13 min read

Gmail Blue Checkmark 2026: How to Get BIMI Verified Fast

The blue tick beside a sender name is Gmail's clearest trust signal in 2026. Here's how the Gmail blue checkmark works and how to earn it with BIMI and a VMC.

OldGmail Team
Gmail Blue Checkmark 2026: How to Get BIMI Verified Fast

You open your inbox and one sender stands out: a rounded logo where the avatar used to be, and beside the name a small blue tick. That mark is the Gmail blue checkmark, and in 2026 it has quietly become the clearest trust signal Google gives ordinary recipients. It tells them, at a glance, that Gmail cryptographically confirmed the email really came from the brand whose logo is showing — not a look-alike domain, not a spoofer, not a phisher borrowing the name.

For anyone who sends email for a living — marketers, founders, support teams, cold-email operators — the Gmail blue checkmark is no longer a vanity badge. It moves open rates, it blunts spoofing, and it signals to Gmail's own filters that your domain plays by the rules. This guide walks through exactly what the mark is, the BIMI standard behind it, the difference between a VMC and a CMC, the DMARC policy you cannot skip, what it costs in 2026, and why the checkmark quietly depends on the same domain reputation that makes an aged inbox worth more than a fresh one.

What the Gmail blue checkmark actually is

The Gmail blue checkmark is a verified-sender indicator that Gmail displays next to a sender's name in the inbox list and inside the opened message. When it appears, hovering or tapping it reveals a line reading roughly "This sender has verified they own [domain] and the logo shown," confirming that Google validated both the domain and the trademarked logo.

It is important to be precise about what the mark proves and what it does not. The Gmail blue checkmark proves three things: the sending domain passed authentication, the brand controls that domain, and a certificate authority verified the brand's ownership of the displayed logo. It does not certify that the content of any given email is honest, that the offer is legitimate, or that the company is reputable — a verified brand can still send a bad campaign. What the mark removes is the impersonation layer: a scammer cannot easily paint your logo and your blue tick onto a message from a domain they do not control.

Google first rolled the checkmark out in 2023 as an extension of BIMI, and through 2025 and into 2026 it expanded coverage to the Gmail Android and iOS apps, so the badge now travels with the sender across desktop and mobile. The visual language matters here: an unverified sender may still show a brand logo through the newer certificate path, but only a fully verified sender earns the actual blue tick.

BIMI: the standard behind the badge

BIMI stands for Brand Indicators for Message Identification. It is an open email standard — not a Google-only feature — that lets a domain publish a logo which participating mailbox providers display beside authenticated messages. Yahoo, Apple Mail, and Fastmail honor BIMI too, but Gmail is the provider that pairs it with the coveted blue tick, which is why most people first meet BIMI as "that thing that gets you the Gmail blue checkmark."

Mechanically, BIMI is a single DNS TXT record published at default._bimi.yourdomain.com. That record points to two things: a URL for your logo, stored as a specially formatted SVG (the SVG Tiny Portable/Secure profile), and optionally a URL for your certificate. When Gmail receives a message that passes authentication, it looks up your BIMI record, fetches the logo, checks the certificate, and — if everything lines up — renders your logo and, for the top certificate tier, the blue checkmark.

The logo file itself trips up a surprising number of senders. BIMI requires a square SVG in the Tiny PS profile: no external references, no scripts, a solid background, and a single centered mark. A logo exported straight from a design tool almost never validates on the first try. Because BIMI sits on top of email authentication, it is downstream of the same signals that keep you out of spam in the first place — the ones we cover in our guide on how to stop emails going to spam.

VMC vs CMC: the two certificate paths

Here is the single most misunderstood point about the Gmail blue checkmark: BIMI can display your logo through two different certificate types, but only one of them unlocks the blue tick.

