59.8%
Certificates >1 year old — in the renewal risk zone
585
Average cert age in days (~19 months) globally
45.9%
Expiring in next 6 months (Jun–Nov 2026)
11.6%
Fresh certs <90 days old — recently deployed
5
Health dimensions in the VMCcerts scoring framework
32.8%
Certificates >24 months — two full renewal cycles old

Executive Summary

BIMI deployment is not a one-time event — it is a system that requires ongoing maintenance across 5 distinct health dimensions. An organisation that deployed BIMI 18 months ago and has not reviewed it since may believe it is “done.” The data suggests otherwise.

59.8% of all active global BIMI certificates are more than 365 days old — in the renewal risk zone where upcoming expiry creates operational jeopardy if not actively managed. The average certificate age globally is 585 days, more than 19 months. 32.8% of certificates are older than two full years, meaning they have already been through at least one renewal cycle — and may be approaching another.

This report introduces the VMCcerts BIMI Health Score Framework: 5 measurable dimensions of BIMI deployment health that any organisation can assess against their own deployment. It also provides the dataset benchmarks that allow organisations to position their health score against the global peer population.

The Framework

5 Dimensions of BIMI Deployment Health

A healthy BIMI deployment requires ongoing attention across 5 areas. Each dimension can be assessed independently, and each carries different risk profiles depending on the organisation’s sector, CA, and sending volume.

D1 · DMARC Enforcement Status
BIMI requires DMARC at p=quarantine or p=reject. Healthy: enforced on all sending domains. At-risk: policy drift, subdomain exemptions, or partial enforcement. Check: run a DMARC lookup on your primary sending domain and all subdomains monthly.
Prerequisite
D2 · Certificate Currency
Certificate must be valid and not approaching expiry. Healthy: >90 days to expiry. Warning: 30–90 days remaining. Critical: <30 days. Benchmark: 59.8% of global certificates are >1 year old. Know your expiry date — set calendar alerts 90 days before.
D2
Time-bound
D3 · Trademark Health
VMC validity depends on the underlying trademark remaining active. If the trademark registration lapses, the VMC renewal will fail. Check: verify trademark renewal dates in your national IP office register annually. Misalignment between trademark and certificate renewal cycles is a common failure mode.
D3
Often missed
D4 · Logo File Integrity
BIMI references a publicly hosted SVG/SVGZ logo file. If that file becomes inaccessible, the logo disappears from inboxes without any certificate error. Check: run an HTTP check on your BIMI logo URL monthly. Validate file against the BIMI SVG profile specification after any website migration.
D4
Silent failure
D5 · DNS Record Accuracy
The BIMI DNS TXT record must reference the current PEM URL. After certificate renewal, the PEM URL changes — the DNS record must be updated immediately. Critical: this is the most common post-renewal failure mode. Validate DNS after every renewal. Use a BIMI inspector tool to confirm mailbox provider visibility.
D5
Most common failure

Section 01

Certificate Age Distribution — The Global Renewal Risk Picture

Global BIMI Certificate Age Distribution (as of 2026-07-02)
Days since issuance · VMCcerts Research Dataset · 20227 records

0–3 months: 2341 (11.6%); 3–6 months: 2212 (10.9%); 6–12 months: 3575 (17.7%); 12–18 months: 3104 (15.3%); 18–24 months: 2357 (11.7%); >24 months: 6638 (32.8%)
Age RangeCertificates% of TotalStatusAction Required
0–3 months234111.6%FreshNo action — monitor DMARC policy drift
3–6 months221210.9%HealthyRoutine check — flag for 6-month review
6–12 months357517.7%Watch zonePlan renewal — initiate process 90 days before expiry
12–18 months310415.3%Risk zoneImmediate renewal review — most are near or past expiry
18–24 months235711.7%High riskVerify certificate is still valid — check expiry date now
>24 months663832.8%Critical auditAudit required — these have been through 1–2 renewals; verify all 5 dimensions
The 32.8% Finding

6638 active global BIMI certificates are older than 24 months. These organisations have maintained BIMI through at least one complete renewal cycle — which is positive. But they are also the most likely to have accumulated health drift: outdated PEM URLs in DNS, trademark renewals not checked, logo files migrated without BIMI SVG validation. A full 5-dimension health audit is warranted for any certificate older than 24 months.

Section 02

The BIMI Health Score — How to Calculate Yours

BIMI Health Score Scale
Points 0–100 across 5 dimensions (20 points each)
0 Critical2550 Moderate75100 Optimal
DimensionMax PointsFull Score CriteriaZero Score Criteria
D1 · DMARC Enforcement20p=reject on all sending domainsp=none or missing on any domain
D2 · Certificate Currency20>90 days to expiry, renewal process activeExpired or <30 days without renewal initiated
D3 · Trademark Health20Trademark active, expiry >12 months, monitoredTrademark lapsed or unmonitored
D4 · Logo File Integrity20BIMI SVG accessible, validated, spec-compliantFile inaccessible or non-compliant
D5 · DNS Record Accuracy20PEM URL current, DNS propagated, mailbox-verifiedStale PEM URL, DNS mismatch
Score RangeStatusRecommended Action
80–100OptimalMaintain monitoring cadence — quarterly full review
60–79HealthyAddress any non-full-score dimension within 30 days
40–59ModerateOne or more dimensions at risk — escalate to owner within 2 weeks
20–39At RiskMultiple failures — immediate audit and remediation
0–19CriticalBIMI likely broken — emergency review, possible logo already gone

Section 03

The Next 6 Months — 3814 Certificates at Expiry Risk

45.9% of all active global BIMI certificates — 3814 organisations — face certificate expiry between June and November 2026. This is not a forecast: these are certificates whose metadata confirms expiry within six months of the dataset snapshot date.

