Knowledge Base
How to request a VMC and prepare your logo in Sectigo Certificate Manager(SCM)
Overview
After following this article, you will have requested a Verified Mark Certificate (VMC) in Sectigo Certificate Manager (SCM), prepared a compliant logo, and published the Brand Indicators for Message Identification (BIMI) record that lets supporting email clients show your logo next to your messages. The logo must be a Scalable Vector Graphics (SVG) file that matches your registered trademark. The article covers prerequisites, four stages (prepare your domain, prepare your logo, submit the request, and publish your BIMI record), how to verify success, and frequently asked questions.
Prerequisites
Before you request a Verified Mark Certificate (VMC), make sure that:
- Your domain is added to Sectigo Certificate Manager (SCM), is active, and is validated.
- Domain-based Message Authentication, Reporting and Conformance (DMARC) is configured and enforced for the domain.
- Your organization has a registered trademark for the logo.
- You have the logo as a Scalable Vector Graphics (SVG) file, or a public web address where it is hosted.
- You have the trademark registration details and the name of the trademark office where the trademark is registered.
Stage 1 — Prepare your domain in Sectigo Certificate Manager
A Verified Mark Certificate (VMC) request cannot proceed until the domain has the correct permissions in Sectigo Certificate Manager (SCM).
- In SCM, open your organization and go to Domains.
- Open the domain for the VMC.
- Enable Mark Certificate, Delegation, and All FQDNs (fully qualified domain names), and then select Save.
- Confirm that the domain status is Active and that domain validation is complete. Resolve any validation issues before you continue.
Stage 2 — Prepare your SVG logo
A Verified Mark Certificate (VMC) logo must be a Scalable Vector Graphics (SVG) file in the BIMI-required format. Most logos need conversion and a few manual corrections.
- Get your logo. If you already use Brand Indicators for Message Identification (BIMI), download your current logo with a BIMI lookup tool. Otherwise, use your original SVG logo file.
- Upload the original SVG file to a BIMI SVG conversion tool, and download the converted SVG file.
- Make the manual corrections in the table below on the converted SVG file, not on the original file.
- Upload the corrected SVG file to a BIMI logo validation tool, and fix every reported error.
| Requirement | What to check |
|---|---|
| SVG Tiny Portable/Secure (Tiny PS) profile | The SVG file must use the tiny-ps profile, not an older SVG profile. |
| No fixed position values | Remove fixed position attributes such as x="0" and y="0". |
| Organization title | Add your exact legal organization name as the SVG title. Use the name shown in SCM under Organization, then Validation Details. Do not use a marketing name, an abbreviation, or website branding. |
| At least two colors | The logo must contain at least two colors. If it has only one, add a second color, export the SVG file again, and validate it again. |
Stage 3 — Submit the VMC request in Sectigo Certificate Manager
- In Sectigo Certificate Manager (SCM), go to Mark Certificates and select Request Certificate.
- Select Standard VMC and your validity period, and then select Next.
- Enter the Common Name. The Common Name is your domain name (for example, example.com), not your organization name (for example, Example Corporation). If you have a previous Verified Mark Certificate (VMC), use the first Subject Alternative Name (SAN) listed in its certificate details.
-
Select a Domain Control Validation (DCV) method:
- Canonical Name (CNAME) record validation is recommended.
- Email validation is also acceptable.
- HTTPS validation usually takes longest.
- Enter your trademark details. Select the trademark office for the country where the trademark is registered, and enter the registration details exactly as they appear in the official registration record.
-
Choose how to host the logo:
- Sectigo hosting: upload the SVG file in SCM.
- Self-hosting: host the SVG file at a public HTTPS web address, and enter that exact address. The file must stay publicly available for as long as you use BIMI.
- Complete every field for the signer (name, title, email, and phone number) and for the Mark Registration Authorized Officer (MRAO), the person who confirms your organization's right to use the trademark (full name, job title, relationship to the organization, email, phone number, postal address, country, and registration information).
- Review all details, submit the request, and confirm that the request status changes to processing.
Stage 4 — Complete validation and publish your BIMI record
Submitting the Verified Mark Certificate (VMC) request does not complete validation. Two validations must finish before the VMC is issued:
- Domain Control Validation (DCV): complete the DCV method you selected immediately after you submit the request. For example, create the Canonical Name (CNAME) record in your Domain Name System (DNS).
- Extended Validation (EV): Sectigo, as the issuing Certificate Authority (CA), validates your organization. Respond quickly to any requests from the Sectigo validation team.
After the VMC is issued, publish your BIMI record:
- Open the issued VMC in Sectigo Certificate Manager (SCM), and note the certificate web address and the logo web address. The certificate is in Privacy-Enhanced Mail (PEM) format.
- Build the BIMI text (TXT) record in this format, where l= is the logo web address and a= is the VMC web address:
v=BIMI1; l=https://<logo-location>; a=https://<certificate-location>; - Check the logo address, the certificate address, and the BIMI syntax before you publish the record.
- In your Domain Name System (DNS), create the BIMI TXT record, and wait for DNS changes to spread across the internet.
How to verify that BIMI is working
After the Domain Name System (DNS) changes have spread, run a Brand Indicators for Message Identification (BIMI) lookup for your domain and confirm that:
- The BIMI record is valid.
- The logo loads.
- The Verified Mark Certificate (VMC) is detected.
Frequently asked questions
Why does my VMC request fail when I submit it in SCM?
The most common causes are missing Verified Mark Certificate (VMC) signer or Mark Registration Authorized Officer (MRAO) details: a missing title, a missing relationship to the organization, an invalid phone number, or incomplete address fields. Complete every field and submit the request again.
Why is my VMC logo rejected?
The Scalable Vector Graphics (SVG) logo usually fails for one of these reasons: it does not use the Tiny PS profile, it contains fixed position values such as x="0" and y="0", it has no organization title, or it has only one color. Correct the SVG file and validate it again.
Why is my BIMI record not working after the VMC is issued?
Check the Brand Indicators for Message Identification (BIMI) text (TXT) record syntax, the certificate web address, the logo web address, and whether the Domain Name System (DNS) change has spread. Also confirm that the logo and certificate web addresses are publicly accessible.
Related articles
Understanding mark certificates :: Sectigo Certificate Manager Documentation
Contacting Sectigo Support
- Support ticket: Support | Sectigo® Official
Need assistance?
Contact our team for help with your purchase or issuing your certificate.