Open Gmail and a handful of senders stand out. Your bank, a big retailer, a newsletter you actually read: each one shows a small round logo where everyone else gets a plain colored circle, and one or two carry a blue checkmark next to the name. It reads like a trust badge. The fair question is whether you should believe it.
Some senders show a round logo and a blue checkmark in Gmail because they use BIMI, a standard that displays a brand’s verified logo on authenticated mail. The checkmark means a certificate authority confirmed the logo belongs to that domain. It proves the message genuinely came from that brand, not that the message is safe to act on.
Why do some senders show a logo or blue checkmark in Gmail?
Those senders turned on a standard called BIMI and paid a certificate authority to vouch for their logo. BIMI lets a company display its own brand logo as the round avatar next to its emails, in place of the generic initial Gmail draws for everyone else. When the certificate behind that logo is a Verified Mark Certificate, Gmail adds the blue checkmark on top. Google began rolling that checkmark out in May 2023, according to Validity.
The logo and the check are earned, not bought off a shelf. A sender has to authenticate its mail and prove it owns the logo before either one appears. That is the whole point of the badge: it costs enough effort that a random spammer cannot casually fake it.
What is BIMI?
BIMI, short for Brand Indicators for Message Identification, is an email standard that shows a brand’s verified logo next to the messages it sends. Your mail app reads a small record the sender publishes, fetches the logo, and draws it as the avatar.
The standard is maintained by the AuthIndicators Working Group, also called the BIMI Group, an industry body whose members include Google and Yahoo. The working group formed in 2019 and published its first technical drafts in 2021. It matters because BIMI only rides on mail that already passes authentication. The logo is not decoration bolted onto any message. It is a marker that sits on top of the SPF, DKIM, and DMARC checks that prove a message came from the domain it claims.
What does the blue checkmark actually prove?
The checkmark proves two narrow things: the message passed authentication, and a third party confirmed the logo belongs to that domain. In its own BIMI setup documentation, Google puts it plainly: logos used with BIMI “are verified by a third party, so recipients can be sure logos in their inbox are legitimate.”
Hover or tap the check and Gmail names the domain it verified. That is the ceiling of what the badge asserts. It confirms the mail is genuinely from that brand’s own domain, and that the logo you see is the brand’s real, certificate-backed logo rather than a forgery. It makes no claim about the words inside the message, the offer being pitched, or whether you should do what the email asks. The check is a statement about identity. It is silent about intent.
What does the logo not prove about a sender you can trust?
The badge answers “who sent this,” not “should I trust this.” Three gaps are worth holding in mind, because the round logo is designed to feel more reassuring than it earns.
First, a verified brand can still send you junk. A real retailer with a checkmark can mail you a misleading countdown, a renewal you forgot you agreed to, or a promo you never wanted. Authentication and a trademark do not make an offer honest. The check proves the sender is who it says, and that is all.
Second, a missing logo does not mean a sender is fake. Most legitimate senders never set up BIMI, because it takes money, a registered trademark or a year of public logo use, and technical work. Your dentist, a small newsletter, and a friend all show plain avatars. Absence of a badge is the normal case, not a warning sign.
Third, the badge does nothing about a look-alike domain. A scammer who registers a domain that reads almost like a real brand will not earn that brand’s checkmark, but the whole plan relies on you glancing at the avatar and skipping the address. Reading the sender’s actual email address still catches more than the logo ever will. Our guide to spotting AI phishing emails walks through checking the mechanics under a polished message, and phishing that hides behind a fake unsubscribe link is the same trick aimed at a different button.
How does a sender earn the logo and checkmark?
Getting a logo into Gmail takes three steps, in order.
- Authenticate the mail. The domain has to pass SPF, DKIM, and DMARC, and its DMARC policy must be set to quarantine or reject rather than the passive monitoring mode. This is the same authentication regime Gmail, Yahoo, and now Outlook demand of bulk senders across the board.
- Get a certificate for the logo. The sender buys either a Verified Mark Certificate or a Common Mark Certificate from an authorized certificate authority such as DigiCert. Per DigiCert, a VMC binds a legally trademarked logo to the domain after the authority verifies ownership.
- Publish the BIMI record. The sender adds a small DNS record pointing to its logo file and its certificate. Once that is live, mail apps can start drawing the logo.
The certificate choice decides whether the sender gets the blue check or just the logo.
| Verified Mark Certificate | Common Mark Certificate | |
|---|---|---|
| Logo must be | A registered trademark | In public use for 12+ months |
| Blue checkmark in Gmail | Yes | No, logo only |
| Gmail support since | 2021 | September 2024 |
| Works in | Gmail, Apple Mail, Yahoo | Gmail only, for now |
Gmail began supporting the Common Mark Certificate on September 24, 2024, according to Google Workspace Updates. A CMC lets a company without a registered trademark show its logo, provided the logo appears on an archived version of its website from at least a year earlier. The tradeoff: a CMC displays the logo but not the checkmark, which stays reserved for trademarked brands with a VMC.
Does the logo appear on iPhone, Yahoo, and other apps?
Yes, but the same brand can look different from one app to the next. Apple Mail supports BIMI on iOS 16, iPadOS 16, macOS Ventura 13 and later, and on iCloud.com, using a Verified Mark Certificate. According to Apple’s support documentation, the logo shows in the message header only after you open the email, not in the inbox list. Apple also stopped accepting VMCs issued by the certificate authority Entrust after November 15, 2024, so some logos published through that authority no longer display.
Yahoo shows brand logos too, in the inbox itself, for high-reputation bulk senders, and it does not strictly require a VMC. The result is that a single sender might show a full logo in Gmail, a header logo in Apple Mail after you open the message, and a plain colored avatar somewhere else. The badge you see depends as much on your mail app as on the sender.
Can a scammer fake the verified checkmark?
Not on the real brand’s domain. The checkmark rides on DMARC enforcement, so a message that forges a trusted domain fails authentication and never earns the logo or the check. That is the defense working as designed: the impersonation that fools people, mail that looks like it came from a company you trust, is exactly what these checks stop before you see it.
What a scammer can still do is send from a different domain, one that reads almost like the real one, which carries no badge at all. They are betting you will read the friendly display name and the avatar instead of the address behind it. So the check is a real signal that a message came from the domain it claims. It is not a promise that the domain deserves your trust, and it is no substitute for reading the sender address one character at a time.
What the logo means for cleaning up your inbox
Here is the quiet irony of the badge. The senders most likely to have a verified logo are the big retailers, platforms, and marketing operations that mail you constantly, because they are the ones with the trademark and the budget to set BIMI up. A checkmark confirms the newsletter genuinely came from them, which often makes it exactly the sender you want to leave.
Authentication is not consent. A verified sender still lands in your inbox because you are on its list, not because you asked to hear from it this week. The way out is the unsubscribe, and the logo has nothing to do with it. Email Unsubscriber scans your Gmail or Outlook inside your own browser, lists every subscription sender, verified logo or not, and fires the genuine one-click unsubscribe wherever a sender supports it. The scan runs on your device, the access stays read-only, and we never read, analyze, or monetize your email content.
The takeaway
The round logo and the blue check are real signals, and they are narrower than they look. BIMI shows a brand’s verified logo, and a Verified Mark Certificate adds the checkmark that a certificate authority confirmed the logo belongs to that domain. Both prove the message genuinely came from the brand it claims. Neither proves the message is safe, the offer is honest, or the sender is one you should keep.
So use the badge for what it is. Treat a checkmark as confirmation of identity, not a green light. And when a verified brand turns out to be a sender you never read, the badge is just a well-authenticated reminder to unsubscribe.