A Verified Mark Certificate (VMC) is the premium path. It requires that your logo be a registered trademark in a recognized jurisdiction. A certificate authority — DigiCert or Entrust are the two authorized issuers — verifies your trademark, your domain ownership, and your organization, then issues the VMC. A domain publishing a valid VMC through BIMI is the only configuration that earns the actual blue verified checkmark in Gmail.

A Common Mark Certificate (CMC) is the newer, more accessible path, added to the standard in late 2024 and honored by Gmail in 2026. A CMC does not require a registered trademark. Instead, the certificate authority validates your logo by proof of continuous public use — typically evidence that you have used the mark publicly for at least twelve months. A CMC will make Gmail display your brand logo as the message avatar, but it will not produce the blue checkmark. The blue tick remains exclusive to VMC.

The table below summarizes the split that decides which badge you can earn.

FactorVMC (Verified Mark Certificate)CMC (Common Mark Certificate)
Shows brand logo in GmailYesYes
Unlocks the Gmail blue checkmarkYesNo
Registered trademark requiredYesNo
Proof of public use accepted insteadNoYes (12+ months)
Issuing authoritiesDigiCert, EntrustDigiCert, Entrust
Typical 2026 annual cost$1,000–$1,500$500–$1,000
Best forTrademarked brands wanting max trustNewer brands, no trademark yet

The practical decision is simple. If you own a registered trademark, go straight for a VMC — it is the only way to the blue tick. If you do not yet hold a trademark, a CMC still earns you the logo, which is a real deliverability and recognition win, and you can upgrade to a VMC later once your trademark registers.

The DMARC requirement you can't skip

Neither certificate does anything until your domain is authenticated, and the gatekeeper is DMARC. Gmail will not display a logo or a Gmail blue checkmark for any domain whose DMARC policy is set to p=none. You must publish an enforced policy — either p=quarantine or p=reject — with SPF and DKIM properly aligned.

That requirement is doing quiet, deliberate work. Google is using the blue checkmark as a carrot to push senders toward strict authentication. To even be eligible, you have to lock down your domain against spoofing first, which is exactly the posture Gmail wants from every bulk sender. The authentication chain looks like this:

  • SPF — publishes which servers may send mail for your domain.
  • DKIM — cryptographically signs each message so recipients can verify it wasn't altered.
  • DMARC — ties SPF and DKIM together, tells receivers what to do with failures, and must be at quarantine or reject.
  • BIMI — sits on top of a passing DMARC and points to your logo and certificate.

If you send in volume, these are the same fundamentals that keep you under Gmail's spam thresholds. We break down the sender rules that share this DNA in our piece on the Gmail spam rate threshold, and the authentication failures that trigger hard bounces in the 550-5.7.26 error fix. Get those right, and BIMI becomes the last mile rather than a fresh mountain to climb.

How to get the Gmail blue checkmark, step by step

Earning the Gmail blue checkmark is a sequence, and each step gates the next. Rushing to buy a certificate before your DMARC is enforced simply wastes money. Work through the stages in order.

  1. Authenticate fully. Publish SPF and DKIM for your sending domain and confirm both pass on real outgoing mail.
  2. Enforce DMARC. Move your DMARC policy from p=none to p=quarantine or p=reject. Watch your aggregate reports for a week or two to make sure no legitimate mail is failing before you tighten.
  3. Prepare a compliant logo. Convert your logo to a square SVG Tiny PS file — solid background, centered mark, no external links or scripts. Validate it with a BIMI logo checker before you host it.
  4. Choose your certificate. Registered trademark in hand → apply for a VMC (the blue-tick path). No trademark → apply for a CMC (logo only). Apply through DigiCert or Entrust.
  5. Complete verification. The certificate authority validates your trademark or proof of use, your domain, and your organization. This can take from a few days to a few weeks.
  6. Publish your BIMI record. Add the default._bimi TXT record pointing to your logo SVG and, for a VMC/CMC, your certificate PEM file.
  7. Wait for propagation. Gmail does not flip the badge on instantly. It can take days of consistent, well-authenticated sending before the logo and checkmark appear for recipients.