For Organisations Expiring Jun–Nov 2026

If your certificate expires in the next six months and you have not initiated renewal, begin immediately. The minimum lead time from renewal initiation to successful DNS propagation is typically 7–14 business days. For organisations with complex trademark portfolios or regulated IT change processes, allow 30–60 days minimum.

What Good Renewal Process Looks Like

90 days before expiry: initiate renewal with CA and verify trademark health. 60 days before: submit renewal application with trademark documentation. 30 days before: receive new certificate, prepare DNS update. On renewal day: update BIMI DNS TXT record with new PEM URL, propagate, validate with BIMI inspector tool within 24 hours.

Expert Interpretation

VMCcerts Research Analysis

The average 585-day cert age tells a story of organisations that deployed and stopped managing

19 months is the average age of an active BIMI certificate as of 2026-07-02. That is more than a full renewal cycle for most CAs. The organisations at 12+ months did not all successfully renew — many have drifted into silent failure: an expired certificate they believe is still working, a DNS record pointing to a PEM URL that is no longer valid, or a logo file that was moved during a website migration without anyone thinking to check the BIMI reference.

Silent failure is BIMI’s most underreported risk

An expired BIMI certificate does not generate an error message that reaches the email marketing team. Recipients simply stop seeing the verified logo. Open rates may decline marginally. No alert fires. For weeks or months, the organisation believes its BIMI is working while recipients see it is not. The only way to detect silent failure is proactive monitoring — running a BIMI lookup tool against your own sending domain on a fixed schedule.

D3 (trademark health) and D4 (logo file integrity) are the two most commonly neglected dimensions

Certificate renewal gets calendar reminders. DNS updates get IT tickets. DMARC policies get quarterly security reviews. But trademark renewal dates are owned by legal and rarely shared with the marketing or IT team managing BIMI. And logo file integrity checks are never performed unless there is a website migration — and even then, BIMI is rarely on the migration checklist. These two dimensions are where healthy deployments decay silently.

FAQ

Frequently Asked Questions

How do I check whether my BIMI deployment is currently working?

Use a public BIMI inspector tool — search for "BIMI inspector" or "BIMI record checker." Enter your sending domain and the tool will query your DNS for the BIMI TXT record, validate the logo file URL, and check the PEM URL. Send a test email to a Gmail or Yahoo Mail address and check whether the logo appears in the sender avatar position. If the logo is visible and the inspector shows no errors, your BIMI is functioning. If either check fails, begin a dimension-by-dimension health audit.

What happens to my inbox logo if my trademark lapses before I renew my BIMI certificate?

The current certificate remains valid until its expiry date regardless of the trademark status — the certificate was already issued. The problem occurs at renewal: when the CA validates your trademark for the renewal application and finds it has lapsed, the renewal is rejected. You must resolve the trademark issue first (reinstate the registration or file a new one) before the CA will issue the new certificate. In the gap between old certificate expiry and successful renewal, your logo disappears from inboxes. This gap can last weeks or months if the trademark issue is complex.

How often should I run a full BIMI health audit?

Quarterly for the full 5-dimension framework. Monthly for D5 (DNS record accuracy) and D4 (logo file integrity) via automated checks. Annually for D3 (trademark health) — check all trademark expiry dates and build a trademark renewal calendar that feeds into your BIMI renewal planning. Set D2 (certificate currency) alerts at 120, 90, and 60 days before expiry — never rely solely on the CA notification, which typically comes at 30 days.
Get Your BIMI Health Score
VMCcerts conducts BIMI health audits across all 5 dimensions — certificate validity, trademark health, DNS accuracy, logo integrity, and DMARC enforcement — for enterprise email programmes.
Cite This Report



VMCcerts Research. (2026). BIMI Health Score Framework 2026 [Research Report]. VMCcerts. https://vmccerts.com/research/bimi-health-score-framework-2026
VMCcerts Research. “BIMI Health Score Framework 2026.” VMCcerts, 2026, https://vmccerts.com/research/bimi-health-score-framework-2026.
@techreport{vmccerts2026BIMIHealthScore,
author = {VMCcerts Research},
title = {BIMI Health Score Framework 2026},
institution = {VMCcerts},
year = {2026},
url = {https://vmccerts.com/research/bimi-health-score-framework-2026},
note = {Dataset: VMCcerts BIMI Dataset v2026.2. Snapshot: 2026-07-02.}
}
TY – RPRT
AU – VMCcerts Research
TI – BIMI Health Score Framework 2026
PY – 2026
PB – VMCcerts
UR – https://vmccerts.com/research/bimi-health-score-framework-2026
ER –