1663
Orgs with 3+ certs
19.3% of all certificate holders
134
Largest portfolio
Finanz Informatik GmbH — banking IT
140
Orgs with 5+ domains
Active programme management needed
39.4%
Certs expiring in 12mo
7974 renewals across the market

01 · The scale problem

What Changes When You Have More Than One Certificate

A single BIMI certificate is a technical configuration. You deploy it, set a calendar reminder, and renew it annually. The cognitive overhead is negligible. The failure mode is a missed renewal — visible, correctable, and recoverable within days.

A portfolio of ten, twenty, or a hundred certificates is a different kind of operational challenge. Each certificate has its own expiry date, its own DNS record, its own SVG file URL, its own CA account, and its own trademark or prior use basis. Stagger those across time and across domains — some issued in different years, some migrated from Entrust, some on different CAs — and the failure mode changes fundamentally. In November 2024, Google Chrome and Mozilla Firefox publicly distrusted Entrust as a Certificate Authority — citing compliance failures — which ended its ability to issue new BIMI certificates. Existing Entrust certificates remain valid until expiry, but no renewals are possible.

“At one certificate, the failure mode is a missed renewal. At twenty certificates, the failure mode is organisational — no single person knows the state of the entire portfolio, expiry dates are scattered across multiple systems, and the first sign of a problem is a user reporting that the logo disappeared on a sending domain nobody was monitoring.”

Tier 1 — Simple
1–2 domains
1–2
Calendar reminders sufficient. Single CA relationship. No special management overhead required.
Tier 2 — Managed
3–10 domains
3–10
Expiry register required. Designated owner per domain. Annual portfolio review cadence. Consider managed service.
Tier 3 — Programme
10+ domains
10+
Formal programme management. Centralised register. Governance structure. Health monitoring. Managed service strongly recommended.

02 · Who runs large portfolios

The Organisations Running the Largest BIMI Portfolios

The CT log data reveals the organisations with the largest BIMI domain portfolios. These are not necessarily the most recognisable consumer brands — they are the organisations with the most complex domain structures, often large financial institutions, media conglomerates, and global retail groups where each subsidiary or regional operation maintains its own sending domain.

#OrganisationSectorDomains
1Finanz Informatik GmbH & Co. KGBanking IT134
2Condé Nast Holdings LimitedMedia81
3TUI AGTravel27
4Hearst Television IncMedia23
5Josef Witt GmbHRetail21
6Humana Inc.Healthcare18
7Achmea Interne Diensten N.V.Insurance17
8Red Bull GmbHRetail/FMCG14
9eBay Inc.Ecommerce13
10PayPal, Inc.Fintech14
The Finanz Informatik pattern

Finanz Informatik is the IT service provider for Germany’s Sparkassen banking group — over 350 savings banks that each operate under their own brand and domain while sharing a common IT infrastructure. Their 134 BIMI certificates represent the Sparkassen network deploying BIMI domain-by-domain, with Finanz Informatik managing the programme centrally. This is the enterprise BIMI management model in its most mature form: one technical team managing a distributed brand portfolio at scale.

03 · The management framework

Four Pillars of Enterprise BIMI Programme Management

Pillar 1 — The Expiry Register
A single source of truth for all certificates: domain, certificate serial number, CA, issue date, expiry date, responsible owner, certificate type (VMC/CMC), trademark basis, and SVG URL.
Reviewed monthly. Updated within 24 hours of any certificate renewal or DNS change.
Automated 90-day, 60-day, and 30-day expiry alerts from the register to the responsible owner and a programme-level backup contact.
DomainCATypeExpiryOwnerStatus
brand.comDigiCertVMC2027-03-14it-ops@Active
brand.co.ukDigiCertVMC2027-01-22it-ops@Active
brand.deGlobalSignVMC2026-09-05de-ops@Renew 90d
sub.brand.comEntrustVMC2026-11-18it-ops@Migrate!
Pillar 2 — CA Standardisation
Standardise on one CA for all domains where possible. Mixed-CA portfolios create multiple billing relationships, multiple support contacts, and multiple renewal processes — all sources of coordination failure.
Exception: where an existing domain has a long-lived certificate from a different CA, allow it to expire naturally and renew to the standard CA rather than forcing an early migration that costs money without urgency.
Entrust exceptions must be treated urgently: any Entrust certificate in the portfolio cannot be renewed with Entrust. Identify them in the expiry register and flag immediately for migration planning.
Pillar 3 — Health Monitoring
Monthly automated DNS resolution check across all domains in the portfolio: BIMI TXT record resolves, PEM URL returns 200, SVG URL returns 200, certificate is not expired.
Quarterly test send from each domain to a Gmail or Yahoo Mail account to confirm logo display. Automated DNS checks catch most failures; the visual test catches edge cases like SVG file format degradation after a website migration.
Annual trademark currency check: confirm all trademark registrations underpinning VMC certificates are current and have not lapsed or been challenged. A lapsed trademark invalidates the VMC basis at renewal.
Pillar 4 — Governance Structure
Programme owner: One named individual with accountability for the BIMI portfolio. Typically IT operations or email infrastructure lead. Not marketing — this is infrastructure, not campaigns.
Domain owners: Each domain in the portfolio has a named technical contact responsible for DNS changes and renewal approval. In multi-region organisations, this is typically the regional IT lead.
Renewal authorisation: Define who approves renewal spend. For most organisations, BIMI certificate renewals should be pre-approved as a standard operational expense, not individually approved — approval delays are the primary cause of late renewals.
New domain onboarding: A documented process for adding a new domain to the BIMI programme. When a new brand or subdomain is launched, BIMI should be included in the infrastructure checklist — not discovered 18 months later.