The whole process rewards patience over shortcuts. There is no button in Gmail that grants the mark, no fast-track fee, and no way to skip the trademark requirement for the blue tick specifically.

What the Gmail blue checkmark costs in 2026

The Gmail blue checkmark is free from Google's side — Gmail charges nothing to display it. The cost sits entirely with the certificate authority and, if you don't have one yet, the trademark registration behind a VMC.

Line itemTypical 2026 costNotes
VMC (annual)$1,000–$1,500 / yearRequired for the blue checkmark
CMC (annual)$500–$1,000 / yearLogo only, no blue tick
Trademark registration$250–$2,000+ one-timeNeeded for a VMC if you don't already hold one
DMARC / authentication tooling$0–$100+ / monthFree for small senders; paid platforms for scale
Logo SVG conversion$0–$150 one-timeDo it yourself or hire a designer

For an established brand that already owns its trademark, the real annual outlay is the VMC alone — roughly a thousand dollars a year for a persistent trust badge in front of every Gmail recipient. For a young brand, the trademark registration is the larger, slower cost, which is exactly why the CMC path exists as an interim step.

Why the blue checkmark moves deliverability

Skeptics ask whether a small blue tick is worth four figures a year. In 2026 the answer, for high-volume senders, is increasingly yes — and for three distinct reasons.

Recognition and open rates. A logo and a verified badge make your message visually louder in a crowded inbox. Brands that have deployed BIMI consistently report measurable lifts in open rates, because recipients recognize and trust the sender before they read the subject line.

Anti-spoofing. The checkmark is a direct shield against impersonation. When customers are trained to look for your blue tick, a phishing email from a look-alike domain — which cannot produce the mark — stands out as suspicious. For banks, retailers, and any brand that scammers imitate, that protection is the whole point.

A reputation signal to Gmail's own filters. Reaching the badge means you enforced DMARC, aligned SPF and DKIM, and passed CA verification. That is a strong, hard-to-fake indication of a legitimate, well-run sender, and it aligns your domain with the sending posture Gmail rewards. It is one more layer on the domain reputation that governs whether you land in the inbox at all — the same reputation dynamics we explore in how Gmail account age affects inbox placement.

Why your checkmark isn't showing

Plenty of senders complete every step and still see no logo, or a logo but no blue tick. The usual culprits are narrow and fixable.

  • DMARC still at p=none. The most common cause. An unenforced policy disqualifies you entirely — logo and checkmark both.
  • CMC instead of VMC. If your logo shows but no blue tick appears, you likely have a Common Mark Certificate. Only a VMC produces the tick.
  • Invalid logo SVG. A file that isn't strict Tiny PS — with a transparent background, external references, or a non-square canvas — silently fails validation.
  • SPF/DKIM alignment gaps. DMARC can pass on one mechanism while the alignment BIMI needs is missing. Check both align to your visible From domain.
  • Not enough sending history. Gmail wants to see consistent, authenticated volume from the domain before it trusts the mark. A brand-new domain may wait weeks.
  • Certificate expired. VMCs and CMCs are annual. Let one lapse and the badge vanishes until you renew.

Work that list top to bottom. In the overwhelming majority of "no checkmark" tickets, the answer is either an unenforced DMARC policy or a CMC where the sender expected a VMC.

Blue checkmark, domains, and aged Gmail accounts

One clarification saves a lot of confusion: the Gmail blue checkmark is a feature for domains that send mail, not for individual @gmail.com mailboxes. You cannot BIMI-verify a personal Gmail address, because BIMI lives in the DNS of a domain you control, and nobody controls the DNS of gmail.com but Google. The checkmark is aimed at brands sending from their own domains — [email protected] — through Gmail or any provider.

