threat. The Anti-Phishing Working Group (APWG) identified 3.8 million unique attacks in 2025, showing just how widespread these schemes have become. Cybersecurity Awareness Month emphasizes the importance of recognizing and reporting phishing, while organizations also have an important role to play in making legitimate communications easier to authenticate and recognize.
Phishing has become more convincing, making traditional warning signs harder to rely on. Training and awareness still matter, but technical safeguards and trust signals can give recipients additional ways to distinguish legitimate brand communications from impersonation attempts.
Email remains a top form of outreach and a great way to connect brands and consumers. By combining authentication with visible brand signals, organizations can help protect recipients, make legitimate messages easier to recognize, and build brand trust.
Phishing refers to deceptive messages designed to steal information, credentials, or prompt harmful actions. These attacks often rely on spoofing or impersonation to make messages appear to come from a trusted source.
Phishing emails in the past were often difficult to spot, but still included a few key tells:
Savvy users noticed these scam signals and responded accordingly, but these days, phishing emails are a lot more polished, and therefore, more convincing. Content is more persuasive, as attackers may use professional formatting, personal details, lookalike domains, spoofed display names, or multiple channels such as email and text messages to imitate legitimate brands and contacts. AI can also make fraudulent messages easier to create at scale and harder to distinguish based on writing quality alone.
Traditional phishing red flags still matter, but they are no longer enough to differentiate dangerous emails from their legitimate counterparts.
Cybersecurity Awareness Month reinforces the ongoing need to recognize and proactively address phishing. There are measures that both senders and recipients can take. Organizations can support user awareness with technical safeguards and trust signals that help recipients recognize legitimate communications and identify suspicious messages.
It should not be entirely on the email recipient to distinguish phishing attacks from authentic messages. Brands and email providers can do much of the heavy lifting by implementing frameworks and protocols that help address phishing at the source. Several protocols work together to address email security risks and to enable visual trust indicators, including:
BIMI enables brands to display logos in email inboxes, while mark certificates provide the third party validation of the organization and logo that many mailbox providers require for display. This adds an independently validated visual brand signal to authenticated email.
Two types of Mark Certificates help bring the advantages of brand visibility and visual trust to client or customer inboxes. Verified mark certificates (VMCs) allow brands to display trademarked logos and to qualify for Gmail's blue checkmark.
Common Mark Certificates (CMCs) provide an option for eligible organizations without a registered trademark. Qualifying logos must have been in public use for at least 12 months.
The Secure/Multipurpose Internet Mail Extensions standard offers a pathway to secure emails through encryption and digital signatures. Typically purchased from certificate authorities (CAs) and installed in email clients, these certificates use public-key cryptography to secure email contents — attachments included.
Through S/MIME, digital signatures help email recipients confirm sender identities so they feel confident that messages come from trusted sources. Furthermore, S/MIME proves that messages have not been changed in transit. When encryption is used, message content and attachments can be protected so that only the intended recipient can decrypt them.
These capabilities can strengthen phishing defenses by giving recipients an additional way to verify sender identity and message integrity, making it more difficult for attackers to successfully impersonate a legitimate signed sender.
Recognizing and reporting phishing is a key part of cybersecurity awareness, but as schemes continue to grow more sophisticated, watching for well-known red flags is not sufficient. User awareness should be reinforced by technical safeguards. Frameworks such as SPF, DKIM, and DMARC provide a foundation for email authentication, helping organizations protect their sending domains and make unauthorized messages easier for receiving systems to identify.
BIMI and mark certificates signal credibility with visual cues on top of that technical foundation. Through BIMI and VMCs (or CMCs), validated brand logos can appear in supported email inboxes.
Under this approach, both senders and recipients have important parts to play. Organizations set the stage for secure email communication by implementing SPF, DKIM, DMARC, and BIMI — and adding S/MIME when verified sender identity, digital signing, or encryption is needed.
Recipients do their part by carefully inspecting sender domains and looking for validated brand logos (and, when relevant, Gmail blue checkmarks). They should avoid clicking on any links that are unexpected or seem suspicious. The same level of caution should be applied to unanticipated attachments. Unexpected or sensitive requests that emerge should be verified through alternative channels. Any phishing schemes that come to light must be quickly reported.
Sectigo supports stronger email trust through solutions designed for different aspects of email identity and security. Mark Certificates validate brand identity and logos for supported inboxes, while S/MIME certificates support sender verification, digital signing, message integrity, and encryption.