FAQ

Enterprise Portfolio Questions

Should we standardise all domains on a single SVG logo file, or allow different logos per domain?

Where domains share the same brand identity (regional country domains for the same brand — brand.com, brand.co.uk, brand.de), standardise on a single SVG file hosted at a stable, CDN-backed URL. This means one logo update propagates to all domains simultaneously. For genuinely separate brands or sub-brands with distinct visual identities, each brand needs its own BIMI-compliant SVG and its own trademark or prior use basis. Do not use a parent brand's trademark for a sub-brand that has its own distinct visual identity — the CA will validate the logo against the trademark, and mismatches cause rejection.

How do we handle BIMI for domains that send from multiple ESPs?

BIMI operates at the domain level — not at the ESP level. If your domain brand.com sends from both Mailchimp (for marketing) and SendGrid (for transactional), BIMI applies to all emails sent from brand.com as long as both sending sources pass DMARC authentication under brand.com's policy. The BIMI certificate and DNS record are the same regardless of which ESP sends the email. The key operational requirement is ensuring all ESPs are DKIM-aligned to brand.com — which is a DMARC prerequisite regardless of BIMI.

What happens to BIMI when we retire a sending domain?

When a domain is retired and no longer used for sending email, the BIMI certificate and DNS record become irrelevant — the domain is not active so no emails display the logo. You have two options: let the certificate lapse at expiry without renewal (saving the certificate cost), or maintain the DNS record and certificate if the domain may be reactivated. If the domain is retired permanently, remove the BIMI DNS record as part of the domain retirement process to maintain DNS hygiene. Update the expiry register to reflect the retirement.

Can we use a wildcard certificate to cover multiple subdomains?

BIMI certificates are not issued as wildcards. Each sending domain (or subdomain) requires its own BIMI certificate. A certificate issued for brand.com does not cover campaigns.brand.com or newsletters.brand.com. Each subdomain that appears in the From address of emails requires its own BIMI DNS record and its own certificate if you want the verified logo to display on emails from that subdomain. This is a deliberate aspect of the BIMI standard — domain-level verification is more secure than wildcard coverage.
VMCcerts manages enterprise BIMI portfolios
For organisations with 3 or more certificates, VMCcerts provides centralised expiry tracking, renewal coordination, health monitoring, and CA management across all domains — a managed programme, not just certificate procurement.
Cite This Report



VMCcerts Research. (2026). Enterprise Multi-Domain BIMI Management 2026 [Research Report]. VMCcerts. https://vmccerts.com/research/enterprise-multi-domain-bimi-management
VMCcerts Research. “Enterprise Multi-Domain BIMI Management 2026.” VMCcerts, 2026, https://vmccerts.com/research/enterprise-multi-domain-bimi-management.
@techreport{vmccerts2026EnterpriseMultiDomain,
author = {VMCcerts Research},
title = {Enterprise Multi-Domain BIMI Management 2026},
institution = {VMCcerts},
year = {2026},
url = {https://vmccerts.com/research/enterprise-multi-domain-bimi-management},
note = {Dataset: VMCcerts BIMI Dataset v2026.2. Snapshot: 2026-07-02.}
}
TY – RPRT
AU – VMCcerts Research
TI – Enterprise Multi-Domain BIMI Management 2026
PY – 2026
PB – VMCcerts
UR – https://vmccerts.com/research/enterprise-multi-domain-bimi-management
ER –