That distinction matters for anyone running outreach at scale. If you send from your own domain, BIMI and the blue tick are directly on the table once your authentication is in order. If you send transactional or reply mail through Gmail-based inboxes — including aged accounts used to keep sending warm and trusted — the checkmark isn't the lever; sender reputation, warmup, and volume discipline are. The two strategies stack rather than compete: a verified brand domain for your marketing blasts, and well-aged, well-reputed inboxes for the one-to-one conversations that follow.

Reputation is the through-line in both cases. Whether it's a certificate authority validating your logo or Gmail's filters weighing your sending history, the system is asking the same question — has this sender behaved like a legitimate one over time? That is precisely why operators lean on aged, phone-verified Gmail accounts for the human side of outreach, and reserve the BIMI badge for the branded, high-volume side. If you're weighing where each fits in a real sending stack, our comparison of account age and inbox placement pairs naturally with everything on this page.

Frequently asked questions

Can I get the Gmail blue checkmark for a personal @gmail.com address?

No. The blue checkmark is only available for domains you control, because it depends on a BIMI record in that domain's DNS plus DMARC, SPF, and DKIM. Nobody can add BIMI records to gmail.com itself, so a personal Gmail address can never display the mark. The feature is designed for brands sending from their own custom domains.

Does a CMC give me the blue checkmark or just my logo?

A Common Mark Certificate displays your brand logo as the message avatar in Gmail, but it does not produce the blue verified checkmark. The blue tick is exclusive to a Verified Mark Certificate, which requires a registered trademark. If you see your logo but no tick, you almost certainly have a CMC.

How long does it take for the Gmail blue checkmark to appear?

After you publish a valid BIMI record with a VMC and enforce DMARC, expect anywhere from a few days to a few weeks. Gmail waits for consistent, well-authenticated sending from your domain before it trusts and renders the mark. A domain with little sending history will generally wait longer than an established one.

Is DMARC really required for the Gmail blue checkmark?

Yes, and it must be enforced. A DMARC policy of p=none disqualifies you from any BIMI display, logo or checkmark. You need p=quarantine or p=reject with SPF and DKIM aligned to your visible From domain. Google uses this requirement to push senders toward strict anti-spoofing before granting the trust badge.

How much does the Gmail blue checkmark cost per year in 2026?

Google charges nothing to display it. The cost is the VMC, typically $1,000 to $1,500 a year from DigiCert or Entrust. If you don't already own a registered trademark, budget a one-time trademark registration on top, which can run from a few hundred to a couple thousand dollars depending on jurisdiction and legal help.

Will the Gmail blue checkmark stop my emails from going to spam?

Not by itself, but it helps indirectly. Qualifying for the checkmark forces you to enforce DMARC and align authentication, which are core deliverability requirements. The mark also strengthens your reputation signals with Gmail. It is one layer, though — you still need clean lists, low complaint rates, and disciplined volume to stay in the inbox.

The bottom line on the Gmail blue checkmark

The Gmail blue checkmark in 2026 is the plainest trust badge Google hands to recipients, and earning it is less about paying a fee than about proving your domain is authenticated, your logo is genuinely yours, and your sending history is clean. Enforce DMARC, align SPF and DKIM, prepare a compliant logo, and choose the VMC path if you want the tick or the CMC path if you just want your logo showing while your trademark catches up. Do the authentication work first and the badge becomes the easy part — skip it and no certificate on earth will turn the tick on.

Want the fast version, plus current sender templates, warmup playbooks, and deliverability answers for real 2026 campaigns? Join our community on Telegram at t.me/mixgmail — we share the setups that keep brand domains verified and inboxes landing, and we're happy to look at your specific BIMI or authentication snag.

Aged Gmail Account

Buy old Gmail accounts starting at just $1. Aged from 6 months to 15 years. Instant delivery via Telegram.


From $1 per account
In Stock ⚡ Instant Delivery
Order on Telegram Chat on WhatsApp